<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ExtremeControl PVID misconfiguration for a role - not assigned to correct VLAN in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremecontrol-pvid-misconfiguration-for-a-role-not-assigned-to/m-p/112342#M12284</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to configure a policy for a group of users in the Access Control Engine but the actual policy that is being deployed to the switch does not correspond with what I am looking to achieve. Below you can see the exact policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;configure policy profile 6 name "Enterprise Access" pvid-status "enable" pvid 4095 cos-status "enable" cos 3 untagged-vlans 2005&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;The behaviour that I am aiming for is that all users who are assigned to the Enterprise Access role based are assigned to VLAN 2005 (meaning that the port they are connected to is configured as untagged for VLAN 2005). The uplinks are manually configured with all the VLANs that could potentially be used in the switch. The configuration relevant to this is as follows:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In Policy -&amp;gt; Roles/Services -&amp;gt; Enterprise Access -&amp;gt; VLAN egress. Configured VID 2005 as untagged.&lt;/LI&gt;&lt;LI&gt;As a result of this, in&amp;nbsp;Policy -&amp;gt; Roles/Services -&amp;gt; Enterprise Access -&amp;gt; Mappings, the value 2005 is configured with type VLAN (RFC 3580).&lt;/LI&gt;&lt;LI&gt;In Policy -&amp;gt; VLANs I have created the global VLAN VLAN_Enterprise with VID 2005 and mapped it to the role Enterprise access, configuring to always write the VLAN to the device.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What am I missing? The device connecting authenticates properly and appears in the end-system tab confirming that it is assigned to Enterprise access. However, it does not have connectivity and does not receive an IP address. By manually forcing the policy in the switch to use the PVID 2005:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;configure policy profile 6 name "Enterprise Access" pvid-status "enable" pvid 2005 cos-status "enable" cos 3 untagged-vlans 2005&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then, it behaves as expected. What am I missing? Are any of the configurations I have followed redundant/unnecessary and is there anything that I may have overlooked?&lt;/P&gt;&lt;P&gt;I would also be grateful if you could provide more guidance on Policy VLAN Islands. The concept is clear to me yet I cannot wrap my head around how to configure them or the inner workings.&lt;/P&gt;&lt;P&gt;Thanks for your help,&lt;/P&gt;&lt;P&gt;Gerard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Sep 2024 16:04:39 GMT</pubDate>
    <dc:creator>gerivives</dc:creator>
    <dc:date>2024-09-05T16:04:39Z</dc:date>
    <item>
      <title>ExtremeControl PVID misconfiguration for a role - not assigned to correct VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremecontrol-pvid-misconfiguration-for-a-role-not-assigned-to/m-p/112342#M12284</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to configure a policy for a group of users in the Access Control Engine but the actual policy that is being deployed to the switch does not correspond with what I am looking to achieve. Below you can see the exact policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;configure policy profile 6 name "Enterprise Access" pvid-status "enable" pvid 4095 cos-status "enable" cos 3 untagged-vlans 2005&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;The behaviour that I am aiming for is that all users who are assigned to the Enterprise Access role based are assigned to VLAN 2005 (meaning that the port they are connected to is configured as untagged for VLAN 2005). The uplinks are manually configured with all the VLANs that could potentially be used in the switch. The configuration relevant to this is as follows:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In Policy -&amp;gt; Roles/Services -&amp;gt; Enterprise Access -&amp;gt; VLAN egress. Configured VID 2005 as untagged.&lt;/LI&gt;&lt;LI&gt;As a result of this, in&amp;nbsp;Policy -&amp;gt; Roles/Services -&amp;gt; Enterprise Access -&amp;gt; Mappings, the value 2005 is configured with type VLAN (RFC 3580).&lt;/LI&gt;&lt;LI&gt;In Policy -&amp;gt; VLANs I have created the global VLAN VLAN_Enterprise with VID 2005 and mapped it to the role Enterprise access, configuring to always write the VLAN to the device.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What am I missing? The device connecting authenticates properly and appears in the end-system tab confirming that it is assigned to Enterprise access. However, it does not have connectivity and does not receive an IP address. By manually forcing the policy in the switch to use the PVID 2005:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;configure policy profile 6 name "Enterprise Access" pvid-status "enable" pvid 2005 cos-status "enable" cos 3 untagged-vlans 2005&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then, it behaves as expected. What am I missing? Are any of the configurations I have followed redundant/unnecessary and is there anything that I may have overlooked?&lt;/P&gt;&lt;P&gt;I would also be grateful if you could provide more guidance on Policy VLAN Islands. The concept is clear to me yet I cannot wrap my head around how to configure them or the inner workings.&lt;/P&gt;&lt;P&gt;Thanks for your help,&lt;/P&gt;&lt;P&gt;Gerard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 16:04:39 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremecontrol-pvid-misconfiguration-for-a-role-not-assigned-to/m-p/112342#M12284</guid>
      <dc:creator>gerivives</dc:creator>
      <dc:date>2024-09-05T16:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl PVID misconfiguration for a role - not assigned to correct VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremecontrol-pvid-misconfiguration-for-a-role-not-assigned-to/m-p/112354#M12285</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/48890"&gt;@gerivives&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you are probably just missing this setting here:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Stefan_K__0-1725558176028.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8126i57E2E72E9A57251E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Stefan_K__0-1725558176028.png" alt="Stefan_K__0-1725558176028.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I guess it is set to "permit traffic", change it to "contain to VLAN" and choose VLAN2005 from the dropdown.&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the way, if you only want to do VLAN assignment without any specific roles/rules/services, you can simply rely on RFC3580 without the use of policies. Policy aissgnment is done via Policy Mappings in NAC. Make sure to change the radius attributes of the switch to "RFC 3580 - VLAN ID &amp;amp; Extreme Policy" to be able to use both RFC3580 and Policies. "configure maptable response both" also needs to be configured on the switch.&lt;/P&gt;&lt;P&gt;Best regards&lt;BR /&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 17:45:56 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremecontrol-pvid-misconfiguration-for-a-role-not-assigned-to/m-p/112354#M12285</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2024-09-05T17:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl PVID misconfiguration for a role - not assigned to correct VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremecontrol-pvid-misconfiguration-for-a-role-not-assigned-to/m-p/112526#M12287</link>
      <description>&lt;P&gt;I would agree. The "VLAN Egress" tab is meant to allow configuration of VLANs on egress, but not for PVID.&lt;BR /&gt;&lt;BR /&gt;"Contain to VLAN" should set pvid and egress of untagged.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 12:54:04 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/extremecontrol-pvid-misconfiguration-for-a-role-not-assigned-to/m-p/112526#M12287</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2024-09-06T12:54:04Z</dc:date>
    </item>
  </channel>
</rss>

