Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

8021x with Juniper Switch

This thread has been viewed 44 times
  • 1.  8021x with Juniper Switch

    Posted Sep 16, 2022 10:07 AM
      |   view attached
    I'm trying to get 8021x working on a Juniper ex2300 switch.  I see the authentication requests on Clearpass and devices being allowed but it appears the devices aren't getting an address.  This is what i see for dhcp statistics:
    Packets dropped:
    Total 13
    Invalid server address 2
    Interface not configured 11
    Also attaching a cleaned up config.

    Attachment(s)

    txt
    test-switch.txt   29 KB 1 version


  • 2.  RE: 8021x with Juniper Switch

    EMPLOYEE
    Posted Sep 18, 2022 01:40 AM
    check your configuration against this.
    https://www.juniper.net/documentation/en_US/release-independent/nce/topics/example/nce157-example-aruba-dot1x-mac.html

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 3.  RE: 8021x with Juniper Switch

    Posted Sep 19, 2022 10:48 AM
    I got something back from the juniper forums as well.  I'll compare and report back.


  • 4.  RE: 8021x with Juniper Switch

    Posted Sep 19, 2022 12:05 PM
    checked against juniper recommendations and everything looks correct.  Still no dhcp


  • 5.  RE: 8021x with Juniper Switch

    EMPLOYEE
    Posted Sep 21, 2022 07:26 AM
    I'm not really familiar with EX Switching, but if you place a client in the same VLAN on a port that is not configured for 802.1X (normal open port, without authentication), does it get an IP address in that case?

    Do you have a command on the switch to see the authentication sessions, port status, VLAN assignment, etc? Then you can verify that the client is in the correct VLAN, no ACLs are applied, etc.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 6.  RE: 8021x with Juniper Switch

    Posted Sep 27, 2022 11:44 AM
    Just to follow up, still having this issue.


  • 7.  RE: 8021x with Juniper Switch

    Posted Oct 28, 2022 04:23 PM
    Still the same.


  • 8.  RE: 8021x with Juniper Switch

    Posted Oct 28, 2022 08:51 PM
    Help us help you :)

    Herman asked if you plug the device into a non-authentication port with the same VLAN does the client complete DHCP?

    ------------------------------
    ACNSA | ACEA | ACCP | ACMP
    ------------------------------



  • 9.  RE: 8021x with Juniper Switch

    Posted Oct 31, 2022 02:07 PM
    i got dhcp working by removing the firewall portion of the juniper recommended configuration.  I'm stuck now on getting the colorless port configuration working:
    https://www.juniper.net/documentation/en_US/release-independent/nce/topics/example/nce-209-configuring-colorless-ports-ex-aruba-clearpass-policy.html

    The Clearpass approval/authentication is working but its not pushing back the vlan option.  I'm only getting the voip vlan working or the switch will just default to vlan 1


  • 10.  RE: 8021x with Juniper Switch

    Posted Nov 01, 2022 07:56 AM
    Hi, can you show the enforcement profile where you want to send the vlan to that switch? What is the vlan number you want to send?


  • 11.  RE: 8021x with Juniper Switch

    Posted Nov 01, 2022 12:31 PM
    To follow up on this i got it working by removing the firewall filters on the switch.  I started a conversation about colorless ports on this post:
    https://community.arubanetworks.com/discussion/colorless-ports-with-clearpass-and-juniper


  • 12.  RE: 8021x with Juniper Switch

    Posted Nov 01, 2022 12:33 PM
    the one thing i don't have working is getting a workstation recognized.  i'm trying to have the enforcement policy look the hostname up in active directory.


  • 13.  RE: 8021x with Juniper Switch

    MVP GURU
    Posted Nov 01, 2022 03:15 PM
    Use the below example for returning VLANs.



    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022
    If my post was useful accept solution and/or give kudos
    ------------------------------