<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local Administrator account and Extreme NAC in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120304#M12831</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I was incorrect in my first response.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In addition to the Local Password Repository account you'll need to create an AAA account to look to the local password repository.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For example:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ryan_Yacobucci_0-1758123473985.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9189i11FBA46930AE9BD5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ryan_Yacobucci_0-1758123473985.png" alt="Ryan_Yacobucci_0-1758123473985.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The AAA line should be set to look for "Authentication Type" of "Management Login" with a pattern defined as the local user that is attempting to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication Method should be set to Local Authentication.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Make sure the placement of this new AAA rule will be used. The AAA runs like an ACL, first match wins, so if you put this rule at the bottom and a rule in the AAA higher up is a match, this new rule will not be used.&lt;BR /&gt;&lt;BR /&gt;Once this is in place, you should be able to get authentication to succeed.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;-Ryan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Sep 2025 15:40:18 GMT</pubDate>
    <dc:creator>Ryan_Yacobucci</dc:creator>
    <dc:date>2025-09-17T15:40:18Z</dc:date>
    <item>
      <title>Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120288#M12826</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apologies if this question is in the wrong section.&lt;/P&gt;&lt;P&gt;We are using XMC- SE and NAC control in our environment.&amp;nbsp; We are currently testing User and Machine Authentication via Certificates.&amp;nbsp; The User and Machine are domain joined and can authenticate as expected.&lt;/P&gt;&lt;P&gt;However, I am finding I cannot authenticate an end user device when I login with a local administrator account.&amp;nbsp; This makes sense as the settings are setup to use domain joined authentication.&lt;/P&gt;&lt;P&gt;My question is, can local administrator accounts on end user devices somehow be authenticated to give network access?&amp;nbsp; When I login with the local administrator account, the network drops off after a short time.&amp;nbsp; In XMC I can see for the local administrator account the message "Rejected NTLM Authentication".&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 10:44:11 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120288#M12826</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-09-16T10:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120289#M12827</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;You can set up a username/password in the local password repository that can be used with local admin accounts. The "LDAP Authentication" or "Local Authentication" authentication method in your AAA should both also check the local password repository during the authentication. I don't believe you'll need any additional rules, just add the credentials into the local password repository which can be found in the AAA configurations.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 12:09:41 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120289#M12827</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2025-09-16T12:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120290#M12828</link>
      <description>&lt;P&gt;You can configure specific NAC AAA rule for handling authentication for those local accounts (perhaps you need to change AAA from Basic to Advanced configuration first)&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 12:10:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120290#M12828</guid>
      <dc:creator>Bartek</dc:creator>
      <dc:date>2025-09-16T12:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120291#M12829</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/8653"&gt;@RyanS&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/17121"&gt;@Bartek&lt;/a&gt;&amp;nbsp; - thanks both.&amp;nbsp; I did see the document for adding the account to the local password repository.&amp;nbsp; However, the document was dated 2019 and involved setting son the NAC side too.&amp;nbsp; Is there a more up to date document per chance?&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 12:15:45 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120291#M12829</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-09-16T12:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120295#M12830</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I have added in the credentials as stated in the comments above.&amp;nbsp; This is coming back with Rejected NTLM Authentication.&lt;/P&gt;&lt;P&gt;With User/Machine Authentication the end device is allocated a subnet due to it's location.&amp;nbsp; If no Rules are met as in this case - local administrator account, there is a fall back subnet the end device is allocated.&lt;/P&gt;&lt;P&gt;Is a new rule needed for this?&amp;nbsp; Ideally, I would the end device to keep the subnet IP like when this is logged in as a domain user.&lt;/P&gt;&lt;P&gt;The message I have are:&lt;/P&gt;&lt;P&gt;Username: Local Admin, Auth Type: 802.1X, Reason: Rejected NTLM Authentication&lt;/P&gt;&lt;P&gt;Then the session is no longer active due to: Lost Carrier.&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 13:39:54 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120295#M12830</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-09-16T13:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120304#M12831</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I was incorrect in my first response.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In addition to the Local Password Repository account you'll need to create an AAA account to look to the local password repository.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For example:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ryan_Yacobucci_0-1758123473985.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9189i11FBA46930AE9BD5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ryan_Yacobucci_0-1758123473985.png" alt="Ryan_Yacobucci_0-1758123473985.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The AAA line should be set to look for "Authentication Type" of "Management Login" with a pattern defined as the local user that is attempting to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication Method should be set to Local Authentication.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Make sure the placement of this new AAA rule will be used. The AAA runs like an ACL, first match wins, so if you put this rule at the bottom and a rule in the AAA higher up is a match, this new rule will not be used.&lt;BR /&gt;&lt;BR /&gt;Once this is in place, you should be able to get authentication to succeed.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;-Ryan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 15:40:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120304#M12831</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2025-09-17T15:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120312#M12832</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/33973"&gt;@Ryan_Yacobucci&lt;/a&gt;&amp;nbsp; - thanks for the reply.&amp;nbsp; Is the AAA account added in in the option below?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_0-1758191738564.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9191iBE73E48EF6D079B0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_0-1758191738564.png" alt="ExtremeNewbie_0-1758191738564.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I also have AAA Rules under configuration please see below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_1-1758191815331.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9192i2F7529E6207CCCFE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_1-1758191815331.png" alt="ExtremeNewbie_1-1758191815331.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Which option is the best place for this?&amp;nbsp; I also have other AAA Rules and like you have said need to ensure this is placed correctly.&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 10:37:57 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120312#M12832</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-09-18T10:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120317#M12833</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I have created the AAA Rule as suggested please see below.&amp;nbsp; This does not match the rule and goes straight to CatchAll when trying to login as the local administrator account.&amp;nbsp; I have tried with and without the Password Authentication option as in the screenshot below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To confirm, the local administrator account has been added to the Local Password Repository under the Default option and the rule has been created as below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_0-1758206256477.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9193i61991AFC065A9CCB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_0-1758206256477.png" alt="ExtremeNewbie_0-1758206256477.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 14:41:08 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120317#M12833</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-09-18T14:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120323#M12834</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;You need an AAA rule to handle the authentication, and you need a rules engine rule to handle the authorization.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;See this article for an example:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://extreme-networks.my.site.com/ExtrArticleDetail?an=000081977" target="_blank"&gt;https://extreme-networks.my.site.com/ExtrArticleDetail?an=000081977&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Sat, 20 Sep 2025 22:11:04 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120323#M12834</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2025-09-20T22:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120329#M12835</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/33973"&gt;@Ryan_Yacobucci&lt;/a&gt;&amp;nbsp;- Thanks for the reply.&amp;nbsp; I have gone though the document.&amp;nbsp; One item to note is that the local administrator account is &lt;STRONG&gt;not&lt;/STRONG&gt; a domain account.&amp;nbsp; The link in your reply above refers to a domain administrator account.&amp;nbsp; I set this up as&amp;nbsp; Local Authentication - see screenshot below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_0-1758549386860.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9195i3191A306718D8494/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_0-1758549386860.png" alt="ExtremeNewbie_0-1758549386860.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_1-1758549424479.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9196iBB2E56DD0633D12A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_1-1758549424479.png" alt="ExtremeNewbie_1-1758549424479.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As such, I don't believe NTLM Authentication will work as LDAP Authentication Type needs to be local as in the screenshot above.&amp;nbsp; If I have misread this I apologise.&amp;nbsp; To re-iterate, the account needed is a Local Administrator account (end user device) and this is not a domain account.&lt;/P&gt;&lt;P&gt;Many Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 13:59:48 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120329#M12835</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-09-22T13:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120331#M12836</link>
      <description>&lt;P&gt;You are correct, since there is no LDAP integration you cannot utilize an LDAP criteria in order to match a rule to provide mgmt RADIUS attributes.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Instead, you would need to define a "username" user group with the users you want to allow access.&lt;BR /&gt;&lt;BR /&gt;There are two main concepts that need to be considered here:&lt;BR /&gt;1. The authentication from the switch needs to be processed.&amp;nbsp;&lt;BR /&gt;This is the AAA with local password authentication.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This will only perform the "Accept" or "Reject" based on user password. To gain access to switches, you need to provide a RADIUS attribute to provide an authorization level, which leads us to #2.&lt;BR /&gt;&lt;BR /&gt;2. The Control appliance needs to send a RADIUS attribute to allow management access, and at which level the user is authorized. (Read only versus Read/Write)&lt;BR /&gt;&lt;BR /&gt;This is the purpose of the rule in Control rules engine. There needs to be a rule that matches on management authentication to provide the appropriate RADIUS attribute (Server-Type=6 usually) to gain read/write management access.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;While you do not have the ability to do an LDAP look, you need a rule to provide the "Service-Type=6" attribute for management access.&lt;BR /&gt;&lt;BR /&gt;In turn, you also need a rule to Reject users that are NOT allowed. With switch engine/EXOS an "Accept" is enough to get ready-only access, so a reject needs to be returned to prevent anyone hitting the "catch-all" rule and getting an "accept".&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 15:18:56 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120331#M12836</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2025-09-22T15:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120332#M12837</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/33973"&gt;@Ryan_Yacobucci&lt;/a&gt;&amp;nbsp;- thanks for the reply.&amp;nbsp; Is there documentation showing how to put this in place?&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 15:24:54 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120332#M12837</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-09-22T15:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120333#M12838</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;If you follow the guide I provided above, but instead of an "LDAP User Group" use a "Username" user group and define the users you want to login.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 15:38:29 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120333#M12838</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2025-09-22T15:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120413#M12840</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/33973"&gt;@Ryan_Yacobucci&lt;/a&gt;&amp;nbsp;I have created the local user as per instructions please see below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_1-1759307026501.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9207i805119725D80B2A5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_1-1759307026501.png" alt="ExtremeNewbie_1-1759307026501.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_0-1759306953955.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9206iD09BBA6FCFBA38BC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_0-1759306953955.png" alt="ExtremeNewbie_0-1759306953955.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have created a new AAA Rule for this and placed this at the top of the list - please see below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_2-1759307170649.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9208i384ABC9FC7BDE8AF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_2-1759307170649.png" alt="ExtremeNewbie_2-1759307170649.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have created a new Rule for this as described - see below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_3-1759307299222.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9209iB8F912195D8B21B1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_3-1759307299222.png" alt="ExtremeNewbie_3-1759307299222.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Profile is below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_4-1759307347570.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9210iB1AE31704E44CB3B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_4-1759307347570.png" alt="ExtremeNewbie_4-1759307347570.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_5-1759307372327.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9211iA9F483E26E17EF9A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_5-1759307372327.png" alt="ExtremeNewbie_5-1759307372327.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_6-1759307494989.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9212i73C8DF82F9F80B6D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_6-1759307494989.png" alt="ExtremeNewbie_6-1759307494989.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then the Reject Rule - this is what I am unsure about.&amp;nbsp; I have set this to Reject Authentication Requests - see below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_7-1759307610578.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9213i0810D2EE55835733/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_7-1759307610578.png" alt="ExtremeNewbie_7-1759307610578.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_8-1759307647713.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9214i8288852FE9E61098/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_8-1759307647713.png" alt="ExtremeNewbie_8-1759307647713.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In total, it looks like this - see below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_9-1759307708316.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9215i26DF0999F6353E02/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_9-1759307708316.png" alt="ExtremeNewbie_9-1759307708316.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I believe this is all that is needed from the AAA and Rule side.&amp;nbsp; Please correct me if I am wrong.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If all the above is correct, the next step is to configure the switch in the NAC Engine to accept Any Access?&amp;nbsp; Will this then accept Radius and the new AAA/Rule created above?&amp;nbsp; The new Rule is not enabled at the moment as I have not completed the NAC side yet.&lt;/P&gt;&lt;P&gt;Many Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 08:39:06 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120413#M12840</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-10-01T08:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120416#M12841</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;This looks pretty good to me.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Authentication is configured to handle the local users by the local password repository.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Authorization is configured to send back an administrative response if it's an authorized user, and ANY other management logins will be rejected.&lt;BR /&gt;&lt;BR /&gt;Some final considerations:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;1. When you add the switch you have to set the Auth Access type to "Any Access". This will have Control attempt to configure the device to send RADIUS requests for management access. As long as the device supports dynamic RADIUS configuration, when you enforce the NAC, NAC will reconfigure RADIUS to enable for the management realm/facility.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Once you enforce, make sure the configuration is changed accordingly.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;2. When you add the switch, make sure the "RADIUS attributes to send" contains the necessary attributes for management access.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Service-Type for EXOS&lt;BR /&gt;Service-Type or Passport-Access-Priority for VOSS depending on version&lt;BR /&gt;Service-Type for XIQ-C&lt;BR /&gt;&lt;BR /&gt;Typically Service-Type=6 will get you read/write access.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 20:31:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120416#M12841</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2025-10-01T20:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120418#M12843</link>
      <description>&lt;P&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/33973"&gt;@Ryan_Yacobucci&lt;/a&gt;&amp;nbsp;- many thanks for checking and confirming the setup.&amp;nbsp; I will look at the switch side shortly.&amp;nbsp; One other item from me, when adding a username to the user group, does a wildcard for example &lt;STRONG&gt;.\name&lt;/STRONG&gt; work for this?&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 08:14:10 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120418#M12843</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-10-02T08:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120442#M12845</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;You should be able to use * for a wildcard for username usergroups.&lt;BR /&gt;&lt;BR /&gt;The user/host/pattern matching within the AAA itself has a more fully feature regex capability, but within usergroups there is only very limited capability. * will work for wildcards within usergroups.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Sat, 04 Oct 2025 19:07:04 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120442#M12845</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2025-10-04T19:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: Local Administrator account and Extreme NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120451#M12847</link>
      <description>&lt;P&gt;Hello Ryan - I have tried as suggested and have a couple of issues.&lt;/P&gt;&lt;P&gt;1. The setup as it is, the Rule created for this is not hit and the Authentication attempted is 802.1X see below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_0-1759754209509.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9225i114B042F97189620/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_0-1759754209509.png" alt="ExtremeNewbie_0-1759754209509.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2. When I run the Evaluation Tool for this, it comes back as OK and no issues - see below.&lt;/P&gt;&lt;P&gt;AAA Rule&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_1-1759754523993.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9226i5BB48D5278CA34C6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_1-1759754523993.png" alt="ExtremeNewbie_1-1759754523993.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Access Rule&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_2-1759754550549.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9227i8FB312F201BA2014/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_2-1759754550549.png" alt="ExtremeNewbie_2-1759754550549.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I also have an issue where the Reject Rule is applied across the board and is leading to Authentication rejections.&amp;nbsp; I have turned the Reject Rule off for now - see below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_3-1759754704407.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9228i91328BDF167612D4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_3-1759754704407.png" alt="ExtremeNewbie_3-1759754704407.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExtremeNewbie_4-1759754713943.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9229i9081BC2B6B3158C5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExtremeNewbie_4-1759754713943.png" alt="ExtremeNewbie_4-1759754713943.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The Reject Rule is directly below the Accept Rule.&amp;nbsp; Something I believe is wrong with the setup/placement of this Rule.&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2025 12:47:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/local-administrator-account-and-extreme-nac/m-p/120451#M12847</guid>
      <dc:creator>ExtremeNewbie</dc:creator>
      <dc:date>2025-10-06T12:47:18Z</dc:date>
    </item>
  </channel>
</rss>

