Wireless Access

 View Only
  • 1.  MAC Caching not working properly (new central)

    Posted 11 days ago

    Using the new entral for our wireless management, im running into a problem where a user is prompted with a captive portal page even though they have signed in recently, we have "MAC Caching" enabled on the Central NAC authentication profile, with the session limit of 180Days.

    have found someone going through the same thing here:Aruba Central and MAC Caching problem | Wireless Access

    but im not too sure if the randomized MAC address on the client side is the problem as we were able to use the same exact function on classic central.

    if anyone is familiar with this problem, please advice on how to fix, or if this is bug or something



  • 2.  RE: MAC Caching not working properly (new central)

    Posted 13 hours ago

    Before assuming it's a bug, worth proving whether the client hitting the portal is the same MAC that got cached. Randomization is the usual suspect and it isn't ruled out by having worked on Classic, since Windows and iOS both rotate the per-network address on a forget and rejoin, and the two platforms don't necessarily key the cached endpoint the same way.

    After a successful portal login, check the endpoint actually exists in Central NAC and note the MAC. Then when someone gets re-prompted, compare the MAC in the client list against that entry. If they differ you have your answer and the fix is client side, disabling private addresses for that SSID. If they match, then it's the caching itself and worth a TAC case with both records.

    Also check where your 180 day limit is applied. The profile value and the role can disagree, and the shorter one wins.



    ------------------------------
    Dustin Burns

    @Worldcom Exchange, Inc.


    If my post was useful accept solution and/or give kudos
    ------------------------------