Security

 View Only
  • 1.  RADIUS Accounting when in initial-role

    Posted Oct 12, 2023 06:56 AM

    Hi,

    2930 switches WC.15.11.14

    cppm 6.11.4

    Implementing mac/8021.x auth on a switch port. Cppm configured to use DURs as appropriate for state of authentication. 2 services on cppm one  running in monitor mode, the othe live. Service selection  based upon device groups .

    For switches using the cppm monitor mode  service ( when configured to download user roles) a sh port-access clients shows that every port is in  the defined initial-role. which  allows network access via the statically defined   VLAN.  reauth happens every session timeout. period. However I get NO accounting data appearing at the cppm server. looking at the switch it also shows that thre are no in/out accounting packets.

    For switches using the live service, cppm sends a DUR to the client and everything works as expected including  accounting information

    Should i be able to send accounting packets when  in the initial-role ? Is there a specific entry in the local user role I need to add to enable sending of accounting imnformation?

    A



  • 2.  RE: RADIUS Accounting when in initial-role

    Posted Oct 16, 2023 04:40 AM

    For accounting, the (or an) authentication should succeed. For the devices in the initial role, do you see a successful authentication (802.1X or MAC Auth)?



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 3.  RE: RADIUS Accounting when in initial-role

    Posted Oct 16, 2023 06:12 AM
    The switches talk to a ClearPass service in monitor mode but yes can see a successful auth. Assuming here that Cppm sends just an access accept in monitor mode without any other params
    A




  • 4.  RE: RADIUS Accounting when in initial-role

    Posted Oct 17, 2023 09:05 AM

    And on the switch 'show port-access clients' or 'show port-access clients <port> detail', does that show a successful authenticated client?

    If a client is authenticated, and no role is returned so the client stays in the initial role, I would expect accounting (because the client is authenticated). If you don't see, you may best work with TAC to find out why there is no accounting data sent.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: RADIUS Accounting when in initial-role

    Posted Oct 17, 2023 09:47 AM
    Ok so show port-access client detail 1/3 shows that the auth type is , Mac-authenticated and the client status is initial-role
    Cppm access tracker shows Mac address on that port hitting monitor mode process which would send back an access accept
    A




  • 6.  RE: RADIUS Accounting when in initial-role

    Posted Oct 20, 2023 10:39 AM

    Then you may best work with TAC to find out why there is no accounting data sent.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------