<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: mac to role mapping in EXOS in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21710#M1327</link>
    <description>i figure it out:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://emc.extremenetworks.com/content/polman/docs/l_p_at_port_prop_gen.html#mappings" target="_blank" rel="nofollow noreferrer noopener"&gt;https://emc.extremenetworks.com/content/polman/docs/l_p_at_port_prop_gen.html#mappings&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
configure policy profile 1 name "Innovaphone" pvid-status "enable" pvid 172 untagged-vlans 172&lt;BR /&gt;
configure policy rule admin-profile macsource 00-90-33-00-00-00 mask 24 port-string 1 admin-pid 1&lt;BR /&gt;
configure policy rule admin-profile macsource 00-90-33-00-00-00 mask 24 port-string 2 admin-pid 1Be aware this works not with EXOS 22.5 - 22.5-Patch-2-2 include a fix.&lt;BR /&gt;</description>
    <pubDate>Tue, 04 Sep 2018 21:45:00 GMT</pubDate>
    <dc:creator>M_Nees</dc:creator>
    <dc:date>2018-09-04T21:45:00Z</dc:date>
    <item>
      <title>mac to role mapping in EXOS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21705#M1322</link>
      <description>I have a client with EOS switches that uses MAC-To-Role Mapping from Policy Manager to allow certain devices to access the network with a different policy than the default when comunication between the switch and the NAC is interrupted.&lt;BR /&gt;
&lt;BR /&gt;
In EXOS, I can not do that, only VLAN to Role mapping works (not Mac to role or IP to role).&lt;BR /&gt;
&lt;BR /&gt;
The client is security-concious and is concerned that in remote offices, if the NAC is not available, everyone can get in. They want to still be able to apply certain security to certain devices.&lt;BR /&gt;
&lt;BR /&gt;
Is there a different method to make sure a local (inside the switch) autentication happens only if the NAC is not available for auhentication?</description>
      <pubDate>Tue, 13 Jun 2017 20:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21705#M1322</guid>
      <dc:creator>jsoler</dc:creator>
      <dc:date>2017-06-13T20:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: mac to role mapping in EXOS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21706#M1323</link>
      <description>Hello Jordi,&lt;BR /&gt;
&lt;BR /&gt;
For added security, you can configure your EXOS device for limited/locked MAC learning as per this article from our Knowledge Base:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/Q_A/How-to-enable-port-security-mac-learning-on-Summit-X460" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/Q_A/How-to-enable-port-security-mac-learning-on-S...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 13 Jun 2017 20:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21706#M1323</guid>
      <dc:creator>Ash_Curtis</dc:creator>
      <dc:date>2017-06-13T20:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: mac to role mapping in EXOS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21707#M1324</link>
      <description>Thanks for the reply, that this would not help if a new user/device wanted to enter the LAN after the NAC communication was interrupted.</description>
      <pubDate>Tue, 13 Jun 2017 20:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21707#M1324</guid>
      <dc:creator>jsoler</dc:creator>
      <dc:date>2017-06-13T20:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: mac to role mapping in EXOS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21708#M1325</link>
      <description>Yes, that is correct, your options here are limited to configuring the number of MAC addresses that can be learned or the specific MAC addresses that can use a given port. &lt;BR /&gt;
&lt;BR /&gt;
If you do not know a potential users MAC address that may wish to use a given port in the future, you will need to limit the number of MAC addresses that can be learned but of course this leaves the port open to learning ANY new MAC addresses up to the configured limit.</description>
      <pubDate>Tue, 13 Jun 2017 20:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21708#M1325</guid>
      <dc:creator>Ash_Curtis</dc:creator>
      <dc:date>2017-06-13T20:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: mac to role mapping in EXOS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21709#M1326</link>
      <description>On EXOS 22.2/22.3/22.4 MAC-to-Role Mapping seems to be possible but only at "port-level" not "device level".&lt;BR /&gt;
Unfortunately i do not figured out how to configure that!&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Sep 2018 21:45:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21709#M1326</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2018-09-04T21:45:00Z</dc:date>
    </item>
    <item>
      <title>RE: mac to role mapping in EXOS</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21710#M1327</link>
      <description>i figure it out:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://emc.extremenetworks.com/content/polman/docs/l_p_at_port_prop_gen.html#mappings" target="_blank" rel="nofollow noreferrer noopener"&gt;https://emc.extremenetworks.com/content/polman/docs/l_p_at_port_prop_gen.html#mappings&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
configure policy profile 1 name "Innovaphone" pvid-status "enable" pvid 172 untagged-vlans 172&lt;BR /&gt;
configure policy rule admin-profile macsource 00-90-33-00-00-00 mask 24 port-string 1 admin-pid 1&lt;BR /&gt;
configure policy rule admin-profile macsource 00-90-33-00-00-00 mask 24 port-string 2 admin-pid 1Be aware this works not with EXOS 22.5 - 22.5-Patch-2-2 include a fix.&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Sep 2018 21:45:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/mac-to-role-mapping-in-exos/m-p/21710#M1327</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2018-09-04T21:45:00Z</dc:date>
    </item>
  </channel>
</rss>

