Security

 View Only
Expand all | Collapse all

CPPM Access licenses for Roaming eduroam users

This thread has been viewed 37 times
  • 1.  CPPM Access licenses for Roaming eduroam users

    Posted Mar 04, 2026 07:10 AM

    We have just migrated our eduroam authentication to ClearPass and have noticed that we have way too many licenses being used up by Roaming users i.e. users from our institution who are on other eduroam sites, authenticating back to us via the National Proxies.

    The roaming authentications are one-off RADIUS authentications: the users don't show up on Insight, don't get assigned roles, no RADIUS Accounting etc. they just get accepted or denied.

    My first thought was should these authentications be tying up an Access license anyway?  But if they should, is there a way to prune the licenses for these more frequently?  We get re-authentications for the same user quite often, presumably as they roam or as their device goes to sleep and wakes up, but judging by the numbers, it appears to be using up yet another license every time they re-authenticate.

    Thanks in advance



    -------------------------------------------


  • 2.  RE: CPPM Access licenses for Roaming eduroam users

    Posted Mar 04, 2026 10:08 AM

    Yes a RADIUS session = Access license consumed. Make sure you have RADIUS accounting properly configured on your NADs.

    -------------------------------------------



  • 3.  RE: CPPM Access licenses for Roaming eduroam users

    Posted Mar 04, 2026 11:08 AM

    Thanks, unfortunately with proxied RADIUS we have no control over the authentication server so cannot get RADIUS accounting turned on, let along properly configured!  It's fine for our local users.

    I was hoping that CPPM could be configured to either realise that two authentication requests for the same username, and device MAC address are the same session so would consume only one license, or as users regularly re-authenticate because of roaming, we could set a low timeout for these proxied sessions?

    -------------------------------------------



  • 4.  RE: CPPM Access licenses for Roaming eduroam users

    Posted Mar 04, 2026 11:49 AM

    Yeah I don't play in the EDUROAM space so I'm not sure how exactly this is "supposed" to work. But from the ClearPass licensing point of view it's all based on active sessions, those are reliably released/consumed via RADIUS accounting messages.

    -------------------------------------------



  • 5.  RE: CPPM Access licenses for Roaming eduroam users

    Posted Mar 04, 2026 05:44 PM

    ClearPass does do that, the license is consumed based on the MAC address of the device.  If Accounting isn't in place, then you'll see that license count as used for 24 hours.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 6.  RE: CPPM Access licenses for Roaming eduroam users

    Posted Mar 05, 2026 05:34 AM

    Thanks chulcher,

    JTo clarify, does that mean if the same MAC address makes multiple authentications in 24 hours they would only consume one license?  If so, our stats don't bear that out, or we have other devices using up licenses we are not aware of.

    Is there any way to interrogate CPPM to extract details of the license usage, to see which MAC addresses are assigned to licenses?

    Thanks




  • 7.  RE: CPPM Access licenses for Roaming eduroam users

    Posted Mar 05, 2026 09:32 AM

    That should be the case, yes.  If you believe that you're seeing otherwise, then I'd recommend opening a case with TAC to help you determine where the discrepancy lies.

    Is the license consumption causing an operational issue at this point?



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 8.  RE: CPPM Access licenses for Roaming eduroam users

    Posted Mar 05, 2026 10:11 AM

    I will do that as the number of licenses used is at least 1,000-1,500 higher than I would expect if it were only assignng one license per MAC.  We don't have a critical problem as we have enough spare licenses at the moment, but I will raise a TAC case as you suggest, to look further into it.

    Thanks again for clarifying how it should work

    -------------------------------------------



  • 9.  RE: CPPM Access licenses for Roaming eduroam users
    Best Answer

    Posted Mar 06, 2026 08:36 AM

    David, this is probably expected. All RADIUS authentications that run through ClearPass will consume a license counted against the unique MAC address for 24 hour, unless via accounting ClearPass learns that the session has been terminated. In an eduroam environment, where you don't have accounting, or don't control accounting this may require that you need more licenses than you would need in the case accounting would be implemented.

    What typically helps is the Licensing dashboard and Licensing report in ClearPass Insight:

    If you need to know which clients are consuming those licenses, you can create a Licensing Report:

    When you run the report, the time interval is not relevant as it is a report on the time you run it, you will get a zip file with in it a CSV containing all authentications counting against the licenses (obfuscated MAC&Username to protect the innocent):

    This report helped me multiple times to better understand why you see the numbers that you see.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 10.  RE: CPPM Access licenses for Roaming eduroam users

    Posted Mar 06, 2026 09:36 AM

    Thank you Herman, I wasn't aware I could get the detail from Insight so that's really useful.  Coupling that with other authentication reports, I have been able to check the data now and I can see that I do simpy have more users roaming on remote sites than I ever expected.

    Thanks to all for your help and constructive comments.

    -------------------------------------------



  • 11.  RE: CPPM Access licenses for Roaming eduroam users

    Posted Mar 06, 2026 10:07 AM

    David, on the 'more roaming user than expected', I've seen that with universities that are on a campus with other institutes that use eduroam, or on a busy location as a train station. Users connect, and pretty fast after that disconnect when they move out of the range again. I'd say if you configure accounting for those controllers/APs, the licenses for those users should be released quickly, and not cause any issues. At least now you have the data to work further on...



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------