RE: ArubaOS 8.5.0.9 Clients not getting an address

2021-07-08 Thread Michael Holden
If you’re using a LACP link between the controller/MD and the uplink switch double check that LACP signaling is correct. We’ve seen this with at least one switch vendor where the LAG showed up, but traffic was intermittent. From: The EDUCAUSE Wireless Issues Community Group Listserv On

RE: [WIRELESS-LAN] Aruba AP 510 Series/Windows Devices

2021-06-08 Thread Michael Holden
Yes, this was AP manufacturer independent as the root cause of the issue was in the way the device driver handles 802.11ax (WiFi 6). If the user has updated their driver the issue is resolved, but you’d have to rely on the user to properly upgrade their devices. If all they connect to is

Re: [WIRELESS-LAN] android 11 upcoming changes Feb 15th 2021

2021-02-02 Thread Michael Holden
We've seen much the same. A Pixel 2XL and a Pixel3XL fully updated, the 2XL had the Don't Validate option, but the Pixel3XL did not. We added the CA cert to a subpage on the guest captive portal for ease of access to the Wireless device, and provided some instructions for the devices. The

RE: Weak Security

2020-12-02 Thread Michael Holden
+1 Kill WEP and TKIP Please beware of enabling WPA3 or OWE! Can’t wait to be able to use them, but there are still some serious driver issues out there. For instance, the Google Pixel 3 used to (may still) kernel panic and reboot the phone when connecting to a WPA3-Personal SSID. No error, no

Re: [WIRELESS-LAN] [EXTERNAL] [WIRELESS-LAN] Clearpass onboarding redirect not working on Safari

2020-11-16 Thread Michael Holden
For the wireless side the ASE has a pretty good walkthrough. https://ase.arubanetworks.com/solutions/id/161 Does the captive portal happen if you try to go to another non-https site on Apple while connected? If so, there's a check box for Apple Captive-portal Network Assistant by-pass that

RE: [WIRELESS-LAN] Status of Wi-Fi 6 Client Drivers?

2020-10-01 Thread Michael Holden
The new encryptions can also cause issues with some of the supplicants. We’ve seen some clients requesting user/pass when connecting to an Open network running the Open Wireless Enhanced (OWE). Google Pixel 3’s used to Seg fault and rebooting the phone when connecting to WPA3-Personal along

RE: [WIRELESS-LAN] Ex: Re: [WIRELESS-LAN] neighbors 'jamming' 2.4GHz spectrum

2020-01-29 Thread Michael Holden
Aruba gives the following warning when doing containment / deauth The Federal Communications Commission ("FCC") and some third parties have alleged that, under certain circumstances, use of containment functionality violates 47 U.S.C. Section 333 and/or other FCC rules, regulations or policies.

RE: [External] [WIRELESS-LAN] Joining Sonos to a campus network

2019-11-27 Thread Michael Holden
We’ve had issues specifically with Sonos and Aruba AirGroups, even custom built AirGroup definitions didn’t work. This was left at the engineering level with Aruba working for an AOS8 patch to resolve the issue. The last version we tested with was 8.3.0.9 and that still wasn’t patched /

RE: [WIRELESS-LAN] Aruba 8.5.0.3

2019-10-15 Thread Michael Holden
Yes. If you have AP-515’s you should be on 8.5.0.x code, DO NOT USE 8.4.x CODE. So far it looks like the same fixes in the 8.3.0.8 code are in the 8.5.0.3, but several folks are still having mDNS and SSDP issues with AirGroups on both. Not sure about 8.3.0.9 just yet. From: The EDUCAUSE

RE: [WIRELESS-LAN] Feasibility of an open SSID for student use

2019-09-13 Thread Michael Holden
Has anyone got the eduroam CAT working with EAP-TLS? Couldn’t find a good way for loading the certificates. May have missed the documentation for that portion. From: The EDUCAUSE Wireless Issues Community Group Listserv On Behalf Of Enfield, Chuck Sent: Friday, September 13, 2019 8:42 AM To:

Re: [WIRELESS-LAN] Feasibility of an open SSID for student use

2019-09-12 Thread Michael Holden
2nd that, self guided EAP-PEAP is convenient, but the Evil Twin Attack isn't exactly new or difficult. In the past I've used a optional layered approach. Give an option on the open SSID captive portal for initial onboarding, or limited Guest access (weekly type) captive portal re-login after

RE: [WIRELESS-LAN] [Ext] Re: [WIRELESS-LAN] Residential Wireless and Gaming

2019-09-03 Thread Michael Holden
Check out the RF and Roaming Optimization Guide here: https://community.arubanetworks.com/t5/Validated-Reference-Design/RF-and-Roaming-Optimization-for-Aruba-802-11ac-Networks/ta-p/508678 Some of this is very applicable even in a Cisco WLC environment. Such as making sure that you disable