RE: [EXTERNAL] Re: [WIRELESS-LAN] Transitioning from older controller to new controller

2020-11-11 Thread Turpin, Max
I’m interested as well, please add me. Thanks. From: The EDUCAUSE Wireless Issues Community Group Listserv On Behalf Of Tariq Adnan Sent: Wednesday, November 11, 2020 6:06 PM To: WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU Subject: [EXTERNAL] Re: [WIRELESS-LAN] Transitioning from older controller to ne

RE: [EXTERNAL] [WIRELESS-LAN] Clearpass onboarding redirect not working on Safari

2020-11-17 Thread Turpin, Max
As mentioned, you need to have an IP address for every subnet using a captive portal. If you use clustered controllers, you need have an SVI on each controller for each subnet. If you don’t want to do that, you can try enabling ‘allow tri-session with DNAT’ within the firewall settings on your

RE: [EXTERNAL] [WIRELESS-LAN] Aruba 8.7 issues

2020-12-29 Thread Turpin, Max
Robert, I’ve seen similar behavior but it happened during a cluster rebuild prior to a code upgrade. Unfortunately, it’s been a while and I was not able to find my notes from that case. What I do remember is that like your issue, the APs were pingable, but they would not join the cluster. I end

Re: [EXTERNAL] Re: [WIRELESS-LAN] Android 11 and Cert Verification

2021-01-16 Thread Turpin, Max
You do have to maintain a pki or have someone else do it but CRLs are hardly necessary if you do identity checking as part of your radius service. If you want to do posture checking you will need to use some sort of agent (as far as I know) so that could certainly be part of your on boarding sol

Re: [EXTERNAL] Re: [WIRELESS-LAN] ArubaOS 8.5.0.11 or 8.6.0.6 Experiences?

2021-01-16 Thread Turpin, Max
I am running I got his MTU issue right now. But we also do not have CPSec enabled and are going to be enabling it. The MTU should be 1200 with CPSec enabled. Are you saying this bug is fixed in 8.5.0.11? Many thanks. On Jan 15, 2021, at 6:16 PM, Johnson, Christopher wrote:  Thank to everyone

RE: [WIRELESS-LAN] eduroam CAT Config/Cert Renewal with New Root

2021-08-09 Thread Turpin, Max
Back to the original question. If you are talking about the EAP certificates, I would caution against using an EAP certificate with two separate roots. You are asking for trouble. At the very best, your clients will get certificate errors and warnings. At worst, you will have clients that will f

RE: [WIRELESS-LAN] eduroam CAT Config/Cert Renewal with New Root

2021-08-09 Thread Turpin, Max
No current operating systems enforce EAP EKU at the moment. If it were suddenly enforced, the majority of EAP networks would break. Whether right or wrong (it's wrong), that is just how the majority of networks are currently deployed. From: The EDUCAUSE Wireless Issues Community Group Listserv

Re: [EXTERNAL] Re: [WIRELESS-LAN] Wireless Scanning Apps

2021-09-03 Thread Turpin, Max
Aruba Utilities is great. I wish they had it for iOS. On Sep 3, 2021, at 2:53 PM, Tim Cantin wrote:  WiFi Analyzer, which also has an inexpensive pro version (totally worth it) On Fri, Sep 3, 2021 at 2:51 PM Hales, David mailto:dha...@tntech.edu>> wrote: I was wondering if anyone had any free

Re: [EXTERNAL] Re: [WIRELESS-LAN] Wireless Scanning Apps

2021-09-03 Thread Turpin, Max
Anything similar to Aruba Utilities for iOS? On Sep 3, 2021, at 6:10 PM, Gould, Todd wrote:  I love the Aruba Utilities app. It's free and shows a host of pretty valuable information, like nearby access points, RSSI, DSS, BLE etc. ToddG Networks & Systems Williams College On Fri, Sep 3, 2021

Cisco EAP-TLS fragmentation with active/active firewalls

2021-09-13 Thread Turpin, Max
Hey everyone, Hoping everyone is having a peaceful start of the semester. Reaching out because we’re dealing with a doozy of a problem and hoping someone else may have dealt with this and can help. We are running several pairs of Cisco 5520 controllers running 8.5.171 code. We have recently do

Re: [WIRELESS-LAN] Cisco EAP-TLS fragmentation with active/active firewalls

2021-09-13 Thread Turpin, Max
ll vs the other per session. I know this can be done at the interface level. I don’t remember what they called it off the top of my head. From: The EDUCAUSE Wireless Issues Community Group Listserv On Behalf Of Turpin, Max Sent: Monday, September 13, 2021 11:09 AM To: WIRELESS-LAN@LISTSE

Re: [WIRELESS-LAN] Cisco EAP-TLS fragmentation with active/active firewalls

2021-09-13 Thread Turpin, Max
: Monday, September 13, 2021 at 12:29 PM To: "WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU" Subject: Re: [WIRELESS-LAN] Cisco EAP-TLS fragmentation with active/active firewalls TCP vs UDP From: The EDUCAUSE Wireless Issues Community Group Listserv on behalf of Turpin, Max Date: Monday, Septembe

Re: [WIRELESS-LAN] Cisco EAP-TLS fragmentation with active/active firewalls

2021-09-13 Thread Turpin, Max
Community Group Listserv on behalf of "Turpin, Max" Reply-To: The EDUCAUSE Wireless Issues Community Group Listserv Date: Monday, September 13, 2021 at 12:30 PM To: "WIRELESS-LAN@LISTSERV.EDUCAUSE.EDU" Subject: Re: [WIRELESS-LAN] Cisco EAP-TLS fragmentation with active/activ