<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Kerberos authentication with nac: change user or logout at the end system in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/kerberos-authentication-with-nac-change-user-or-logout-at-the/m-p/22632#M1496</link>
    <description>&lt;P&gt;Hello community,&lt;BR /&gt;&lt;BR /&gt;I´m testing NAC authentication with kerberos from X440-G2-switches.&lt;BR /&gt;&lt;BR /&gt;I have a few questions/issues:&lt;BR /&gt;&lt;BR /&gt;1. If I log on to a windows client against the AD, I see the session in the cli of the switch with show identity-management entries, but it will disappear after few minutes, even the PC is active and logged in. Is this okay?&lt;BR /&gt;&lt;BR /&gt;2. After logging in to the PC, I can see the username in NAC. But when I log out from the PC, I still see the username and the end system is accepted based on this.&lt;BR /&gt;&lt;BR /&gt;3. If I logout from the client and login with another user, I see the active user in the cli of the switch, but I have to reauthenticate the End System in NAC to see the other user that is currently logged in.&lt;BR /&gt;&lt;BR /&gt;I think, the switch should sent something like a notification to the NAC, if users log out or there is an user change. Is this possible?&lt;BR /&gt;&lt;BR /&gt;If there is a similiar post in the hub, please show me the link. I´ve searched the forum, but didn´t found any suitable topic.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance for your replies!&lt;BR /&gt;&lt;BR /&gt;Kind Regards, Ralf&lt;/P&gt;</description>
    <pubDate>Tue, 23 Oct 2018 19:38:00 GMT</pubDate>
    <dc:creator>Ralf</dc:creator>
    <dc:date>2018-10-23T19:38:00Z</dc:date>
    <item>
      <title>Kerberos authentication with nac: change user or logout at the end system</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/kerberos-authentication-with-nac-change-user-or-logout-at-the/m-p/22632#M1496</link>
      <description>&lt;P&gt;Hello community,&lt;BR /&gt;&lt;BR /&gt;I´m testing NAC authentication with kerberos from X440-G2-switches.&lt;BR /&gt;&lt;BR /&gt;I have a few questions/issues:&lt;BR /&gt;&lt;BR /&gt;1. If I log on to a windows client against the AD, I see the session in the cli of the switch with show identity-management entries, but it will disappear after few minutes, even the PC is active and logged in. Is this okay?&lt;BR /&gt;&lt;BR /&gt;2. After logging in to the PC, I can see the username in NAC. But when I log out from the PC, I still see the username and the end system is accepted based on this.&lt;BR /&gt;&lt;BR /&gt;3. If I logout from the client and login with another user, I see the active user in the cli of the switch, but I have to reauthenticate the End System in NAC to see the other user that is currently logged in.&lt;BR /&gt;&lt;BR /&gt;I think, the switch should sent something like a notification to the NAC, if users log out or there is an user change. Is this possible?&lt;BR /&gt;&lt;BR /&gt;If there is a similiar post in the hub, please show me the link. I´ve searched the forum, but didn´t found any suitable topic.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance for your replies!&lt;BR /&gt;&lt;BR /&gt;Kind Regards, Ralf&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 19:38:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/kerberos-authentication-with-nac-change-user-or-logout-at-the/m-p/22632#M1496</guid>
      <dc:creator>Ralf</dc:creator>
      <dc:date>2018-10-23T19:38:00Z</dc:date>
    </item>
  </channel>
</rss>

