Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Teap and Received error TLV from client

This thread has been viewed 20 times
  • 1.  Teap and Received error TLV from client

    Posted Mar 29, 2023 11:04 AM

    Hi,

    I'm testing SCEPMan and an Azure/Intune only device.

    I'm using TEAP for the method with a modified EAP-TLS that doesn't check for authorization as it's just pulling from the Endpoint Repo and Intune extension

    Though I've only configured machine authentication atm (is that ok?)

    The only error I'm getting now is "teap: Received error tlv 2002 from client"

    Would anyone have suggestions on this? I am assuming it's cert related but the client machine has the client cert and trusted root cert from SCEPMan. The root cert from SCEPMan was added to Clearpass



  • 2.  RE: Teap and Received error TLV from client

    EMPLOYEE
    Posted Apr 03, 2023 09:43 AM

    From the RFC

    2002  Unexpected TLVs Exchanged

    What type and version is your Client?
    What is the ClearPass version?
    Does the same certificate work with EAP-TLS?



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: Teap and Received error TLV from client

    Posted Apr 03, 2023 09:52 AM

    Hi Herman,

    This was just to test an Azure/Intune only device, so I ended up adding PEAP (with EAP-TLS as the inner method) to my existing wired service which was just EAP-TLS.

    I changed the client to use PEAP and same certificates and it worked fine. 

    I'll revisit TEAP again some other time. Thanks for your response.