cancel
Showing results for 
Search instead for 
Did you mean: 

Supported RADIUS attributes and CoA on HiveManager NG

Supported RADIUS attributes and CoA on HiveManager NG

james_wood
New Contributor
Supported RADIUS attributes and CoA on HiveManager NG
4 REPLIES 4

sglassman
New Contributor

Good information. I wonder if this was a change from classic to NG? Our NAC is currently setup to use COA as it's the proffered method for deauth's and I am thinking we might have an issue since we migrated to NG during the Thanksgiving break....not sure yet.

james_wood
New Contributor

You can enable CoA on the RADIUS server config screen and it works fine if you are using a local RADIUS server on the same network as your APs. But, if you are using a remote RADIUS there is no easy way to do this; however I think I found a solution. You have to use the Aerohive RADIUS Proxy feature in HM, because normally, the RADIUS requests come from each AP individually, so you cannot perform a CoA back to the individual AP from a remote RADIUS (too many port forwards and how to redirect port 3799 to all AP's at the same time!)

 

So when you enable the Aerohive RADIUS proxy you nominate one of your AP's to be the proxy and then all RADIUS requests come from that IP to your RADIUS and you can send CoA's back to that.

 

Thanks

sglassman
New Contributor

Hi James-did you ever get answer on the COA part of your question? I am looking into this and have the same question....

james_wood
New Contributor

Hi,

 

I have a quick question - we have customers using HiveManager (NG) - does that support passing back a bandwidth (speed) limit in the RADIUS Access-Accept reply, and also, can you share any documentation on how we can perform a CoA (Disconnect Message) from our RADIUS to HiveManager? I believe this to be RFC 3576 / 5176.

 

Lastly, I'm confused about the different variations of Hive. It was originally Hive Manager (using HiveOS), then NG surfaced, now it says HiveManager (formwally NG).

 

So, is the old legacy Hive still a product?

 

Thank you

 

James

GTM-P2G8KFN