Security

 View Only
last person joined: 21 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Radius service stops after update to ClearPass 6.11.7 on C1000 machines

This thread has been viewed 74 times
  • 1.  Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Mar 06, 2024 07:07 AM

    Hi

    A customer is running multiple clusters based on C1000 and C3010 hardware servers. During deployment in the lab environments we haven't seen any issues after update to ClearPass 6.11.7. But after deployment in the first production C1000 cluster we see that the Radius service is indicated as Stopped in the Services Control tab on both the servers in the cluster. It's not totally stopped, because some clients get through with authentication, so the impression is that the service is restarting over and over again. No logs in the Event log regarding issues with the Radius service. Only reports from users with authentication issues.

    Has anyone else noticed any strange behavior after update to 6.11.7?

    On other customers running virtual ClearPass server I haven't seen issues with 6.11.7.

    We are currently working with TAC to solve the issue.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------


  • 2.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    EMPLOYEE
    Posted Mar 11, 2024 10:22 AM

    Did you find a root cause and solution for this? Have not seen this myself.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Mar 14, 2024 04:44 AM

    Hi Jonas,

    I had this issue last week also after updating to 6.11.7. One of my authorisation sources was not functioning correctly, even it was not used.

    The radius and tacacs service started but stopped very quickly. 

    After deleting the authz source the services could start. and it al worked again.

    Best regards,

    Erik




  • 4.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Mar 14, 2024 05:08 AM

    Hi Erik

    Interesting, but a bit of special case as your authz source wasn't utilized. In most cases you have references to the authz sources in role mapping or enforcement policies.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 5.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Mar 14, 2024 05:07 AM

    Hi Herman

    No we have not got any root cause from TAC yet. They are still working with the logs.

    We rolled back to the previous version and the function was restored.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 6.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Mar 14, 2024 05:19 AM

    Hi Jons,

    I my case, rollback did not work, after starting the appliance same issue.

    Yes I tested with some authz sources, but forgot to delete them, but the query was not fully right. Missing a ";"

    Best regards,

    Erik




  • 7.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Apr 05, 2024 01:34 PM

    Yep, this matches my own experience.  When doing complex scenarios with custom sources, the UI will sometimes permit syntactically invalid configurations to get built for the underlying RADIUS server daemon.  In my case it was something silly (setting Entrata as an authn source instead of authz.)




  • 8.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted 4 days ago

    Hi,

    we have exactly the same issue.
    TAC support couldn't solve the problem so far.

    Our old clearpass installation works like charm, no propblems at all.
    We exported the configruation of our running productive clearpass and imported the config on our new clearpass server (6.11.8).
    As soon as we use the radius for example wifi auth. the radius service is crashing.

    Ablsoutly no idea why this is happening.
    Send a tons of logs to TAC but without any solution.

    Any news here?

    Regards from Springfield.




  • 9.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    MVP
    Posted 4 days ago

    We have not yet moved from 6.9.13. Over a year ago, we tried a failed upgrade to 6.10 and had to roll back due to configuration upgrade issues. Perhaps there was something in your old configuration that did not properly upgrade to 6.11.

    We have built a new, clean configuration for ClearPass and will soon start moving to 6.12.x to gain improved Entra ID authorization.

    Just sharing our personal journey in case it is helpful.



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 10.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted 3 days ago

    Hi

    We have got the information from TAC that they have found a bug and is working on a fix. Bug track ID CP-52622.

    The fix hasn´t been deliviered yet, and we have postponed the patching to 6.11.7 on our C3010 servers.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 11.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted 3 days ago

    Hi,

    sounds great.
    But it sounds like that you haven't problems with 6.11 prior 7?

    I got following errors in the log files:

    kernel - - - [3099117.704404] radiusd[4047577]: segfault at 5b8 ip 00007f9036bbbe9d sp 00007f901cff4710 error 4 in libcrypto.so.1.1.1k[7f9036a43000+2b6000]
    kernel - - - [3099117.704418] Code: 00 00 bf 0f 00 00 00 48 8d 0d 76 27 0d 00 e8 2a 19 fe ff 31 c0 eb 8e 66 0f 1f 44 00 00 f3 0f 1e fa 55 53 48 89 fb 48 83 ec 08 <48> 8b 3f 48 85 ff 74 1b 89 f5 e8 94 45 07 00 39 c5 7d 10 48 8b 3b
    ernel - - - radiusd[4047577]: segfault at 5b8 ip 00007f9036bbbe9d sp 00007f901cff4710 error 4 in libcrypto.so.1.1.1k[7f9036a43000+2b6000]
    kernel - - - Code: 00 00 bf 0f 00 00 00 48 8d 0d 76 27 0d 00 e8 2a 19 fe ff 31 c0 eb 8e 66 0f 1f 44 00 00 f3 0f 1e fa 55 53 48 89 fb 48 83 ec 08 <48> 8b 3f 48 85 ff 74 1b 89 f5 e8 94 45 07 00 39 c5 7d 10 48 8b 3b
    systemd 1 - - cpass-radius-server.service: Main process exited, code=killed, status=11/SEGV
    systemd 1 - - cpass-radius-server.service: Failed with result 'signal'

    And TAC didn't see any problems... well... lol

    Edit: We did a rollback to 6.11.1 and the radius service has no problems, everything is working fine.

    6.11.6 the problems begin.

    So we stay at 6.11.1 and wait for a new update.

    Edit 2:

    We did some tests.

    Upgraded to 6.11.6, Problem is back. Rollback to 6.11.1, everything is fine.

    Now upgraded to 6.11.5, everything is fine.

    So the problem comes with 6.11.6

    Regard
    Ralph




  • 12.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    MVP
    Posted 3 days ago

    Is this bug present in 6.12.1?

    We are getting ready to deploy our C3000 & C3010 servers on 6.11 ISO & then to 6.12.1.



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 13.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted 2 days ago

    I haven't got any information if the issue is present in 6.12 or not, nor if it's just related to C1000 or all hardware and virtual platforms



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------