We are having an issue with our Radius configuration on our 2930M switches, I think I have tracked down the issue but as I'm still teaching myself the Aruba switches, I was looking for a second/third opinion.
Our Setup: Aruba 2930M edges (WC.16.11.0006), we use Radius to set port VLAN assignment based on AD workstation group membership, and this does currently work but only if the primary (first listed) server is active, if it is off line then nothing happens, all configured ports, default to the configured Unauth VLAN.
Typical Port configuration:
interface 4/34
untagged vlan 51
aaa port-access authenticator
aaa port-access authenticator unauth-vid 51
aaa port-access controlled-direction in
spanning-tree admin-edge-port
spanning-tree bpdu-protection
exit
Radius configuration on Switch:
radius-server host 172.16.0.10 key "987654321123456789"
radius-server host 172.16.1.10 key "987654321123456789"
There is no other Radius configuration on the switch, If I do a Show Radius I get:
Status and Counters - General RADIUS Information
Dead RADIUS server are preceded by *
Deadtime (minutes) : 0 TLS Dead Time (minutes) : 0
Timeout (seconds) : 5 TLS Timeout (seconds) : 30
Retransmit Attempts : 3 TLS Connection Timeout (seconds) : 30
Global Encryption Key :
Dynamic Authorization UDP Port : 3799
Source IP Selection : Outgoing Interface
Tracking : Disabled
Request Packet Count : 3
Track Dead Servers Only : Disabled
Tracking Period (seconds) : 300
ClearPass Identity :
Auth Acct DM/ Time |
Server IP Addr Port Port CoA Window | Encryption Key OOBM
--------------- ----- ----- --- ------ + ------------------------------------- ------------------------------------------------ ----
172.16.0.10 1812 1813 No 300 | 987654321123456789 No
172.16.1.10 1812 1813 No 300 | 987654321123456789 No
both of these servers (Windows 2012R2 running NPS) are members of the default server group (Radius) I'm thinking that the Dead time being 0 is the issue and because of this the primary is never considered as dead when it is off line or not contactable for some other reason, as I test to confirm the secondary was working I removed the Primary (172.16.0.10) once that happened it all started to work again after a short time.
On reading up on this I can see that the Timeout and Retransmit values are the defaults, is this just case I need to add a setting for deadtime ???
Thanks Simon