Security

 View Only
last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Getting error in EAP-TLS authentication.

This thread has been viewed 20 times
  • 1.  Getting error in EAP-TLS authentication.

    Posted Mar 14, 2024 09:52 AM

    I am getting many failed connection with the below error . Is anyone experience the same behavior . Help me with the suggestions and fix 



  • 2.  RE: Getting error in EAP-TLS authentication.

    Posted Mar 14, 2024 09:59 AM

    Hi

    What type of client get this error? As the error message states "fatal alert by client" the error is on the client side.

    Some additional information would also be good to know:

    • What version of ClearPass are you running?
    • Have anything changed in the environment like updates on the client side or ClearPass?
    • Do you also have working EAP-TLS authentications?


    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 3.  RE: Getting error in EAP-TLS authentication.

    Posted Mar 14, 2024 02:43 PM

    What type of client get this error? Mobile phones

    • What version of ClearPass are you running? 6.10.8
    • Have anything changed in the environment like updates on the client side or ClearPass?No
    • Do you also have working EAP-TLS authentications? Yes 





  • 4.  RE: Getting error in EAP-TLS authentication.

    EMPLOYEE
    Posted Mar 15, 2024 08:55 AM

    May be best to work with TAC on this. I've seen multiple reasons, like server certificate not trusted, no client certificate enrolled to the client device, authorization servers that were unreachable or take a lot of time. There is something that the client does not like. It may be good to find what the failing clients have in common (same OS, new enrolled, renewed certificate, or so).



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------