Controllerless Networks

 View Only
last person joined: 2 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

802.1x causing WiFi and VPN disconnects

This thread has been viewed 32 times
  • 1.  802.1x causing WiFi and VPN disconnects

    Posted Jul 20, 2022 01:26 PM
    Hello all,

    Hoping someone can help.  Quick overview of our architecture:

    - 2 x Aruba ClearPass virtual 5k appliances
    - IAP 325's & virtual controllers
    - mix of architecture for routers, switches, firewalls inbetween
    - Intune used to push a WiFi profile to clients
    - Clients have PKCS certificates pushed from Intune, these are validated by ClearPass
    - when the clients observe the VPN drop a timeout is seen in ClearPass
    - clients with newer / higher spec WiFi adapters are less effected

    Symptoms on WiFi:

    - Windows 10 laptop clients observe frequent VPN disconnects and poor call quality issues with soft phones
    - the VPN disconnects occur randomly, one client will disconnect whilst the person next to them will remain connected
    - pings to the internet remain good whilst the VPN drops
    - the behaviour only occurs when clients connect to an SSID configured with 802.1x / certificate based authentication, when connected to an open SSID or SSID with PSK the VPN does not drop - observed for several hours
    - for testing, clients have been connected directly to the WiFi switch with a CAT6 in the relevant VLAN with no authentication, no issues observed

    Aruba TAC have been engaged for several months and requested BSSID / Wireshark captures but they do not show 802.1 frames for some reason.

    Basically it's clear the issue is related to 802.1x, any help would be much appreciated!

    Many thanks


  • 2.  RE: 802.1x causing WiFi and VPN disconnects

    EMPLOYEE
    Posted Jul 20, 2022 02:07 PM
    Do you have broadcast filtering on that SSID?

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 3.  RE: 802.1x causing WiFi and VPN disconnects

    Posted Jul 20, 2022 06:40 PM
    Appears we have inconsistent configuration for the specific SSID.  2 of our sites are configured as follows:

    Broadcast filtering - ARP
    Multicast transmission Optimisation - Disabled
    Dynamic Multicast Optimisation - Enabled

    The other 2 have the following:

    Broadcast filtering - Disabled
    Multicast transmission Optimisation - Enabled
    Dynamic Multicast Optimisation - Enabled

    The VPN drops occur on all sites.

    Many thanks


  • 4.  RE: 802.1x causing WiFi and VPN disconnects

    EMPLOYEE
    Posted Jul 20, 2022 09:08 PM
    You should start by upgrading your clients to the latest driver and observe the upgraded clients.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 5.  RE: 802.1x causing WiFi and VPN disconnects

    Posted Jul 21, 2022 09:45 AM
    Thank you for the suggestion.

    The drivers have been updated on a test laptop, unfortunately the VPN drops still occur.


  • 6.  RE: 802.1x causing WiFi and VPN disconnects

    EMPLOYEE
    Posted Jul 22, 2022 04:38 AM
    You mentioned: IAP-325 & virtual controllers. Do you mean that there are separate VMC's running? Or are these IAPs in Instant mode running with the VC running in the APs?
    What version are the IAPs running?
    If running with a virtual controller, how many IAPs are there in the cluster?
    If running with a virtual controller, do you have dynamic radius proxy configured/enabled?
    If running with a virtual controller, have you checked if the timeout messages are on specific APs or across all APs?
    If running with a virtual controller, have you researched if there is a correlation between the timeouts and roaming events of the clients?

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 7.  RE: 802.1x causing WiFi and VPN disconnects

    Posted Jul 27, 2022 05:00 AM

    You mentioned: IAP-325 & virtual controllers. Do you mean that there are separate VMC's running? Or are these IAPs in Instant mode running with the VC running in the APs?  IAPs in instant mode with the VC running on APs

    What version are the IAPs running? v8.9.0.3

    If running with a virtual controller, how many IAPs are there in the cluster?  Varies from 10 to 24 depending on the site

    If running with a virtual controller, do you have dynamic radius proxy configured/enabled?  Yes

    If running with a virtual controller, have you checked if the timeout messages are on specific APs or across all APs?  We have only checked the APs serving the affected client(s)

    If running with a virtual controller, have you researched if there is a correlation between the timeouts and roaming events of the clients?  VPN disconnects occur frequently for desk-based clients so I don't think roaming is a factor




  • 8.  RE: 802.1x causing WiFi and VPN disconnects

    EMPLOYEE
    Posted Jul 27, 2022 07:33 AM
    What is your channel width on the 5ghz band?  By default it is 80mhz, which can cause issues in dense environments.
    What is the ARM transmit power range for your access points?

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 9.  RE: 802.1x causing WiFi and VPN disconnects

    Posted Jul 27, 2022 09:13 AM
    80MHz support is disabled. 

    ARM configuration: Min: 12, Max: 21

    Thanks!