Page 2 of 2

Re: Wired Mac Authentication Time Based using Clearpass

Posted: 26 Jan 2024 14:25
by silvio
I am not realy sure about that all. I think that CPPM has to sent DM request if the allowed time is expired. With this message the switch should deauth the client. With your own port down/up you initiate a new authentication.
Maybe in CPPM is a misconfiguration. I don't know the necessary config there. You should open a ticket at ALE.
But it will be fine to clarify us if you have your solution.
BR Silvio

Re: Wired Mac Authentication Time Based using Clearpass

Posted: 29 Jan 2024 02:18
by silvio
You can check with wireshark at a mirror-port (or monitor) or via tcpdump, if CPPM sends a message in case the allowed time is ellapsed. If there is a message than the issue is at the switch. Without message (this is what the last statistic command is saying) the issue is at CPPM.
regards Silvio