04-11-2024 04:05 AM
We have implemented a wireless network integrated with remote RADIUS authentication using Cisco ISE. To gain network access, a user's device posture needs to be compliant and the user must exist in the Active Directory identity store. However, after successful authentication and posturing, the network connection is disconnecting unexpectedly. We'd appreciate it if anyone has experience with this issue.
04-11-2024 04:27 AM
How do you have CoA configured? What is the auth method? What exactly is the Aruba NAD? IAP? Central? Mobility Controller? Are you performing redirection-based posture?
https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356
04-11-2024 05:19 AM
Thank you for quick response
04-11-2024 05:27 AM - edited 04-11-2024 05:28 AM
What port is CoA set to? I would highly suggest not using the built-in Aruba Wireless NAD profile and use this one: https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904
Why is PEAP being used? Why not EAP-TLS or TEAP? With certificates?
How are you handling the redirect page on Aruba? Static? Again reference the link I posted above for a dynamic way to handle this instead.
Since you are using Instant AP mode is the cluster healthy? Do you have RADIUS proxy enabled? Or is each AP defined as a NAD within ISE? Any reason not to use Aruba Central management instead?
04-12-2024 12:47 AM
04-12-2024 05:18 AM
"not receiving the redirection link"? What do you mean? How have you confirmed this? What do the ISE live logs look like? Did you follow the other steps as needed in the link I posted?
04-15-2024 12:38 AM
04-15-2024 05:17 AM
Did you update the authorization rule accordingly to use the autogenerated PSN URL instead of whatever Static URL you had it set to?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide