Wireless Access

last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

[WIP Issue] open SSID association

This thread has been viewed 1 times
  • 1.  [WIP Issue] open SSID association

    Posted Jan 02, 2015 02:48 PM

    hi and happy new year.

    I use the WIP Wizard to configure the wip (ids and ips) , but when done found that the users can’t associate with an open WLAN ( guest wlan) , and didn’t know way .

    Any suggestion, any idea, any usefull document.

    Thank you.



  • 2.  RE: [WIP Issue] open SSID association

    EMPLOYEE
    Posted Jan 02, 2015 03:18 PM

    rchahboune,

     

    Change the configuration back to the default.  We do not have enough information to understand why it is not working.

     



  • 3.  RE: [WIP Issue] open SSID association

    Posted Jan 02, 2015 04:17 PM

    yes,

    i do that ( i disable the IPS and the IDS ), and when done the  the association to the OPEN SSID become possible.

     



  • 4.  RE: [WIP Issue] open SSID association

    EMPLOYEE
    Posted Jan 02, 2015 04:19 PM

    Well,

     

    That is your answer.  The problem is your settings.  IDS settings can block traffic from legitimate SSIDs, as well.

     



  • 5.  RE: [WIP Issue] open SSID association

    Posted Jan 02, 2015 04:22 PM

    i configure a new WIP profile

    do the following

     

    IDS Configuration

    high level

    IPS configuration

    High level

     when done , the asscotiation with the open (captive portal WLAN) become impossible , custumer can't connect to it, and when i disable the WIP (ids and ips off), the association with the open WLAN become possible and normal.

    my question is what is the WIPS parameter that prevent the assocation with the open WLAN.

    regards



  • 6.  RE: [WIP Issue] open SSID association

    EMPLOYEE
    Posted Jan 05, 2015 08:28 AM

    @rchahboune wrote:

    i configure a new WIP profile

    do the following

     

    IDS Configuration

    high level

    IPS configuration

    High level

     when done , the asscotiation with the open (captive portal WLAN) become impossible , custumer can't connect to it, and when i disable the WIP (ids and ips off), the association with the open WLAN become possible and normal.

    my question is what is the WIPS parameter that prevent the assocation with the open WLAN.

    regards


    We need the exact WIP configration to understand what could be blocking the clients--there are MANY checkboxes that could be stopping clients from connecting.

     

    Honestly, IDS/IPS  is typically not applied to an open SSID, because there are many attacks that could be done to users that do not have encryption enabled.  If the customer is serious about  protecting against attacks, they should first enable strong encryption.



  • 7.  RE: [WIP Issue] open SSID association

    Posted Jan 05, 2015 03:27 PM

    hi cjoseph,

    for the configuration i followed the WIPS wizard , and i configure the the ids and ips rule at the high level.

    I use the IDS/IPS for some APGROUP that contain a VAP with strong encryption (WPA2 Entrerise) and  open SSID (Guest SSID with captive portal authentication).

    when done the open ssid has become inaccessible.

     

     



  • 8.  RE: [WIP Issue] open SSID association

    Posted Jan 03, 2015 09:16 PM
    Please uncheck the following under IDS Unauthorized Device profile under the advance tab.

    - Privacy
    - Require WPA


  • 9.  RE: [WIP Issue] open SSID association

    Posted Jan 04, 2015 01:24 PM

    wajih.anees@bell.ca wrote:
    Please uncheck the following under IDS Unauthorized Device profile under the advance tab.

    - Privacy
    - Require WPA

    thank you for the replay  i have uncheck Require WPA but not Privacy , i will do iit soon.



  • 10.  RE: [WIP Issue] open SSID association

    Posted Jan 05, 2015 08:08 AM

    have you checked your logs, they might provide information on why clients are kicked off when WIPs is on, then you can disable those.



  • 11.  RE: [WIP Issue] open SSID association

    Posted Jan 05, 2015 03:29 PM

    @boneyard wrote:

    have you checked your logs, they might provide information on why clients are kicked off when WIPs is on, then you can disable those.


    good idea i will try to.



  • 12.  RE: [WIP Issue] open SSID association

    EMPLOYEE
    Posted Jan 06, 2015 03:28 AM

    What is the customer policy with respect to WIPS that you are trying to achieve?

     

    Is there something specific in the 'high' profile that the customer wants enabled?

     

    An over vealous configuration of WIPS policy can have a detrimental effect, even to your own legitimate ssids, as cjoseph mentioned.

     

    I would suggest starting with the 'low' profile and tuning up the features that you require.

     

    Nevertheless, I believe that the 'privacy' setting in the unauthorised-device-profile is what is causing your issues, though the logs will confirm that.

     



  • 13.  RE: [WIP Issue] open SSID association

    Posted Jan 06, 2015 03:57 AM

    @Michael_Clarke wrote:

    What is the customer policy with respect to WIPS that you are trying to achieve?

     

    Is there something specific in the 'high' profile that the customer wants enabled?

     

    An over vealous configuration of WIPS policy can have a detrimental effect, even to your own legitimate ssids, as cjoseph mentioned.

     

    I would suggest starting with the 'low' profile and tuning up the features that you require.

     

    Nevertheless, I believe that the 'privacy' setting in the unauthorised-device-profile is what is causing your issues, though the logs will confirm that.

     


    i agree with you , the IDS/IPS have to be configured step by step according to the needs, but i deploy that for a custumer who is not familiar with Aruba ,that's why I chose the highest level.