Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass guest wi-fi not working no attibutes in radius request not matching service

This thread has been viewed 20 times
  • 1.  Clearpass guest wi-fi not working no attibutes in radius request not matching service

    Posted May 24, 2023 11:13 AM

    Hi all,
    I used the Clearpass services wizard to setup a Guest wi-fi with MAC caching.  In Clearpass this creates two services.  One for MAC authentication and one for the guest authentication.  I also used setup a new WLAN on my Aruba controller cluster. 

    When my client tries to connect, I get the captive portal, I enter my guest username and password and the request is refused.

    I check in Access tracker and the service for Guest authentication has no attributes in the radius request.  Only username.  no AP name where the request came in, no nothing.  In the MAC authentication service, I get all the attributes for the device.  Device type, OS, service, etc.  This also fails but I would suspect that since I haven't logged in yet.

    Does anyone have any ideas why the radius request is not matching the service or the request not have any attributes?



  • 2.  RE: Clearpass guest wi-fi not working no attibutes in radius request not matching service

    Posted May 24, 2023 11:19 AM




  • 3.  RE: Clearpass guest wi-fi not working no attibutes in radius request not matching service

    Posted May 24, 2023 11:23 AM




  • 4.  RE: Clearpass guest wi-fi not working no attibutes in radius request not matching service

    Posted May 24, 2023 04:45 PM

    Actually, I think this might be more on the controller side.  Something is missing in one of the controller profiles and the Client-Station-ID is not being sent.  Anyone have any ideas?




  • 5.  RE: Clearpass guest wi-fi not working no attibutes in radius request not matching service
    Best Answer

    EMPLOYEE
    Posted May 24, 2023 07:22 PM

    it looks like you have enabled pre-auth check "using Aruba Application Authentication" in weblogin, that's why you see application as source in access tracker
    you can set the pre-auth check to use RADIUS or dont have it at all.
    in your current setup you need to configure an additional webauth service 



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 6.  RE: Clearpass guest wi-fi not working no attibutes in radius request not matching service

    Posted May 30, 2023 11:48 AM

    Thanks ariyap that was it  I changed pre-auth from application to RADIUS in the web login page.  Now I'm authenticating. 

    I have a few more things to figure out now.  Now that I'm logged into the guest wi-fi, the captive portal window redirect to the Clearpass login page.  That should probably go to our main web site.  Also, the MAC authentication server is not matching and I have to log in each time. 

    Thanks again.