<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC - location based VLAN Assignment in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15911#M197</link>
    <description>We are using Extreme NAC as Proxy Radius with Microsoft NPS.&lt;BR /&gt;At the moments VLANs are assigned based on radius response from NPS which is working fine.&lt;BR /&gt;&lt;BR /&gt;What we would like to do now is the following:&lt;BR /&gt;&lt;BR /&gt;1. NPS responds with vlan name "client" if end system is successfully authenticated.&lt;BR /&gt;2. on switch1, if NPS response is "client" - vlan should be "client_1"&lt;BR /&gt;3. on switch2, if NPS response is "client" - vlan should be "client_2"&lt;BR /&gt;4. on switch3, if NPS response is "client" - vlan should be "client_3"&lt;BR /&gt;5. and so on&lt;BR /&gt;&lt;BR /&gt;So based on switch location group we want modify the vlan information from NPS for the final assignment of the end system.&lt;BR /&gt;Is this possible to implement with Extreme NAC?&lt;BR /&gt;</description>
    <pubDate>Thu, 20 Jan 2022 12:42:00 GMT</pubDate>
    <dc:creator>Thomas_Hilber</dc:creator>
    <dc:date>2022-01-20T12:42:00Z</dc:date>
    <item>
      <title>NAC - location based VLAN Assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15911#M197</link>
      <description>We are using Extreme NAC as Proxy Radius with Microsoft NPS.&lt;BR /&gt;At the moments VLANs are assigned based on radius response from NPS which is working fine.&lt;BR /&gt;&lt;BR /&gt;What we would like to do now is the following:&lt;BR /&gt;&lt;BR /&gt;1. NPS responds with vlan name "client" if end system is successfully authenticated.&lt;BR /&gt;2. on switch1, if NPS response is "client" - vlan should be "client_1"&lt;BR /&gt;3. on switch2, if NPS response is "client" - vlan should be "client_2"&lt;BR /&gt;4. on switch3, if NPS response is "client" - vlan should be "client_3"&lt;BR /&gt;5. and so on&lt;BR /&gt;&lt;BR /&gt;So based on switch location group we want modify the vlan information from NPS for the final assignment of the end system.&lt;BR /&gt;Is this possible to implement with Extreme NAC?&lt;BR /&gt;</description>
      <pubDate>Thu, 20 Jan 2022 12:42:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15911#M197</guid>
      <dc:creator>Thomas_Hilber</dc:creator>
      <dc:date>2022-01-20T12:42:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - location based VLAN Assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15912#M198</link>
      <description>Are you using policy with Extreme switches for the clients?&amp;nbsp; If so Policy Vlan Islands may be your solution.</description>
      <pubDate>Fri, 21 Jan 2022 17:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15912#M198</guid>
      <dc:creator>Brian_Anderson1</dc:creator>
      <dc:date>2022-01-21T17:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - location based VLAN Assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15913#M199</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Yes, NAC has the ability to provide a different authorization based on location group by utilizing location based policy mappings.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;You will have one rule that has one profile that mappings to a number of policy mappings that are used based on location criteria within the policy mapping itself.&lt;BR /&gt;&lt;BR /&gt;For instance:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;
&lt;/P&gt;&lt;P&gt;Unregistered with "Map to Location" "Any"&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="f721a6f0885443adbbdb9a511b84d07c.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2081iF7254A3ADF8025C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="f721a6f0885443adbbdb9a511b84d07c.png" alt="f721a6f0885443adbbdb9a511b84d07c.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Unregistered with "Map to location" "XCC". XCC being the IP address of the XCC controller.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="0368bd76b38746e2b5125f0ae7c57c06.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/880i891BD2F271A93552/image-size/large?v=v2&amp;amp;px=999" role="button" title="0368bd76b38746e2b5125f0ae7c57c06.png" alt="0368bd76b38746e2b5125f0ae7c57c06.png" /&gt;&lt;/span&gt;&lt;BR /&gt;So there are two policy mappings named "Unregistered", but if the XCC controller sends the RADIUS access request NAC will send a different policy named based on the policy mapping:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="8f918fa76d2b478282e9847ad7c40d3c.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5418iF61613BA89F17F33/image-size/large?v=v2&amp;amp;px=999" role="button" title="8f918fa76d2b478282e9847ad7c40d3c.png" alt="8f918fa76d2b478282e9847ad7c40d3c.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;So NAC would send "Unregistered role for BCS_WIRELESS" as the filter-id ONLY to the XCC. Any other switch would have the filter-id of "Unregistered" sent.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;So you would create a new policy mapping for each switch location group, and define the switches inside the location group.&lt;BR /&gt;&lt;BR /&gt;You'll probably be working with RFC 3580 for VLAN authorization. There is no difference. Instead of filer-id you would send a different VLAN ID.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;So:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;policyMappingName - Location group: switch 1 - VLAN 1&lt;BR /&gt;policyMappingName - Location group: switch 2 - VLAN 2&lt;BR /&gt;policyMappingName - Location group: switch 3 - VLAN 3&lt;BR /&gt;policyMappingName - Location group: switch 4 - VLAN 4&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;They key is that the policy mapping name must all be the same, and you should leave one of the policy mappings set to location of "any" or NAC will throw an error on enforce saying that there is no default policy mapping.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jan 2022 20:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15913#M199</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2022-01-22T20:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - location based VLAN Assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15914#M200</link>
      <description>Hi Brian! Unfortunately we have got a lot of older switches which are not policy capable, but we will have a look on this.</description>
      <pubDate>Wed, 26 Jan 2022 16:41:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15914#M200</guid>
      <dc:creator>Thomas_Hilber</dc:creator>
      <dc:date>2022-01-26T16:41:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - location based VLAN Assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15915#M201</link>
      <description>Hi Ryan,&lt;BR /&gt;&lt;BR /&gt;thank you this could be the way to go.&lt;BR /&gt;&lt;BR /&gt;But is NAC also capable to evaluate the VLAN name returned with&amp;nbsp; &lt;SPAN&gt;RFC 3580 from NPS server.&lt;BR /&gt;&lt;BR /&gt;Because we could also have the following situation when the end system is a printer:&lt;BR /&gt;1. NPS responds with vlan name "printer" if end system is successfully authenticated.&lt;BR /&gt;2. on switch1, if NPS response is "printer" - vlan should be "printer_1"&lt;BR /&gt;3. on switch2, if NPS response is "printer" - vlan should be "printer_2"&lt;BR /&gt;4. on switch3, if NPS response is "printer" - vlan should be "printer_3"&lt;BR /&gt;5. and so on&lt;BR /&gt;&lt;BR /&gt;So it would be a two stage process:&lt;BR /&gt;first look into vlan returned by NPS&lt;BR /&gt;then assign the "new" vlan name based on switch location&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;</description>
      <pubDate>Wed, 26 Jan 2022 16:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15915#M201</guid>
      <dc:creator>Thomas_Hilber</dc:creator>
      <dc:date>2022-01-26T16:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - location based VLAN Assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15916#M202</link>
      <description>Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If NPS is already providing the correct RADIUS attributes you can configure the profile to just pass through what NPS has already provided. In the NAC profile deselect "Replace RADIUS response attributes" and it will pass to the client whatever NPS send to NAC.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. NPS responds with vlan name "printer" if end system is successfully authenticated.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. on switch1, if NPS response is "printer" - vlan should be "printer_1" --&amp;gt; NAC passes through RFC 3580 VLAN to client&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. on switch2, if NPS response is "printer" - vlan should be "printer_2" --&amp;gt; NAC passes through RFC 3580 VLAN to client&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4. on switch3, if NPS response is "printer" - vlan should be "printer_3" --&amp;gt; NAC passes through RFC 3580 VLAN to client&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5. and so on&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;NAC can also evaluate RADIUS AVPs and they can be used in the rule criteria to make a rule decision. There is a RADIUS user group criteria where you can define the AVP returned by NPS in order to hit a specific rule. Eg. If NPS returns RFC 3580 tunnel-private-group of 7 that can be used as a criteria to match a group.&amp;nbsp;&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Jan 2022 16:59:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15916#M202</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2022-01-26T16:59:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - location based VLAN Assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15917#M203</link>
      <description>why are you proxying the requests to the NPS? What values and sources uses the NPS for decision?&lt;BR /&gt;&lt;BR /&gt;From my current point of view, it would be much easier for you, to only use the NAC.&lt;BR /&gt;I don't know if NAC is able to modify the vlan-tunnel-atribute received from the NPS.</description>
      <pubDate>Wed, 26 Jan 2022 19:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15917#M203</guid>
      <dc:creator>PeterK</dc:creator>
      <dc:date>2022-01-26T19:23:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC - location based VLAN Assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15918#M204</link>
      <description>&lt;P&gt;This is the way I would recommend to do it:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;1. NAC rule for Printers:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ed6dbb36721940d9884fbfbcc4a8a6af.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5799iC498E1CBAC92DD4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="ed6dbb36721940d9884fbfbcc4a8a6af.png" alt="ed6dbb36721940d9884fbfbcc4a8a6af.png" /&gt;&lt;/span&gt;&lt;BR /&gt;2 Policy Mapping for Printers has multiple mappings with location group per switch:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="55e62ad7df1640e4a8a5e47fe1c7213b.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/837i6E6DF3AD2CE3CE6E/image-size/large?v=v2&amp;amp;px=999" role="button" title="55e62ad7df1640e4a8a5e47fe1c7213b.png" alt="55e62ad7df1640e4a8a5e47fe1c7213b.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="5fd64a39f9e64885b965d676b9d4b44e.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2491i044AACEA309B5E9B/image-size/large?v=v2&amp;amp;px=999" role="button" title="5fd64a39f9e64885b965d676b9d4b44e.png" alt="5fd64a39f9e64885b965d676b9d4b44e.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;All printers will hit the "Printer" rule and NAC will send different RFC 3580 VLAN authorizations based on the switch that sent the authentication request.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Brian's solution is a one too. If Policy VLAN islands or policy isn't supported by the older or 3rd party devices as long as they can process an RFC 3580 VLAN authorization with VLAN name instead of VLAN ID you can configure the same VLAN name on all switches, and map it to a different VLAN ID per switch.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;
&lt;/P&gt;&lt;P&gt;So:&lt;BR /&gt;Switch 1 would would have "Printer" VLAN be VLAN 1&lt;BR /&gt;Switch 2 would would have "Printer" VLAN be VLAN 2&lt;BR /&gt;Switch 3 would would have "Printer" VLAN be VLAN 3&lt;BR /&gt;&lt;BR /&gt;NAC would always send back RFC 3580 VLAN NAME (Printer), and the individual switch can provision the unique VLAN per switch accordingly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;
&lt;/P&gt;&lt;P&gt;Policy VLAN Islands just makes it easy to deploy and manage this type of configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 21:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-location-based-vlan-assignment/m-p/15918#M204</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2022-01-26T21:19:00Z</dc:date>
    </item>
  </channel>
</rss>

