Security

 View Only
last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

framed-ip-address sometimes blank

This thread has been viewed 19 times
  • 1.  framed-ip-address sometimes blank

    Posted 21 days ago

    Good Morning,

    We use a transparent web proxy, which relys on Clearpass sending its radius accounting packets through upon a wired or wireless device authenticating using 802.1x.

    The accounting packet needs to contain the framed-ip-address.

    My understanding is that the switch sends the IP address to clearpass using a DHCP helper on the aruba switch which is configured on each vlan.

    This is working.

    Occassionally, we get a radius authentication event in Clearpass, where the framed-ip-address is blank.  It only happens on wired 802.1x devices, which are connected to the aruba 2930F switch which has aaa port authentication configured.   I realise that this is probably a timing this, and that the device doesn't yet have an IP address at the point that the port is authenticated.

    My question is, why does the interim accounting packet not send through to clearpass when the device eventually gets its IP address?

    my switches 'radius accounting' is configured with:

    aaa server-group radius "CPPM" host 192.168.xx.xx
    aaa accounting update periodic 1
    aaa accounting commands interim-update radius
    aaa accounting network start-stop radius server-group "CPPM"
    aaa authentication port-access eap-radius server-group "CPPM"



  • 2.  RE: framed-ip-address sometimes blank

    EMPLOYEE
    Posted 21 days ago

    You also need to configure  "client track ip" commands at global and VLAN level, (in reference to CX switches)

    for AOS-S, i think the corresponding command is "ip client-tracker "



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: framed-ip-address sometimes blank

    Posted 21 days ago

    cheers, yes I have checked and we do have an "ip client-tracker trusted"  at the global level.

    I wasnt able to apply it at the vlan though.




  • 4.  RE: framed-ip-address sometimes blank

    Posted 21 days ago

    We've had to configure accounting delay (especially on the initial connect) as it's likely the RADIUS data has been sent to CPPM before the device has got the IP address from DHCP.

    Have a look at this to see if you can configure a delay, suggest starting with 5 seconds then go from there.

    https://techhub.hpe.com/eginfolib/networking/docs/switches/WB/15-18/5998-8152_wb_2920_asg/content/ch06s13.html

    • Acct-Delay-Time




  • 5.  RE: framed-ip-address sometimes blank

    Posted 21 days ago

     In networking, a framed IP address may occasionally appear blank due to configuration errors or issues with the network server.  at t internet plans     This can disrupt connectivity and prevent proper data transmission. Troubleshoot by verifying network settings, checking for software updates, and ensuring compatibility with network protocols. Consult network administrators or technical support for assistance in resolving the issue and restoring stable connectivity.