Controllerless Networks

 View Only
last person joined: 19 hours ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

roaming issue with Captive Portal

This thread has been viewed 58 times
  • 1.  roaming issue with Captive Portal

    Posted Aug 01, 2022 01:39 PM

    Hi Guys, i have IAP-VPN setup with captive portal to an ISE server.
    I have a roaming issue where everytime a client roams, captive portal server always ask for relogin.

    i'm trying to tshoot on IAP side, roaming seems fine but however fine the roaming is, captive portal always ask for relogin.

    other ssid with other security setup has no problem.


    PS: I follow the configuration from this link:

    How To: Cisco ISE Captive Portals with Aruba Wireless

    it has weird setup with employee ssid + MAB but it the only way that it could work.



  • 2.  RE: roaming issue with Captive Portal

    EMPLOYEE
    Posted Aug 01, 2022 01:50 PM
    Are both IAPs in the same cluster?

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 3.  RE: roaming issue with Captive Portal

    Posted Aug 01, 2022 05:03 PM
    Hi Collin, yes they are with radius dynamic proxy on. They have Aruba GRE per-ap tunnel to tunnel the vlan to the controller.


  • 4.  RE: roaming issue with Captive Portal

    EMPLOYEE
    Posted Aug 01, 2022 05:07 PM
    You said dynamic radius proxy and mab, but also captive portal.  What is the workflow for that SSID?

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    HPE Design and Deploy Guides: https://community.arubanetworks.com/support/migrated-knowledge-base?attachments=&communitykey=dcc83c62-1a3a-4dd8-94dc-92968ea6fff1&pageindex=0&pagesize=12&search=&sort=most_recent&viewtype=card
    ------------------------------



  • 5.  RE: roaming issue with Captive Portal

    Posted Aug 01, 2022 05:15 PM
    I tried to use guest ssid with captive portal like i used to but that doesnt seem to work with ISE. Some Cisco forum in the link i attached has this setup with employee ssid. The MAB seems to only trigger the ssid to have captive portal enable in the employee ssid.


  • 6.  RE: roaming issue with Captive Portal

    Posted Aug 02, 2022 02:05 AM
    Hi Collin,
    seems like after roaming, the roamed user got its role changed back to the pre-auth role.
    what might causing this?


  • 7.  RE: roaming issue with Captive Portal
    Best Answer

    EMPLOYEE
    Posted Aug 02, 2022 03:37 AM
    It seems that your MAB (what we call MAC Caching in ClearPass) does not work properly. I'm not an ISE expert, but from what I read in the documentation is the workflow quite similar to ClearPass:
    - Client connects, goes through MAC authentication and is 'unknown' or does not belong to the GuestEndpoints group and gets in the pre-auth role to get redirected to the captive portal.
    - Client goes through the captive portal authentication, on successful authentication the client MAC address is added to the GuestEndpoints group.
    - When a client roams, new MAC auth happens, at that time because the client MAC address is now part of the group, the normal guest access (no captive portal) is returned.

    Please check if the client is added to that GuestEnpoint group; if not, check in the captive portal part why it isn't and fix that.
    If it is, check why the MAC auth doesn't return the guest role. For that, be aware that roles are case-sensitive in Aruba WLAN, and that if the returned role does not exist on the AP/controller, the default role will be applied... which likely is the one with redirects.

    You may check this video on how the guest + captive portal + mac caching workflow is supposed to work, where it uses ClearPass, but the steps should be similar with ISE.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 8.  RE: roaming issue with Captive Portal

    Posted Aug 02, 2022 06:29 AM
    Hi Herman,

    i have used MAB in clearpass, i understand the flow.
    so my problem now is why everytime a user roams, the IAP always trigger MAB? that's not supposed to happen right?


  • 9.  RE: roaming issue with Captive Portal

    EMPLOYEE
    Posted Aug 02, 2022 06:47 AM
    I wonder if you have enabled "dynamic radius proxy" on the VC


    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 10.  RE: roaming issue with Captive Portal

    Posted Aug 02, 2022 06:57 AM
    yes i have.

    all authentication has been proxied to the VC.


  • 11.  RE: roaming issue with Captive Portal

    EMPLOYEE
    Posted Aug 02, 2022 08:04 AM
    Yes, on every roam with IAP, I would expect a (MAC) authentication.

    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 12.  RE: roaming issue with Captive Portal

    Posted Aug 02, 2022 08:59 AM
    Is it possible to skip mac auth like okc in dot1x?


  • 13.  RE: roaming issue with Captive Portal

    Posted Feb 10, 2023 04:51 AM

    I don't know if it's an issue but i have the same things, each time the client roam, a mac auth is sent to clearpass. It consuming a lot of ressource from server side 




  • 14.  RE: roaming issue with Captive Portal

    Posted Feb 22, 2024 12:04 PM

    Hello,

    How did you manage to solve this?

    I have a similar scenario, Internal Captive portal in Aruba Central + External Radius server (Macmon) and my guest SSID is always asking for credentials when the roaming happens.

    Strange thing is, we have some other solutions with another WLAN vendor but same Radius solution and this doesn't happen, even if there are roaming events, there are never MAC auth req received on the server, so something is handled differently there, I am wondering why this cannot be done in Aruba?

    Aruba TAC is pointing me to the Radius server, but honestly, I have my doubts, since the 1st authentication is successful, and they are saying the MAC address should be stored somewhere in the Radius server, but then, what happens with security? If i bring another device and use a "MAC spoofing" method, it would be able to join the network without providing username/password... So, there should be another way around... PLEASE HELP!!