Good afternoon all,
We're dealing with an University owned computer that has authenticated successfully and thus been successfully assigned an Aruba role within our AOS8.10 Controller environment. The role has been configured to deny traffic to a couple of subnets and then allow all. All of that said, I'm seeing traffic from this client to our domain controller getting denied (see datapath output below). Since the role should allow this traffic I'm at a loss as to why it would still get denied.
Client IP = 10.124.35.58
Domain Contoller IP = 10.2.0.63
Second DC IP = 10.2.0.62
---------------------------------------------------------------------------------------------------------------------------------------------------
(MC1) [MDC] *#show datapath session table 10.124.35.58 | include 10.2.0.6
10.124.35.58 10.2.0.63 17 63905 389 0/0 0 0 0 tunnel 6209 9 3 756 FDC 20
10.2.0.63 10.124.35.58 17 389 63905 0/0 0 0 1 tunnel 6209 9 0 0 FDY 20
10.124.35.58 10.2.0.62 6 50458 445 0/0 0 0 1 tunnel 6209 221 68 17214 Ci 20
10.2.0.62 10.124.35.58 6 445 50458 0/0 0 0 1 tunnel 6209 221 64 9636 i 28
10.2.0.62 10.124.35.58 17 389 63907 0/0 0 0 0 tunnel 6209 8 0 0 FDY 20
10.124.35.58 10.2.0.62 17 63907 389 0/0 0 0 0 tunnel 6209 8 3 756 FDC 20
------------------------------
[Matt]
[Director of Infrastructure Services]
------------------------------