<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Using Facebook for NAC Login in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15632#M150</link>
    <description>Hi John,&lt;BR /&gt;
&lt;BR /&gt;
I've already tried this config... Both L7 hostname rule on wireless controller (and creating the DNS proxy domains as L7 rules) or Allowed Domains at NAC and I got the same results.&lt;BR /&gt;
&lt;BR /&gt;
As I said, Google and MS works perfectly, but it seems that the Controller L7 rules for Facebook (hostname facebook.com) aren't working, and it still trying to redirect (it doesn't happen with the google or MS rules).&lt;BR /&gt;
&lt;BR /&gt;
Maybe a Controller issue? There's any way to debug it (seeing what got "allowed" and what hits the botton Redirect rule)?&lt;BR /&gt;
&lt;BR /&gt;
Thanks!&lt;BR /&gt;
&lt;BR /&gt;
-Leo</description>
    <pubDate>Thu, 15 Feb 2018 22:56:00 GMT</pubDate>
    <dc:creator>LeoP1</dc:creator>
    <dc:date>2018-02-15T22:56:00Z</dc:date>
    <item>
      <title>Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15630#M148</link>
      <description>Hi Guys,&lt;BR /&gt;
&lt;BR /&gt;
Resuming this conversation, I'm still in trouble..&lt;BR /&gt;
&lt;BR /&gt;
I have a customer willing to enable social media authentication with NAC (ExtremeWireless 10.41.02.0014 and NAC 8.1.1.4). His TOP priority is to enable Facebook login.&lt;BR /&gt;
&lt;BR /&gt;
I've already configured Google and Microsoft logins and both work like a charm (using L7 rules B@AP topology), but Facebook still a mess.&lt;BR /&gt;
&lt;BR /&gt;
The L7 rules allowing Facebook (default and the custom I've created) seems not to work.&lt;BR /&gt;
&lt;BR /&gt;
Already tried using the HTTP NAC Portal, but when it jumps to Facebook I got the HSTS problem (when enabling HTTPS redirection) or no access (if I deny HTTPS after allow L7 rules). &lt;BR /&gt;
&lt;BR /&gt;
The only way I found is to allow all HTTPS, but this is unacceptable for the customer.&lt;BR /&gt;
&lt;BR /&gt;
Already tried to mess with "Allowed Sites" on NAC, but I had no luck.&lt;BR /&gt;
&lt;BR /&gt;
I'm running out of ideas (and time)... Anyone have any idea?&lt;BR /&gt;
&lt;BR /&gt;
Thanks!&lt;BR /&gt;
&lt;BR /&gt;
-Leo  Note: This conversation was created from a &lt;A href="https://community.extremenetworks.com/extreme/topics/facebook-login-k818x72o18tvf/replies/19322506" target="_blank" rel="nofollow noreferrer noopener"&gt;reply&lt;/A&gt; on: &lt;A href="https://community.extremenetworks.com/extreme/topics/facebook-login-k818x72o18tvf" target="_blank" rel="nofollow noreferrer noopener"&gt;Facebook login on NAC&lt;/A&gt;.</description>
      <pubDate>Thu, 15 Feb 2018 05:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15630#M148</guid>
      <dc:creator>LeoP1</dc:creator>
      <dc:date>2018-02-15T05:04:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15631#M149</link>
      <description>Hi Leonardo,&lt;BR /&gt;
&lt;BR /&gt;
I believe the "Special Deployment Considerations" section in the link below has the information you're looking for in terms of which domains you must allow for Facebook Registration to function properly.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/portal_config/l_ov_ia_ht_oauth_facebook.htm?Highlight=facebook" target="_blank" rel="nofollow noreferrer noopener"&gt;http://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/portal_config/l_ov_i...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Please let us know if that doesn't work.&lt;BR /&gt;
&lt;BR /&gt;
Thank you,&lt;BR /&gt;
&lt;BR /&gt;
John</description>
      <pubDate>Thu, 15 Feb 2018 22:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15631#M149</guid>
      <dc:creator>John_Moore</dc:creator>
      <dc:date>2018-02-15T22:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15632#M150</link>
      <description>Hi John,&lt;BR /&gt;
&lt;BR /&gt;
I've already tried this config... Both L7 hostname rule on wireless controller (and creating the DNS proxy domains as L7 rules) or Allowed Domains at NAC and I got the same results.&lt;BR /&gt;
&lt;BR /&gt;
As I said, Google and MS works perfectly, but it seems that the Controller L7 rules for Facebook (hostname facebook.com) aren't working, and it still trying to redirect (it doesn't happen with the google or MS rules).&lt;BR /&gt;
&lt;BR /&gt;
Maybe a Controller issue? There's any way to debug it (seeing what got "allowed" and what hits the botton Redirect rule)?&lt;BR /&gt;
&lt;BR /&gt;
Thanks!&lt;BR /&gt;
&lt;BR /&gt;
-Leo</description>
      <pubDate>Thu, 15 Feb 2018 22:56:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15632#M150</guid>
      <dc:creator>LeoP1</dc:creator>
      <dc:date>2018-02-15T22:56:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15633#M151</link>
      <description>Hi guys, &lt;BR /&gt;
&lt;BR /&gt;
I was working on some tests, and I found that, by some odd reason, the L7 hostname rule for facebook.com seems to be really ignored by AP (creating other similar rules works fine).&lt;BR /&gt;
&lt;BR /&gt;
It looks like the facebook.com is getting redirected instead of allowed...&lt;BR /&gt;
&lt;BR /&gt;
Any ideas?</description>
      <pubDate>Fri, 16 Feb 2018 02:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15633#M151</guid>
      <dc:creator>LeoP1</dc:creator>
      <dc:date>2018-02-16T02:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15634#M152</link>
      <description>Hi Leo,&lt;BR /&gt;
&lt;BR /&gt;
I spoke with the developer who is in charge of the guest registration functionality and he is now looking into it. Let me know if you have any other questions or if you uncover any additional clues.&lt;BR /&gt;
&lt;BR /&gt;
Thanks again!&lt;BR /&gt;
&lt;BR /&gt;
John</description>
      <pubDate>Sat, 17 Feb 2018 02:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15634#M152</guid>
      <dc:creator>John_Moore</dc:creator>
      <dc:date>2018-02-17T02:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15635#M153</link>
      <description>As far as I unterstand that is a issue with the AP L7 rule and has nothing to do with EMC/Control so someone from the IdentiFi team need to look into it.&lt;BR /&gt;
&lt;BR /&gt;
Here another post that looks like the same issue....&lt;BR /&gt;
&lt;A href="https://community.extremenetworks.com/extreme/topics/l7-role-versio-10-21-01" target="_blank" rel="nofollow noreferrer noopener"&gt;https://community.extremenetworks.com/extreme/topics/l7-role-versio-10-21-01&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 17 Feb 2018 02:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15635#M153</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-02-17T02:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15636#M154</link>
      <description>Leo, what AP model is used in the deployment ?</description>
      <pubDate>Sat, 17 Feb 2018 03:10:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15636#M154</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-02-17T03:10:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15637#M155</link>
      <description>Hi Ronald,&lt;BR /&gt;
&lt;BR /&gt;
I completely agree with you... It's an IdentiFi issue and not EMC/NAC problem.&lt;BR /&gt;
&lt;BR /&gt;
I'm testing with a B@AP tagged topology (upgraded to the latest version today just to make sure) and 3805i and 3825i APs.&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
&lt;BR /&gt;
-Leo</description>
      <pubDate>Sat, 17 Feb 2018 03:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15637#M155</guid>
      <dc:creator>LeoP1</dc:creator>
      <dc:date>2018-02-17T03:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15638#M156</link>
      <description>Could you post a screenshot of the unauth and auth role rules.</description>
      <pubDate>Sat, 17 Feb 2018 03:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15638#M156</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-02-17T03:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15639#M157</link>
      <description>Sure!&lt;BR /&gt;
&lt;BR /&gt;
Follows some screenshots. The Auth role works fine.&lt;BR /&gt;
&lt;BR /&gt;
Please, forgive some additional L7 hostname rules I added just to try to make it work (after some sniffing), but without success.&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
-Leo&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-54806-d497of-UnAuth-1_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4789i379C25A092B18E99/image-size/large?v=v2&amp;amp;px=999" role="button" title="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-54806-d497of-UnAuth-1_inline.png" alt="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-54806-d497of-UnAuth-1_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt; &lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-32766-1k0de4f-UnAuth-2_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/764i6686308B2D51F012/image-size/large?v=v2&amp;amp;px=999" role="button" title="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-32766-1k0de4f-UnAuth-2_inline.png" alt="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-32766-1k0de4f-UnAuth-2_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-54806-1922ln1-UnAuth-3_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4741iB7082886B5C1135B/image-size/large?v=v2&amp;amp;px=999" role="button" title="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-54806-1922ln1-UnAuth-3_inline.png" alt="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-54806-1922ln1-UnAuth-3_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-9411-1s03f3y-Auth-1_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3060i826AABEACFF7B606/image-size/large?v=v2&amp;amp;px=999" role="button" title="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-9411-1s03f3y-Auth-1_inline.png" alt="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-9411-1s03f3y-Auth-1_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-59389-vbcguz-Auth-2_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1303iEA8259795C59CD1B/image-size/large?v=v2&amp;amp;px=999" role="button" title="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-59389-vbcguz-Auth-2_inline.png" alt="57f808849fd64f988a46f6cb070815cb_RackMultipart20180216-59389-vbcguz-Auth-2_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Feb 2018 03:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15639#M157</guid>
      <dc:creator>LeoP1</dc:creator>
      <dc:date>2018-02-17T03:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15640#M158</link>
      <description>Hi Leonardo &lt;BR /&gt;
&lt;BR /&gt;
I think it would be best if you open a case with GTAC, could you please take a packet capture on the client so we can take a look at the HTTP traffic?&lt;BR /&gt;
&lt;BR /&gt;
-Gareth</description>
      <pubDate>Sat, 17 Feb 2018 03:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/15640#M158</guid>
      <dc:creator>Gareth_Mitchell</dc:creator>
      <dc:date>2018-02-17T03:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/120057#M12818</link>
      <description>&lt;P&gt;Hi Leo,&lt;/P&gt;&lt;P&gt;I get where you’re stuck. Facebook login is always a bit trickier with NAC compared to Google or Microsoft because of the strict HSTS enforcement. The redirect loop usually happens because the NAC portal can’t properly handle the HTTPS handshake before Facebook forces secure connections. That’s why you’re only seeing success when you allow all HTTPS traffic.&lt;/P&gt;&lt;P&gt;A cleaner way is to explicitly whitelist the domains that Facebook needs for authentication. Instead of just facebook.com, you’ll need to add a handful of supporting domains like fbcdn.net, akamaihd.net, facebook.net, and sometimes messenger.com into the NAC “Allowed Sites” list. This ensures the login page and supporting scripts can load without you having to open HTTPS globally. Also, double-check that your L7 rule isn’t getting bypassed by DNS resolution quirks—sometimes pushing a manual DNS override for Facebook helps stabilize access.&lt;/P&gt;&lt;P&gt;Another option is to switch your NAC portal to use full HTTPS instead of HTTP+redirect. You’ll need a proper SSL cert trusted by browsers to avoid HSTS blocks. That way the initial handshake is already secure, and Facebook won’t complain when the login page tries to load.&lt;/P&gt;&lt;P&gt;Think of it like Snapchat filters on &lt;A href="https://snapplanetshub.com/" target="_blank"&gt;https://snapplanetshub.com/&lt;/A&gt;&amp;nbsp;you don’t just unlock one effect, you have to load all the hidden assets in the background to make it work. Facebook login is similar: unless NAC knows all the “extra filters” (domains and scripts) that Facebook depends on, the experience breaks halfway. Unlock all those, and the customer’s login flow should snap right into place.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2025 10:20:33 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/120057#M12818</guid>
      <dc:creator>jerrygen</dc:creator>
      <dc:date>2025-08-25T10:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Using Facebook for NAC Login</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/120774#M12863</link>
      <description>&lt;P&gt;The issue with enabling Facebook login on ExtremeWireless NAC is primarily related to HTTPS and HSTS enforcement, which makes it different from Google or Microsoft logins. Facebook enforces strict HTTPS with HSTS, so any attempt to intercept or redirect traffic at Layer 7 (L7 rules) without proper certificate handling will fail. When you enable HTTPS redirection on the NAC portal, the HSTS policy prevents the browser from accepting the NAC’s certificate, causing login failures, and if you disable HTTPS enforcement, the portal cannot communicate securely with Facebook, resulting in no access.&lt;/P&gt;&lt;P&gt;Unlike Google or Microsoft, Facebook does not allow man-in-the-middle inspection without proper SSL termination, so L7 rules alone aren’t sufficient. The recommended approach is to either use NAC’s built-in social media authentication module specifically designed for Facebook (which handles OAuth and HTTPS properly) or configure SSL bridging with trusted certificates to allow secure Facebook login without opening full HTTPS access to all sites. Without one of these approaches, restricting access while supporting Facebook login is extremely difficult due to HSTS and HTTPS enforcement.&lt;/P&gt;&lt;P&gt;Additionally, when considering social media logins like Facebook, it’s useful to keep in mind how other apps handle connections, such as Snapchat with its &lt;STRONG&gt;Snapchat Planet&lt;/STRONG&gt; feature. Just like Facebook, Snapchat relies on secure connections and multiple backend services to provide real-time features and location-based interactions. Any NAC configuration that attempts to restrict HTTPS or filter traffic too aggressively can interfere with these kinds of features, so planning social media authentication requires understanding that apps like &lt;A href="https://planetssnapchat.com/" target="_self"&gt;Snapchat&lt;/A&gt; Planet&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or any feature that relies on multiple endpoints and secure connections—may behave similarly under strict network policies. This highlights the importance of using proper authentication modules or SSL handling rather than broad allow-all rules.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2025 15:49:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/using-facebook-for-nac-login/m-p/120774#M12863</guid>
      <dc:creator>alijaan897</dc:creator>
      <dc:date>2025-11-14T15:49:18Z</dc:date>
    </item>
  </channel>
</rss>

