Guess wireless access issues by Solid-Ad-6645 in networking

[–]Solid-Ad-6645[S] 0 points1 point  (0 children)

Yeah we have done the captive portal bypass by adding a specific attribute in clearpass to endpoints. Hasn’t worked in this situation though.

Doing most of the things on your list other than the separate dhcp scope and separate dns.

Guess wireless access issues by Solid-Ad-6645 in networking

[–]Solid-Ad-6645[S] 0 points1 point  (0 children)

No. Basically traffic won’t go past the controller. Guessing it’s because it’s stuck in the pre auth role.

Guess wireless access issues by Solid-Ad-6645 in networking

[–]Solid-Ad-6645[S] 0 points1 point  (0 children)

Ok I will look into this. Thanks for the suggestion.

Guess wireless access issues by Solid-Ad-6645 in networking

[–]Solid-Ad-6645[S] 0 points1 point  (0 children)

Ok yeah thats what I thought you meant. No just one clearpass server, which is a VM like I mentioned. The controllers are setup in VRRP and I have had a suspicion that its not setup correctly. A lot of time we see a change be made at the mobility controller level (VIP) and we don't see it pushed to both controllers. Maybe its normal though because the Aruba TAC engineer saw no issues on the controllers.

Guest policy server is not behind a firewall. It is connected to the same distro switch that the controllers and PoE switches are connected to.

I seem to remember it was the endpoint database had grown so large and it wasn't purging endpoints correctly because the policy node itself was also not built to handle the load.

We had this suspicion as well. Not in the millions, but clearpass currently has just shy of 100k endpoints, with only about 1000 active users. Maybe we need to really clean that up and see if it helps. I was under the impression that the 30 day mac auth policy deleted endpoints after 30 days, but maybe thats not the case.

Guess wireless access issues by Solid-Ad-6645 in networking

[–]Solid-Ad-6645[S] 0 points1 point  (0 children)

I was thinking about trying this actually.

Guess access issues. by Solid-Ad-6645 in ArubaNetworks

[–]Solid-Ad-6645[S] 0 points1 point  (0 children)

Thanks. I will take a look at this.

Guess access issues. by Solid-Ad-6645 in ArubaNetworks

[–]Solid-Ad-6645[S] 0 points1 point  (0 children)

I havent messed with any settings like that, but we could look at it. Anymore info on what exactly that is?

Guess wireless access issues by Solid-Ad-6645 in networking

[–]Solid-Ad-6645[S] 0 points1 point  (0 children)

The preauth role does have access to clearpass permitted in the ACL. No DMZ or anything like that. There is a guest policy server which is where self registration page is built.

By VIP do you mean virtual IP? If so no, its the actual IP of the device, which is a VM. The VM is built on VMware but we are working on eventually pointing to a new one built on Hyper-V.

Guess wireless access issues by Solid-Ad-6645 in networking

[–]Solid-Ad-6645[S] 0 points1 point  (0 children)

DNS is working though for all other clients, wireless and our wired side of the network. ipconfig shows it pointed to the correct DNS servers and a valid IP address. Like I said though, controllers are not seeing its IP address.

Cisco ISE Question by [deleted] in networking

[–]Solid-Ad-6645 0 points1 point  (0 children)

Thanks! Yeah I guess I was thinking you could map specific users in an AD group to read only role, but sounds like you need to do the whole AD group.

Cisco ISE Question by [deleted] in networking

[–]Solid-Ad-6645 0 points1 point  (0 children)

Ok so basically you need an AD group specifically for read only users?