Can you share your policy and access tracker results? Alternatively, it may be good to work with your partner or Aruba support to interactively troubleshoot your service and policy. There is not enough information in your requests and all efforts above are just based on guessing what is the situation, while in many of these cases the solution is in a small detail.
If you don't have an IP helper in the Guest VLAN, an automatic CoA will not be triggered as there will not get in new profiling data.
If unknown/unprofiled devices end up in the Guest VLAN, make sure you have an ip-helper or dhcp relay configured towards your ClearPass for that subnet.
If your endpoint has already the correct details, like device type/name, you should check your enforcement policy why it is not sending out the correct enforcement profile.
The Wired Policy Enforcement guide, as available from
https://www.arubanetworks.com/clearpassdocs would provide guidance as well. It is for different switches, so the actual enforcement may be slightly different, but workflows are very similar.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC.
------------------------------
Original Message:
Sent: Dec 03, 2020 10:27 AM
From: Thomas Willems
Subject: Clearpass profiling issue
Herman,
You are correct, just Guest VLAN, not captive portal (isn't configured).
The GUEST VLAN doesn't have any DHCP IP helper, but if I check the MAC in the endpoint database, the right attributes are present.
I don't see any automatic COA.
I can trigger an manual COA, but that doesn't do the trick either.
------------------------------
Thomas Willems
------------------------------
Original Message:
Sent: Dec 03, 2020 10:07 AM
From: Herman Robers
Subject: Clearpass profiling issue
If I summarize correctly:
- client connects to wired port
- MAC auth is happening with Profiling option in the service is enabled
- because it is unknown the enforcement will be the Guest VLAN and a captive portal redirect
At that point, do you get profiling information in? Does Access tracker show the device type next to the client MAC?
Is DHCP ip helper configured from the Guest VLAN?
You don't see an automatic CoA when new profiling data comes it?
Do you see the CoA tab in Access Tracker? That should appear if a CoA is triggered, by profiler or something else.
In this situation, you can successfully trigger a manual CoA?
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC.
Original Message:
Sent: Dec 02, 2020 04:20 PM
From: Thomas Willems
Subject: Clearpass profiling issue
Hi Danny,
The profiler and COA part is in my opinion part of the same solution.
The workflow is that a new device authenticate to CP, gets COA & is profiled. Second auth works on endpoint database authentication.
The device doesn't get to the profiling part of the service. It gets the default action which is the GUEST vlan. The service is just a default wires MAC auth.
Regards,
------------------------------
Thomas Willems
Original Message:
Sent: Dec 02, 2020 01:40 PM
From: Danny Jump
Subject: Clearpass profiling issue
So you've completely pivoted from profiling to a Dynamix-AuthZ question, please be clear about the assistance you want from the community please.
Can you confirm if the switch is correctly forwarding DHCP messages {DIscover/Offer} to CPPM, it will use specifically DHCP Options 55 {from client} & 60 {from server} to determine the type of endpoint.
If manual CoA is working in AT but not in your policy, that points to a policy config.
------------------------------
Danny Jump
"Passionate about CPPM"