Security

 View Only
  • 1.  EAP-TEAP (Search failed due to bad filter) Clearpass

    Posted 17 days ago

    Hi,

    I have created a EAP-TEAP service  on Clearpass, but in the access Tracker I see Timeout Error and failed due to bad filter, how to fix this Problem?



  • 2.  RE: EAP-TEAP (Search failed due to bad filter) Clearpass

    Posted 11 days ago

    Please open a TAC case.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: EAP-TEAP (Search failed due to bad filter) Clearpass

    Posted 6 days ago

    That alert is your AD authentication source rejecting the LDAP query, not RADIUS. TEAP hands the auth source identities a user-only filter chokes on: host/name for machine auth, and the machine account ends in a dollar sign. Check the Input tab in Access Tracker for the exact identity that failed, then the filter on the auth source, and make sure the search base includes Computers.

    Also post your version. 6.14 has a confirmed defect where the dollar sign breaks filter escaping, patch pending. If you're on 6.14 and it's the machine identity failing, it's probably the bug, not your filter.



    ------------------------------
    Dustin Burns

    Lead Mobility Engineer @Worldcom Exchange, Inc.

    ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022-2023
    If my post was useful accept solution and/or give kudos
    ------------------------------