<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Wireless Controller integration with NAC in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/wireless-controller-integration-with-nac/m-p/29610#M2917</link>
    <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
This is a new behavior with NetSight 6.2. NetSight NAC Manager will now populate the end systems table with Wireless client events if they are sent to NetSight.&lt;BR /&gt;
&lt;BR /&gt;
Please check out the following article:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/Solution/Seeing-Non-NAC-End-Systems-in-NAC-Manager/?q=non-nac+end+systems&amp;amp;#38;l=en_US&amp;amp;#38;fs=Search&amp;amp;#38;pn=1" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/Solution/Seeing-Non-NAC-End-Systems-in-NAC-Manage...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
These End Systems are not authenticated, so they do not count towards your End System License count.&lt;BR /&gt;
&lt;BR /&gt;
Let me know if you have any additional questions.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
-Ryan</description>
    <pubDate>Fri, 10 Jul 2015 17:36:00 GMT</pubDate>
    <dc:creator>Ryan_Yacobucci</dc:creator>
    <dc:date>2015-07-10T17:36:00Z</dc:date>
    <item>
      <title>Wireless Controller integration with NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/wireless-controller-integration-with-nac/m-p/29608#M2915</link>
      <description>Hi&lt;BR /&gt;
We are running a C5210 controller with V9.15.07.0008 and NMS V6.2.0.199&lt;BR /&gt;
We have a IA-A-20 NAC appliance also deployed.&lt;BR /&gt;
We have 2 different VNS's configured, one for the production environment and one for Public internet access.&lt;BR /&gt;
&lt;BR /&gt;
The configuration of two VNS's is as follows:&lt;BR /&gt;
&lt;OL&gt; 
&lt;LI&gt;Production VNS&lt;/LI&gt;&lt;/OL&gt;&lt;UL&gt; 
&lt;LI&gt;Configured to use 802.1x Authentication 
&lt;/LI&gt;&lt;LI&gt;802.1x Authentication utilizes a Microsoft NPS server for authentication 
&lt;/LI&gt;&lt;LI&gt;VNS utilizes a "Bridge @ AP" topology&lt;/LI&gt;&lt;/UL&gt;     2. Public Internet VNS&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;Configured to use Mac Authentication 
&lt;/LI&gt;&lt;LI&gt;MAC Authentication utilizes the NAC Appliance server for authentication 
&lt;/LI&gt;&lt;LI&gt;VNS utilizes a "Bridge @ EWC 
&lt;/LI&gt;&lt;LI&gt;DHCP is provided by Service Provider 
&lt;/LI&gt;&lt;LI&gt;The Public Internet Topology interface is configured with a IP address in the Service provider network 
&lt;/LI&gt;&lt;LI&gt;NAC integration is enabled with the IP address of the NAC appliance configured.&lt;/LI&gt;&lt;/UL&gt;If we look in NAC Manager and select "All NAC Appliances" we notice that the "End Systems" tab lists all wireless clients, including the Production clients. &lt;BR /&gt;
If we select the individual NAC appliance it only shows the "End systems" connected to the "Public Internet VNS. We are also missing device type information but the IP's resolve&lt;BR /&gt;
&lt;BR /&gt;
So now for the questions:&lt;BR /&gt;
&lt;BR /&gt;
&lt;OL&gt; 
&lt;LI&gt;Why do we see the Production clients in NAC Manager as "End systems" even though the Production VNS is not configured to use the NAC at all for authentication? 
&lt;/LI&gt;&lt;LI&gt;Does the Production "End systems" count towards my "End system" license? 
&lt;/LI&gt;&lt;LI&gt;Oneview reports the total unique users as the total of both the Production and Public Internet "End systems" we would only like to see the "Public internet" End systems.  &lt;/LI&gt;&lt;/OL&gt;When we deploy the same solution but on older code versions (C5210 = V9.01.02.0017 and NMS 6.1.0.135) we only see the "End systems" for the "Public Internet" and NAC also reports on the Device types ect.&lt;BR /&gt;
&lt;BR /&gt;
This question should probably go to GTAC but i thought lets ask the community first.... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 09 Jul 2015 02:32:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/wireless-controller-integration-with-nac/m-p/29608#M2915</guid>
      <dc:creator>Andre_Brits_Kan</dc:creator>
      <dc:date>2015-07-09T02:32:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Controller integration with NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/wireless-controller-integration-with-nac/m-p/29609#M2916</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
I've run into the same "problem" that I'd see clients from another cloud controller even that one isn't aware of the NAC - so it seems that by integrating the controller into Netsight Console &amp;amp; OneView that NAC will show the clients.&lt;BR /&gt;
&lt;BR /&gt;
The only thing that I'd contribute to your post is the "device type" issue of your second VNS.&lt;BR /&gt;
You need to forward the DHCP request also to the NAC.&lt;BR /&gt;
There are some options - not sure which one is the right one in your deployment.&lt;BR /&gt;
- if you use routed/bridge@EWC and DHCP relay = add the ISP DHCP and NAC IP&lt;BR /&gt;
- if bridge@EWC and there is a router in between you'd configure DHCP helper to foward it to the ISP&amp;amp;NAC&lt;BR /&gt;
&lt;BR /&gt;
-Ron</description>
      <pubDate>Thu, 09 Jul 2015 03:20:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/wireless-controller-integration-with-nac/m-p/29609#M2916</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2015-07-09T03:20:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless Controller integration with NAC</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/wireless-controller-integration-with-nac/m-p/29610#M2917</link>
      <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
This is a new behavior with NetSight 6.2. NetSight NAC Manager will now populate the end systems table with Wireless client events if they are sent to NetSight.&lt;BR /&gt;
&lt;BR /&gt;
Please check out the following article:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/Solution/Seeing-Non-NAC-End-Systems-in-NAC-Manager/?q=non-nac+end+systems&amp;amp;#38;l=en_US&amp;amp;#38;fs=Search&amp;amp;#38;pn=1" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/Solution/Seeing-Non-NAC-End-Systems-in-NAC-Manage...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
These End Systems are not authenticated, so they do not count towards your End System License count.&lt;BR /&gt;
&lt;BR /&gt;
Let me know if you have any additional questions.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
-Ryan</description>
      <pubDate>Fri, 10 Jul 2015 17:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/wireless-controller-integration-with-nac/m-p/29610#M2917</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2015-07-10T17:36:00Z</dc:date>
    </item>
  </channel>
</rss>

