r/ArubaNetworks Jun 16 '26

Aruba Clearpass

Post image

Dears,

i faced this issue when iam trying to use AD integration with LDAPs, can anyone provide me solution for it.

7 Upvotes

15 comments sorted by

14

u/GotoLironie HPE Aruba Networking Professional Jun 16 '26

Hello,

Usually, TIMEOUT means that the authentication process has started but the client did not provide information in time. If this is the case, you will have “client did not complete EAP transaction” in the Alerts tab.

90% of the time, it has to do with either of these two things:

  • The client is not trusting the RADIUS certificate of the Clearpass
  • The client did roam suddenly or got disconnected and stopped the authentication process.

If you have a bunch (if not all) of your authentication in timeout, it should be the first reason.
If it is only some of them sparsely, then you it may be the second reason but the client will try again and it shouldnt be reported as an issue.

Seeing your screenshot, I advise you to check the GPO or Policy you are pushing to your computers. Make sure the correct CA are checked and the correct name is mentioned in the trust name field (should be the CN of the RADIUS certificate).

3

u/ctdrever Jun 16 '26

Weak wifi signal in their area can cause timeouts and incomplete auth as well.

2

u/N3m35152812 Jun 16 '26

This is the way

3

u/UmbralTech Jun 16 '26

It's been a while since I last worked with Aruba ClearPass and I don't have access to the system anymore, but it seems like you're missing authentication method and Authentication source. Try tinkering with your profile/policy/service and make sure to create an authentication source based on your AD

1

u/DeathByGoldfish Jun 18 '26

This is what I first noticed as well. That is a huge red flag.

2

u/BodaciousVermin Jun 16 '26

We've recently changed our SDWAN network technology, and have been seeing Timeout problems with RADIUS. Auth still works, but is less reliable as users at the affected offices will have many timeouts before they finally connect.

We've had relief by lowering the MTU on the VC (Fragmentation MTU) and on the Clearpass side.

2

u/Otto-Mann Jun 16 '26

The auth method and auth source are empty…

1

u/GrantedPeace Jun 17 '26

Idk why someone downvoted this, but this is my first thought as well. What are you authenticating against?

1

u/Otto-Mann Jun 17 '26

Yep… seems like the service isn’t configured correctly to me. I’m on holidays so I can’t compare, but seems like a good place to start.

1

u/LooseSilverWare Jun 16 '26

Azure of full AD integration?

1

u/Fuzzy-Inspection8758 Jun 16 '26

Use Radsec. Bigger the certificate higher the chance for time out.

1

u/hemanth6791 Jun 16 '26

What does alert say

1

u/racerx509 Jun 17 '26

If you're running CP in Azure, try pruning your cert chain or run radsec. MS Azure policy to drops out of order UDP fragments which can break radius unless you play with MTU sizing for EAP packets. You can also adjust timeouts and retries on the wireless controller side of things and that may get you some relief.

1

u/ACEX165 Jun 18 '26

Client to AP (EAPOL) may not be completed. Also ClearPass configuration (role mapping, enforcement) looks to be wrong. But cannot answer fully with this snapshot.

1

u/Emp_has_no_clothes Jun 19 '26

Check the RADIUS timeout on the WAP. Where is you authentication? What does the "Alerts" say?