Comware

 View Only
last person joined: 23 hours ago 

Expand all | Collapse all

Compare7 HPE 5130: Struggling with COA Bounce Port in Enforcement Profile in Clearpass

This thread has been viewed 14 times
  • 1.  Compare7 HPE 5130: Struggling with COA Bounce Port in Enforcement Profile in Clearpass

    Posted 15 days ago

    Hello,

    as meanwhile I'm clueless im hoping for community Input:

    Current Setup:

    HPE 5130 with activated Port Security and therefore 802.1X authenticating against Clearpass

    What's Working:
    Machine based Auth via 802.1X . Vlan Assignment even works with User Auth, so after Windows Login a user gets new VLAN ID ( EAP-TLS). I can bounce ports via Access Tracker successfully. I can see the Traffic via Wireshark and the Switch sends back a COA-ACK (H3C and Cisco Port bounce work, although my CPPM seems to be on 6.11.2.). SO Actually I would state COA Bounce is working as expected when doing manually.

    What's not Working: 

    The User Auth works, but the Client does not recognise, that a new DHCP Lease should be requested. Therefore there are SSO Settings in the LAN GPO and the Check for dynamic VLAN is set Properly. This works with Aruba Switches, but not with the one Comware. When I add the (First tried with H3C , then with Cisco Bounce Profile) to the Enforcement Policy, simply no COA is sent to the Switch. I can not see any Traffic via Wireshark. It really seems Clearpass does not send any COA Packacke through the Enforcement Policy despite of having it defined over there.

    This is causing, that the Client does not recognise a Link down and up to get a new DHCP Lease.

    I have added two Screenshots to show up my Enforcement Policy and my Rules over there.

    I know  - I have read, dynamic vlan assignment is not that nice. possibly your advise will be: go for advanced filtering on Layer3. But: It should work and on Aruba it works. 

    So do you have any input for me to make the Port Bounce working in the Enforcement Policy after the VLAN Assignment so the Clients do get a DHCP Lease?


    Thanks in Advance,
    Dennis 



  • 2.  RE: Compare7 HPE 5130: Struggling with COA Bounce Port in Enforcement Profile in Clearpass

    Posted 12 days ago

    Hi Dennis.

    As a workaround try to add short session timeout (few seconds) into enforcement profile like:

    Radius:IETF

    Session-Timeout

    =

    60

    Did you set device type to H3C? I have similar problem when I set Comware device to Hewlett Packard Enterprise or Aruba.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2024
    ------------------------------



  • 3.  RE: Compare7 HPE 5130: Struggling with COA Bounce Port in Enforcement Profile in Clearpass

    Posted 8 days ago

    Hello,

    did you find any solution?

    I think I have the same problem my switch version is:
    5130EI_7.10.R3507P18


    thank you




  • 4.  RE: Compare7 HPE 5130: Struggling with COA Bounce Port in Enforcement Profile in Clearpass

    Posted 2 days ago

    Hello,

    I think i find the problem in 6.12.0 known issue here number CP‑51806:

    https://www.arubanetworks.com/techdocs/ClearPass/CP_ReleaseNotes_6.x.x/Default.htm#ReleaseNotes/Known/Known-6.12.0.htm

    Is has trouble with Port Bounce mabye that is the reason I will try the workaround solution and see if work

    Thank you