Controllerless Networks

 View Only
Expand all | Collapse all

Cloud Authentication - RADIUS not configured?

This thread has been viewed 47 times
  • 1.  Cloud Authentication - RADIUS not configured?

    Posted Feb 15, 2022 08:43 AM
    Hello,

    Any help with this would be greatly appreciated. I have an open ticket with Aruba support but we're not getting anywhere and it's been months so far...

    I have Instant APs (AP-515) with Aruba Central. 

    Whatever I try I cannot get client computers to authenticate.

    Setup in brief is: (Hybrid on-prem Domain, Azure AD Connect) Cloud Authentication to connect to the SSID. WPA3, Enterprise, Cloud Auth

    Errors are always RADIUS related. e.g. 802.1x Radius Reject received for client ac:etc on BSSID cc:etc on channel 52E of AP hostname cc:etc. Reason: Rejected from radius server

    The summary for the SSID config shows internal auth for client so I'm wondering if under System, Administration Client Configuration should be changed from Internal to RADIUS?

    I do not have internal RADIUS server. I assumed that using Cloud Authentication that role would be via Aruba Central or Azure somehow.

    Ignorance on my part here...

    Thank you,
    Leo.


    ------------------------------
    Leo Pickford
    ------------------------------


  • 2.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 15, 2022 05:21 PM
    no you don't need a RADIUS server, you need to select "CloudAuth" as your authentication server


    https://help.central.arubanetworks.com/2.5.4/documentation/online_help/content/nms/access-points/cfg/networks/cfg-ca-wlan.htm

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba.
    ------------------------------



  • 3.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 16, 2022 07:40 AM
    Hello,

    Thanks for your reply. 

    I had been testing with the configuration you suggest for months but with no joy. 
    Looked through the document reference and it's setup as I think it suggests. 
    I did try changing the 'Role' from Unrestricted to 'Role Based' but it's made no difference.

    Errors continue to be:

    Client 802.1x Radius Reject and Client EAP Failure

    When trying to connect to the SSID I'm using Windows Credentials, Certificate but get the same issue.
    The client computer has then enrollment certificate installed.

    Tested using different hardware and same issue. 

    I'm at a loss. It seems to be a cred mismatch somewhere along the lines. The client computer isn't getting past the first step of authentication...




    ------------------------------
    Leo Pickford
    ------------------------------



  • 4.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 17, 2022 08:47 AM
    You said you have a "hybrid on-prem domain" - is there a Microsoft RADIUS Server (a domain server with the NPS role) on the same site as the APs?

    ------------------------------
    Miguel Goncalves
    ------------------------------



  • 5.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 17, 2022 09:24 AM
    Hello,

    Thank you for your message.

    No there is not. Just checked the PDC and other DCs on-prem. Network Policy and Access Service role is not installed on our Windows Server 2021 R2 domain controllers.

    Haven't got anywhere with pcap via Wireshark to fathom the problem so I've deleted the Aruba Central configuration for CloudAuth and corresponding SSIDs config.

    Tested a new SSID with simple security and all clients connect so the IAP and related infrastructure appears to be fine.

    When our client computers connect they show as NameNumberlocalaplbdom

    I wouldn't be surprised (albeit a total guess) that there is some kind of mismatch between our domain computers, azure and the Aruba onboarding certificate. That and we actually do need some kind of RADIUS server on-prem but what do i know.


    ------------------------------
    Leo Pickford
    ------------------------------



  • 6.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 17, 2022 11:13 AM
    Hi Leo,

    The NPS role doesn't necessarily run on a Domain Controller. Any member server can have it.

    ------------------------------
    Miguel Goncalves
    ------------------------------



  • 7.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 17, 2022 11:40 AM
    Hi Miguel,

    Ok understood. 
    So do you think NPS is a requirement for Cloud Auth? and would explain why I keep getting Client MAC Authentication Reject?

    Thank you so much,
    Leo.

    ------------------------------
    Leo Pickford
    ------------------------------



  • 8.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 17, 2022 11:58 AM
    Well, I'm pretty sure you need a RADIUS authenticator somewhere, whether on cloud or on premises. If you have a hybrid Microsoft deployment - your words! - you could already have a NPS on site.

    The question is: what do you have configured as authentication servers on your WLAN?

    ------------------------------
    Miguel Goncalves
    ------------------------------



  • 9.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 17, 2022 01:24 PM
    Interesting thank you.
    I'm now testing with a new WLAN config which is using MAC Authentication, Primary server: Cloud Auth

    Clients error on connecting, wont get past MAC authentication

    I've asked Aruba support to confirm where the MAC addresses for said clients need to be. I think it's Global, Security, Authentication, etc

    ------------------------------
    Leo Pickford
    ------------------------------



  • 10.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 17, 2022 02:17 PM
    Ah, I see... and have you followed the workflow for cloud authentication? See:

    https://help.central.arubanetworks.com/2.5.4/documentation/online_help/content/nms/policy/prov-clients-wireless.htm

    ------------------------------
    Miguel Goncalves
    ------------------------------



  • 11.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 18, 2022 05:48 AM
    Hey Miguel and good morning :)

    Yeah I followed that from the beginning....

    I got way too excited when I first saw Cloud Onboarding, in that I could onboard clients without needing to do anything woohoo!!!

    It all seemed straightforward for setup.

    Add the client MAC addresses, as per screen shot example:

    Connect up Azure AD and link with SSID
    (I'm selecting a AD group object (originated from AD on-prem) containing corporate devices)

    The Onboarding App seems equally straightforward. I've installed, profile added, authenticated via Microsoft creds and certificate installed.


    Prerequisites for Onboarding states:
    On Windows devices, ensure that the Wi-Fi adapter is enabled to install the network profiles and connect to the network.

    1. I don't fully understand how you'd check the adapter is enabled for network profiles.

    • 2. Perhaps the Azure API graph isn't passing through properly so I'll take another look at that.

    3. Or perhaps the MAC address format in the screen shot isn't correct. I recall a conversation with Aruba status that Address and Name need to be the same as shown.

    ------------------------------
    Leo Pickford
    ------------------------------



  • 12.  RE: Cloud Authentication - RADIUS not configured?

    Posted Feb 18, 2022 09:00 AM
    I think my User Group mapping was wrong, not that its made any difference...

    User Access Policy; User Authentication I had originally set to a AD security group that contained computers only, this now seems like an obvious mistake on my part.

    When I looked at this security group on Azure the group was empty probably because AD Connect isn't synchronising devices.

    Anyhow, I changed this to a User security group which contains Users which on reflection makes more sense.

    Re-tested, Alerts & Events now show:

    Client Roaming Success but Client MAC authentication Reject.

    Radius server 18.159.233.44 for BSSID reject MAC

    So there is still a MAC reject for whatever reason. Whatever format of MAC entered make no difference.





    ------------------------------
    Leo Pickford
    ------------------------------