RE: Odd issue with Aruba wireless...

2011-12-09 Thread Osborne, Bruce W
You really need to setup your validuser ACL. The default configuration is not meant for a production environment. We recently had an issue because our deny based validuser ACL had not been updated when the network topology changed, adding additional subnets. some user had our webmail server's

RE: [WIRELESS-LAN] WPA2-Enterprise - account lockouts and password changes

2011-12-09 Thread Hurt,Trenton William
I know this is a month old, but I have a question regarding the password history check setting. I have suggested this to my AD team but they aren’t familiar with the setting and want to test for months, etc. I really am pushing for them to make the change so that users will get relief from

Re: [WIRELESS-LAN] advice on impementations for Aruba

2011-12-09 Thread Jason Appah
Anyone? Jason Appah Security / Systems Administrator OIT 541-885-1719 On Dec 7, 2011, at 1:52 PM, Jason Appah jason.ap...@oit.edumailto:jason.ap...@oit.edu wrote: All, We are looking to allow the private addresses of the unsecured wireless to pass through our aruba, how would we go about

Re: [WIRELESS-LAN] advice on impementations for Aruba

2011-12-09 Thread Jason Appah
Thanks! Jason Appah Security / Systems Administrator OIT 541-885-1719 On Dec 9, 2011, at 8:24 AM, Brooks, Stan stan.bro...@emory.edumailto:stan.bro...@emory.edu wrote: Jason - We moved our NAT functionality off the Aruba controllers to separate boxes because of some limitations in the NAT

Re: [WIRELESS-LAN] WPA2-Enterprise - account lockouts and password changes

2011-12-09 Thread Zeller, Tom S
I saw this on this list the day after my account had been locked, as always happens upon a pw change (g). (Thanks to however posted it). I suggested we turn this bit on at Indiana. The ADS people have tested it for a month and are happy with it. Security OK'd it today. The identity

Delay in getting IP address on Snow Leopard/Lion on the WLAN

2011-12-09 Thread Aaron Abitia
Hello all, We are currently running Cisco Clean Access 4.8.2 inband NAC on an Aruba 6.1.2.3 WLAN infrastructure, and have an intermittent problem with Apple Macintoshes running Snow Leopard and Lion. Snow Leopard and Lion Macintosh computers take a long time to connect to wireless because

Re: [WIRELESS-LAN] Delay in getting IP address on Snow Leopard/Lion on the WLAN

2011-12-09 Thread Holland, Ryan
Are the dhcp offers you saw from a sniff on the client or elsewhere? === Ryan Holland (sent while mobile) On Dec 9, 2011, at 8:17 PM, Aaron Abitia aabi...@calpoly.edumailto:aabi...@calpoly.edu wrote: Hello all, We are currently running Cisco Clean Access 4.8.2 inband NAC on an Aruba