Confirmed:

  printf "NAS-IP-Address=$controller\nCalling-Station-Id=$mac\n" | radclient -x 
$controller:3799 disconnect $radsecret

will cause the Aruba controller to drop the association for wired clients, just 
like wireless. RADIUS MAC-Auth and VLAN reassignment will be triggered by the 
client's next packet.

So, what I want to know is what sort of changes I need to make to (hopefully 
just) Aruba.pm to get those disconnect packets sent.

I'm also asking Aruba if there's some way to flap link. There might not be, but 
I can live with that. Registration->NormalVLAN can be handled by setting the 
registration DHCP timeout really short. I won't want to do that for normal 
VLAN, but I don't care so much if NormalVLAN->Isolation or 
NormalVLAN->Registration transitions cause loss of connectivity.

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to