And on the switch 'show port-access clients' or 'show port-access clients <port> detail', does that show a successful authenticated client?
If a client is authenticated, and no role is returned so the client stays in the initial role, I would expect accounting (because the client is authenticated). If you don't see, you may best work with TAC to find out why there is no accounting data sent.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Oct 16, 2023 06:11 AM
From: alexs-nd
Subject: RADIUS Accounting when in initial-role
The switches talk to a ClearPass service in monitor mode but yes can see a successful auth. Assuming here that Cppm sends just an access accept in monitor mode without any other params
A
Original Message:
Sent: 10/16/2023 4:40:00 AM
From: Herman Robers
Subject: RE: RADIUS Accounting when in initial-role
For accounting, the (or an) authentication should succeed. For the devices in the initial role, do you see a successful authentication (802.1X or MAC Auth)?
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: Oct 12, 2023 06:55 AM
From: alexs-nd
Subject: RADIUS Accounting when in initial-role
Hi,
2930 switches WC.15.11.14
cppm 6.11.4
Implementing mac/8021.x auth on a switch port. Cppm configured to use DURs as appropriate for state of authentication. 2 services on cppm one running in monitor mode, the othe live. Service selection based upon device groups .
For switches using the cppm monitor mode service ( when configured to download user roles) a sh port-access clients shows that every port is in the defined initial-role. which allows network access via the statically defined VLAN. reauth happens every session timeout. period. However I get NO accounting data appearing at the cppm server. looking at the switch it also shows that thre are no in/out accounting packets.
For switches using the live service, cppm sends a DUR to the client and everything works as expected including accounting information
Should i be able to send accounting packets when in the initial-role ? Is there a specific entry in the local user role I need to add to enable sending of accounting imnformation?
A