Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Radius service stops after update to ClearPass 6.11.7 on C1000 machines

This thread has been viewed 30 times
  • 1.  Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Mar 06, 2024 07:07 AM

    Hi

    A customer is running multiple clusters based on C1000 and C3010 hardware servers. During deployment in the lab environments we haven't seen any issues after update to ClearPass 6.11.7. But after deployment in the first production C1000 cluster we see that the Radius service is indicated as Stopped in the Services Control tab on both the servers in the cluster. It's not totally stopped, because some clients get through with authentication, so the impression is that the service is restarting over and over again. No logs in the Event log regarding issues with the Radius service. Only reports from users with authentication issues.

    Has anyone else noticed any strange behavior after update to 6.11.7?

    On other customers running virtual ClearPass server I haven't seen issues with 6.11.7.

    We are currently working with TAC to solve the issue.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------


  • 2.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    EMPLOYEE
    Posted Mar 11, 2024 10:22 AM

    Did you find a root cause and solution for this? Have not seen this myself.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Mar 14, 2024 04:44 AM

    Hi Jonas,

    I had this issue last week also after updating to 6.11.7. One of my authorisation sources was not functioning correctly, even it was not used.

    The radius and tacacs service started but stopped very quickly. 

    After deleting the authz source the services could start. and it al worked again.

    Best regards,

    Erik




  • 4.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Mar 14, 2024 05:08 AM

    Hi Erik

    Interesting, but a bit of special case as your authz source wasn't utilized. In most cases you have references to the authz sources in role mapping or enforcement policies.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 5.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Mar 14, 2024 05:07 AM

    Hi Herman

    No we have not got any root cause from TAC yet. They are still working with the logs.

    We rolled back to the previous version and the function was restored.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 6.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted Mar 14, 2024 05:19 AM

    Hi Jons,

    I my case, rollback did not work, after starting the appliance same issue.

    Yes I tested with some authz sources, but forgot to delete them, but the query was not fully right. Missing a ";"

    Best regards,

    Erik




  • 7.  RE: Radius service stops after update to ClearPass 6.11.7 on C1000 machines

    Posted 21 days ago

    Yep, this matches my own experience.  When doing complex scenarios with custom sources, the UI will sometimes permit syntactically invalid configurations to get built for the underlying RADIUS server daemon.  In my case it was something silly (setting Entrata as an authn source instead of authz.)