<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Kerberos Snooping with 802.1X in Analytics &amp; Visibility</title>
    <link>https://community.extremenetworks.com/t5/analytics-visibility/kerberos-snooping-with-802-1x/m-p/51391#M10</link>
    <description>After discussion with my co-workers - we believe this feature is available (Netsight V7.x) if you mirror login traffic to NAC appliance (DHCP/kerberos snooping is active by default). &lt;BR /&gt;
End-System Cache should distribute this information to Netsight aka NAC Manager Client ...</description>
    <pubDate>Fri, 28 Jul 2017 18:13:00 GMT</pubDate>
    <dc:creator>M_Nees</dc:creator>
    <dc:date>2017-07-28T18:13:00Z</dc:date>
    <item>
      <title>Kerberos Snooping with 802.1X</title>
      <link>https://community.extremenetworks.com/t5/analytics-visibility/kerberos-snooping-with-802-1x/m-p/51389#M8</link>
      <description>Hi,  Kerberos Snooping allows getting Username  Information if a client is authenticated via MAC. But if the client is  authenticated via 802.1X through its computer account, the Kerberos Information  is ignored. This is reasonable as both (Kerberos and .1X) use the username  column and the 802.1X authentication is more confiding. As a result it is not possible  to get the information which user is logged into the client.&lt;BR /&gt;
  &lt;BR /&gt;
  It is possible to do a user based 802.1X  authentication but when it comes to EAP-TLS it is much more overhead to deal  with user certificates then with computer certificates. Another point against  user authentication is if PEAP is used. In this case the user could use any  client in which he enters his credentials.&lt;BR /&gt;
  &lt;BR /&gt;
  A solution for this could be a new column in the  NAC Manager e.g. "Kerberos Username" which is filled through the kerberos handler. Especially as the purple Extreme switches can do the Kerberos Snooping in the switch, this feature would be very interesting in the near &lt;BR /&gt;
  &lt;BR /&gt;
  I hope this feature will be included soon. What do  you think about?&lt;BR /&gt;
  &lt;BR /&gt;
  Best Regards&lt;BR /&gt;
  Michael&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 07 May 2014 20:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/analytics-visibility/kerberos-snooping-with-802-1x/m-p/51389#M8</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2014-05-07T20:23:00Z</dc:date>
    </item>
    <item>
      <title>RE: Kerberos Snooping with 802.1X</title>
      <link>https://community.extremenetworks.com/t5/analytics-visibility/kerberos-snooping-with-802-1x/m-p/51390#M9</link>
      <description>Is this feature available ???&lt;BR /&gt;</description>
      <pubDate>Fri, 28 Jul 2017 18:13:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/analytics-visibility/kerberos-snooping-with-802-1x/m-p/51390#M9</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2017-07-28T18:13:00Z</dc:date>
    </item>
    <item>
      <title>RE: Kerberos Snooping with 802.1X</title>
      <link>https://community.extremenetworks.com/t5/analytics-visibility/kerberos-snooping-with-802-1x/m-p/51391#M10</link>
      <description>After discussion with my co-workers - we believe this feature is available (Netsight V7.x) if you mirror login traffic to NAC appliance (DHCP/kerberos snooping is active by default). &lt;BR /&gt;
End-System Cache should distribute this information to Netsight aka NAC Manager Client ...</description>
      <pubDate>Fri, 28 Jul 2017 18:13:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/analytics-visibility/kerberos-snooping-with-802-1x/m-p/51391#M10</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2017-07-28T18:13:00Z</dc:date>
    </item>
  </channel>
</rss>

