Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Permanent or 20k days BLACKLIST NOT WORKING

This thread has been viewed 0 times
  • 1.  Permanent or 20k days BLACKLIST NOT WORKING

    Posted Sep 23, 2019 05:38 AM
      |   view attached

    Hi guys anyone can help me how we can permanently or 20k days blacklist a mac-address from Aruba OS 6.5 7000 controller series?

     

    -We have 2 7000 series controller on HA

    -When we try to blacklist a mac address and set its block time to 0 or 2Billion secs. it comes back to 3600 secs or 60 minutes of block time using CLI

    -Some of the blacklisted below were done by the previous network admin.

    -Now when we try to add new mac addresses it defaults to 3600 secs even when we set the block time to 0 or 2 Billion (20k days) secs.

    Capture.JPG

     

    Your suggestions will help us a lot thank you :)



  • 2.  RE: Permanent or 20k days BLACKLIST NOT WORKING

    EMPLOYEE
    Posted Sep 23, 2019 05:54 AM

    If you blacklist a device when it is currently connected, it will default to just 3600 seconds.  Try to use “aaa user delete” to delete the device then run the blacklist command for that device to see if it is different.



  • 3.  RE: Permanent or 20k days BLACKLIST NOT WORKING

    Posted Sep 24, 2019 01:32 AM
      |   view attached

    Hi cjoseph thanks you for your response unfortunately it didn't work or we did something wrong?

     

    We have tried removing the device from the wireless, blacklist and block the mac address again still its block time defaults to 60 minutes

     

    Here is the configuration of the VAP did we miss something on the configuration?

     

    thanks

    123.png



  • 4.  RE: Permanent or 20k days BLACKLIST NOT WORKING

    EMPLOYEE
    Posted Sep 24, 2019 05:06 AM

    Please see the article here:  https://community.arubanetworks.com/t5/Controller-Based-WLANs/How-to-blacklist-users-permanently/ta-p/175712

     

    on that controller, try:

     

    config t

    ap ap-blacklist-time 0



  • 5.  RE: Permanent or 20k days BLACKLIST NOT WORKING

    Posted Sep 24, 2019 10:42 PM

    Hi cjoseph thanks for the response.

     

    unfortunately the "ap ap-blacklist-time 0" doesnt work on global configuration mode 

    1234.png

    is that command supported on that Aruba OS version?

    Thank you. :)



  • 6.  RE: Permanent or 20k days BLACKLIST NOT WORKING

    EMPLOYEE
    Posted Sep 24, 2019 10:49 PM

    Did you execute "config t" ahead of that command?