Solved

XMC Control monitor-only mode for Trial

  • 30 January 2021
  • 3 replies
  • 51 views

We’re far away from defining the Policy and Authentication parts of a design.

Have deployed a Trial of XMC, Analytics, FabricManager and Control v8.5.2.6 in a VSP/ERS Campus Fabric environment.

We want to enable Control  to gain visibility of connected wired devices, but NOT interfere with their operation.

Is there a guide for how to setup such a “monitor-only” scenario? 

icon

Best answer by Miguel-Angel RODRIGUEZ-GARCIA 30 January 2021, 09:57

Hi edward,

You must “interfere” a little bit to gain visibility.

You’ll have to enable eapol on the ports and make a rule that allows anything to gain access to the network.

You’ll then receive all the info into the NAC engines.

 

It is difficult to dump a guide here in the forum as the are many steps but basically:

  1. Set your xmc with all the ERS (and other switches)
    1. with snmp and cli access from XMC
  2. Set your nac infra
    1. define a catch all rule with an accept any rule
  3. Set you ERS
    1. define the radius servers
    2. set the eapol setting
  4. Test

I can provide some dumps of commands for the ERS if needed.

For the other steps all it should be described in the user guide.

Let me know if there are blocking points.

Mig

View original

3 replies

Userlevel 6
Badge +1

Hi edward,

You must “interfere” a little bit to gain visibility.

You’ll have to enable eapol on the ports and make a rule that allows anything to gain access to the network.

You’ll then receive all the info into the NAC engines.

 

It is difficult to dump a guide here in the forum as the are many steps but basically:

  1. Set your xmc with all the ERS (and other switches)
    1. with snmp and cli access from XMC
  2. Set your nac infra
    1. define a catch all rule with an accept any rule
  3. Set you ERS
    1. define the radius servers
    2. set the eapol setting
  4. Test

I can provide some dumps of commands for the ERS if needed.

For the other steps all it should be described in the user guide.

Let me know if there are blocking points.

Mig

Gracias, Miguel-Angel!

I will investigate further via documentation

Ed Z..

@Miguel-Angel RODRIGUEZ-GARCIA

Hello Miguel-Angel, 

I’m in the same situation and don’t see the end-systems connected on my ERS switch.

I’m interested if you have some dumps of commands :pray:

Reply