Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Problems after enabling pefng license

This thread has been viewed 0 times
  • 1.  Problems after enabling pefng license

    Posted Oct 11, 2013 03:02 AM

    Hello,

     

    after enabling the pefng license on a version 5.0.4.12 Controller I have encountered a few problems.

     

    In "Monitoring/ Clients" Tab I can't see anymore associated/authenticated users. But "Monitoring/ Access Points" shows under .bg Clients and .a Clients there are connected users.

     

    What do I have to mind after enabling pefng license?

     

    Using here wpa2-psk wlans on this related controller. I already have created an user role with a firewall rule "any any permit".

     

    1. Is there any setting which prevents that clients aren't shown under "Monitoring/ Clients" Tab?

    2. When using WPA2-PSK how does role derivation works/ where to I have to reference the appropriated user role clients should be assigned after successful authentication?

     

    Regards,

    kokel



  • 2.  RE: Problems after enabling pefng license

    MVP
    Posted Oct 11, 2013 03:43 AM

    I noticed a small bug regarding monitor > client too.

    Can't remember the effected arubaos version, but the 'fix' was to select ipv6 clients and then back to ipv4. Clients showed up this way.



  • 3.  RE: Problems after enabling pefng license

    Posted Oct 11, 2013 03:58 AM

    Hello koenv,

     

    I can click on IPv4, IPv6, All, everytime "No such station found in the system"

     

    Regards,

    kokel



  • 4.  RE: Problems after enabling pefng license

    Posted Oct 11, 2013 05:02 AM

    On CLI:

     

    show user-table

    User Entries: 2/2

     

    show user-table station

    Station Entries: 17

     

    show ap active shows also a lot of 11g Clients and 11a Clients

     

    What am I doing wrong?

     

    Regards,

    kokel

     



  • 5.  RE: Problems after enabling pefng license

    EMPLOYEE
    Posted Oct 11, 2013 05:29 AM

    Kokel,

     

    Please try clearing your browser cache.

     



  • 6.  RE: Problems after enabling pefng license

    Posted Oct 11, 2013 05:37 AM

    I have read this in several other posts.

    Browser cache deleted several times, in different browsers.

     

    But the cli shows the same issue!

     

    user-table entries != clients number from "show ap active" output.

     

    Kokel



  • 7.  RE: Problems after enabling pefng license

    EMPLOYEE
    Posted Oct 11, 2013 05:39 AM

    Ok.

     

    Did you reboot the controller after adding the licenses?

     



  • 8.  RE: Problems after enabling pefng license

    Posted Oct 11, 2013 05:40 AM

    Yes, the license have only the flag "E".



  • 9.  RE: Problems after enabling pefng license

    EMPLOYEE
    Posted Oct 11, 2013 05:42 AM

    Is this a production controller?  You might have to do a "write erase" (not write erase all) and start over and see if you have the same issue.

     



  • 10.  RE: Problems after enabling pefng license

    Posted Oct 11, 2013 08:36 AM

    Yes, it's in production.

     

    Temporarily. I have disabled user derivation rules and now I can see all clients like before.

     

    Why do I have to do write erase? 

     

    Regards,

    Kokel



  • 11.  RE: Problems after enabling pefng license

    EMPLOYEE
    Posted Oct 11, 2013 08:37 AM

    @kokel wrote:

    Yes, it's in production.

     

    Temporarily. I have disabled user derivation rules and now I can see all clients like before.

     

    Why do I have to do write erase? 

     

    Regards,

    Kokel


    You do not have to write erase.  It would be a troubleshooting step.  You should probably open a support case.

     



  • 12.  RE: Problems after enabling pefng license

    Posted Oct 11, 2013 05:33 PM

    If you disable the user derivation rulesthe connected clients will be assigned the initial-role of the AAA profile for a PSK network.  The UDRs would take precedence over this initial-role value.   What do your user derivation rules look like?   Are you assigning roles or vlans?    

     

    show aaa derivation-rules user (to show all UDRs)

     

    then

     

    show aaa derivation-rules user <name-of-rule>