Security

 View Only
  • 1.  RADIUS CoA ClearPass/ AOS8 controller issues

    Posted May 23, 2025 11:42 AM

    Getting the following errors when attempting a CoA from ClearPass -> Aruba Controller. ClearPass appears to send the disconnect request but no disconnect acknowledgement in response.

    A screenshot of a computer

AI-generated content may be incorrect.

    When attempting manually – the following appears 'no response from network device'. Attempted multiple Aruba wireless CoA profiles. 

    A screenshot of a computer

AI-generated content may be incorrect.

    I can see in a pcap that the CoA disconnect appears to be happening but get 'destination unreachable (port unreachable)' between controller and ClearPass. Controller = 192.168.41.245 (MM) and ClearPass = 192.168.41.250. 

    A screenshot of a computer

AI-generated content may be incorrect.

    I have the RFC 3576 server specified in the AAA profile on the controller:

    A screenshot of a computer program

AI-generated content may be incorrect.

    Here is the RFC 3576 server settings:

    A screenshot of a computer

AI-generated content may be incorrect.

    I have even created ACLs in the user roles for UDP 3799 permit from controller (MM) and controller (MC) to and from ClearPass.

    A black screen with white text

AI-generated content may be incorrect.

    Vendor name Aruba and port 3799 enabled in ClearPass devices for MM and MC.

    A screenshot of a computer

AI-generated content may be incorrect.

    Even created a firewall policy on the contoller MM and MC to permit UDP 3799. Not sure why there are hits on the policy, which is slightly confusing considering I'm testing a single client.

    A screenshot of a computer

AI-generated content may be incorrect.

    A screenshot of a computer screen

AI-generated content may be incorrect.

    I have been through the FW settings numerous times with the customer and it appears that everything is open and permit all is in place. 

    Anything obvious missing? 



  • 2.  RE: RADIUS CoA ClearPass/ AOS8 controller issues

    Posted May 23, 2025 11:55 AM
    Edited by shpat May 23, 2025 12:01 PM

    Try to change the format of the MAC Address - Calling-Station-ID Settings under the AAA configuration in the controller.
    I think that the controller does not understand the format without Colon, so when you send a COA, it will return the error you are seeing because that mac does not exist. It is expecting the message to be xx:xx:xx:xx:xx:xx

    Maybe this post would be helpful. 



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 3.  RE: RADIUS CoA ClearPass/ AOS8 controller issues

    Posted Jun 10, 2025 05:51 PM

    @shpat thanks for that. After select the MAC address delimiter to include the colon as suggested above, it doesn't appear to have made a difference. Still 'no response from network device'. Although, the MAC shown below does now appear to include the colon delimiter. Also attempted selecting the lower case option, but I don't think the controller would care about this? Any more thoughts? 




  • 4.  RE: RADIUS CoA ClearPass/ AOS8 controller issues

    Posted Jun 10, 2025 08:32 PM

    Just out of curiosity, is the NAS IP on the controller configured with the IP of the controller on the Configuration>Authentication>Advance>RADIUS Client> NAS IPV4?

    Also i noticed you said:"...Controller = 192.168.41.245 (MM)" , in Aruba OS 8.x users are Anchored in the Mobility Controllers not on the Mobility Masters. So in this case, you should send a disconnect message to the controller where the User is Anchored. 



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 5.  RE: RADIUS CoA ClearPass/ AOS8 controller issues

    Posted Jun 11, 2025 08:11 AM

    Which design are you using? AOS8 with Mobility Master or standalone controller without Mobility Master?



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 6.  RE: RADIUS CoA ClearPass/ AOS8 controller issues

    Posted Jun 11, 2025 12:27 PM

    Sending the CoA to the MCR isn't going to accomplish anything, the packet has to go to the controller.  If you're running standalone controllers under the MCR then you'll need to configure the RADIUS NAS-IP to be used by the controller as the default used will be that of the MCR.  If you're running a cluster then you'll need to either a) configure the cluster VIP to properly support CoA during failover events or b) configure the RADIUS NAS-IP to send the controller IP instead of MCR.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------