09-13-2023 11:54 PM
Hi,
I have a problem with Cisco ISE 2.7 guest access. I can see in live logs that clients have been authenticated correctly but after every successful authentication ISE sending a CoA-request for reauthentication. This is happening every 5 seconds and keeps going forever. In this case we have Cisco ISE acting radius for an Aruba Wireless network.
09-14-2023 05:23 AM
This is expected behavior to make sure the client has access to the network after a successful portal login.
https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-2943876.html
https://community.cisco.com/t5/security-knowledge-base/how-to-cisco-ise-captive-portals-with-aruba-wireless/ta-p/4633904
09-14-2023 06:15 AM
Ok I see,
But we still have problem with clients that constantly being connect and disconnected from the guest wifi every 5-10 second (same time as the CoA-requests). Do you think this is an ISE problem or Aruba problem?
09-14-2023 07:26 AM
Right after they join? Or constantly? I'm possible to say. Are you using the Aruba network device provfile in the article I linked? That NDP is much more modern than the one provided natively in ISE. Is this IAP? Mobility Controller on AOS8.x? Gateway on AOS10? Aruba Central?
09-15-2023 12:07 AM
yes I am using the custom Aruba network profile in ISE, we are using IAP without controller or Aruba Central, just virtual controller on the APs with AOS8.
The clients flapping between connected/disconnected constantly after the first successful portal authentication.
09-15-2023 03:53 AM
So is this driven by CoA packets from ISE or not? ISE should only be sending one CoA. Do you have ISE defined as a Dynamic Authorization server on the IAP?
09-19-2023 05:18 AM - edited 09-19-2023 05:21 AM
Yes ISE is defined as Dynamic Authorization server on IAP. We have seen that the problem only exists when clients using an BYOD MAC-group in ISE (still using guest wifi), but when clients using Guest Portal on ISE it works fine. Check my Authorization profiles below.
Aruba client logs:
deauth Sapcp Ageout (internal ageout) (seq num 0)
deauth Denied; Ageout (seq num 0)
09-14-2023 02:33 PM
@pontusd - if you perform a tcpdump on the PSN that the Aruba WLC is using, you might get some extra clues. Does the Aruba send any RADIUS Accounting to ISE?
09-15-2023 12:12 AM
Doesn't see any interesting in the TCP dumps. Yes I had accounting ON at the Aruba SSID configuration. I turned it off now and I it seems to be better. But the problem with connect/disconnect still exists of course.
09-15-2023 03:52 AM
Accounting should be enabled for proper ISE session/license management.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide