Question

How to configure NAC to send outbound radius attributes for dhcp snooping, bpdu filtering, slpp guard

  • 19 May 2020
  • 1 reply
  • 235 views

What configuratoin is required to setup NAC to send outbound radius attributes for configuring ERS4900 with FA radius attributes like:

dhcp snooping

bpdu filtering

slpp guard

IP-Source Guard

All this should be possible in combination with NAC and ERS 4900.

Thanks in advance


1 reply

Userlevel 6
Badge

Hi Sacha,

 

Whatever is supported on ERS 4900 as RADIUS attributes (see here: https://documentation.extremenetworks.com/ERS_Series/ERS49005900/SW/78x/9036215-00_ConfigSecERS49005900_7.8_CG.pdf and https://documentation.extremenetworks.com/ERS_Series/ERS49005900/SW/78x/9036216-00_ConfigFabConERS49005900_7.8_CG.pdf), they can be configured under selected Policy Mapping in EAC configuration:

https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/l_ov_ia_ht_setup_access_policies.html

https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/l_ov_ia_at_man_policy_mapping.html

 

On the other hand, when adding ERS to EAC engine Switches list (authenticators), you have to specify what RADIUS attributes are to be send back if an authenticating end-system is connected to this particular switch:

https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/c_ov_ia_at_add_switch_window.html#top

 

For BOSS I see ready sets of RADIUS Attributes, e.g. “Extreme BOSS Fabric Attach”. It looks lke that:

FA-VLAN-Create=1
FA-VLAN-ISID=%VLAN_ID%:%CUSTOM1%
FA-VLAN-PVID=%VLAN_ID%

So in the Policy Mapping, VLAN ID should be set and ‘Custom 1’ field shall contain I-SID number.

 

It will work the same for other switches and vendors. If some attribute sets are not there (like you would like to mix few attributes from different sets), you can create a new set on your own. If particular proprietary attributes are not defined (like I saw for WiNG), you can define just %CUSTOM1% and inside a Policy Mapping put entire attribute and value pair.

 

If you need more guidance let us know.

 

Hope that helps,

Tomasz

Reply