Hi community,
i am new here and if this is not appropriate forum please let me know.
I am facing a little "cosmetic" issue in our clearpass/wlc setup.
Let me introduce - we have 2 CP, 2 WLC7210 managed by vWMM. Our clients are mostly wired clients connected to 2930F in tunneled node mode.
I configured policy that authenticate endpoints using 802.1X and role assigned to endpoint depends if there is successful host or user authentication (it is little bit simplified but its like that).
Now, I have a policy that windows clients they start with PEAP authentication using machine or username.
I can see on clearpass, that the process of authentication is like this:
1. Machine boots up and authenticate itself as machine - 29.10. 7:15
2. User logs in and authenticate himself as user mobu2 - 29.10. 7:16
3. User logs out and machine authenticate itself as machine - no happened right now
When endpoint is authenticated as machine, it receive role DomainPC via DUR enforcement profile.
When endpoint is authenticated as user, he receive role Employee via DUR enforcement profile.
All is working fine as far as I can say - the roles are assigned correctly and policies are enforced on WLC also correctly. The issue is, what is displayed in WLC GUI, resp. in CLI user table.
I can see the endpoint has correctly assinged role of Employee, but authentication field is still filled with machine authentication username. Bellow is screenshot from WLC clients page ( btw, the same is visible in airwave, and the same is in CLI show user-table)
This is scenario for appx 90% of endpoint of this type. Rest of the clients are displayed correctly as user authenticated and with correct role:
And also when user do not logs in - i can see that such computers are correctly displayed as machine authenticated with DomainPC role:
I am worrying about that because it is confusing for helpesk operators and it is definitely not correctly displayed info.
Does something like this happened also to you? Is this some kind of bug, or am I missing some configuration?
Just for info: Clearpass 6.8.5, WLC 8.6.0.4
Thanks a lot for
Tomas
------------------------------
Tomas Backo
------------------------------