Security

 View Only
last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM + 7030 controller

This thread has been viewed 15 times
  • 1.  CPPM + 7030 controller

    Posted Mar 21, 2024 05:45 PM

    Hi All,

    Have CPPM 6.9.13 with the latest security path and 7030 controller with some 305 APs.

    There is Sponsored Guest Access configure, which work fine except CoA (would like to disconnect guest users whenever i want).

    So the rfc3576 is configured on both sides. Enforcement profile is ok (i think). When i try to do CoA from CPPM i got:

    • on CPPM: failed for device....
    • on controller: rc_rfc3576.c, rc_process_rfc3576_request:168: CoA server X.X.X.X(cppm ip) has radsec enabled, but CoA request did not come via secure connection.

    Radsec is off.

    Regards

    M.



  • 2.  RE: CPPM + 7030 controller

    Posted Mar 21, 2024 06:24 PM

    So if you run "show running-config | begin "aaa rfc" on your controller (directly on the controller, not a conductor)

    Do you see and "enable-radsec"?



    ------------------------------
    If my post was useful, please Accept Solution and Give Kudos.
    ------------------------------
    Zak Chalupka
    Principal Engineer - HPE Aruba
    ACDX | ACMP | ACSP | ACCP
    wifizak@hpe.com
    ------------------------------
    Ideas expressed here are solely my own and not necessarily that of HPE Aruba.
    ------------------------------



  • 3.  RE: CPPM + 7030 controller

    Posted Mar 22, 2024 07:58 AM

    Hi Zak,

    There is no radsec enable on controller site.

    I think the problem is on CPPM side.

    Regards

    M




  • 4.  RE: CPPM + 7030 controller

    Posted Mar 22, 2024 08:00 AM

    OK, found a solution for now.

    Upgraded CPPM to the 6.9.13 with latest security patch, disabled radsec service. It works :)

    Before upgrade CPPM did the same, but it didn't do the job..

    But think that this is not the final solution.

    Trying to do that right way :)

    Regards

    M.