<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Netlogin for NAC not working on Extreme x440 and x430 Switches in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34233#M3792</link>
    <description>That should do the trick...&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://documentation.extremenetworks.com/exos_22.1/exos_21_1/netlogin/c_configuring-dynamic-vlans-for-network-login.shtml" target="_blank" rel="nofollow noreferrer noopener"&gt;http://documentation.extremenetworks.com/exos_22.1/exos_21_1/netlogin/c_configuring-dynamic-vlans-fo...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
# enable the switch to create/delete VLANs d&lt;BR /&gt;
configure netlogin dynamic-vlan enable&lt;BR /&gt;
&lt;BR /&gt;
# enable the switch to create/delete the VLAN tagged on the uplink - in this example on port#1&lt;BR /&gt;
# only needed if you'd like to have the VLAN also on the uplink&lt;BR /&gt;
configure netlogin dynamic-vlan uplink-ports 1&lt;BR /&gt;
&lt;BR /&gt;
* X430-48t.62 # sh log12/21/2016 23:55:28.49 &lt;I&gt; Network Login MAC user 14DAE9EC029F logged in MAC 14:DA:E9:EC:02:9F port 33 VLAN(s) "SYS_VLAN_0234", authentication Radius&lt;BR /&gt;
12/21/2016 23:55:28.26 &lt;I&gt; Port 33 link UP at speed 1 Gbps and full-duplex&lt;BR /&gt;
&lt;BR /&gt;&lt;/I&gt;&lt;/I&gt;</description>
    <pubDate>Thu, 22 Dec 2016 04:58:00 GMT</pubDate>
    <dc:creator>Ronald_Dvorak</dc:creator>
    <dc:date>2016-12-22T04:58:00Z</dc:date>
    <item>
      <title>Netlogin for NAC not working on Extreme x440 and x430 Switches</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34227#M3786</link>
      <description>We have deployed NAC and applied the rules and enabled Netlogin on x430 and x440 switches with ExtremeXOS version 16.2.1.6. The MAC authentication shows passed in Netsight and in switch however its not applied in reality if the switch doesnt have the ports configured to the repective vlan. &lt;BR /&gt;
We are lost in this are we missing something in the configuration.&lt;BR /&gt;
&lt;BR /&gt;
Here is the configuration on the switch.&lt;BR /&gt;
&lt;BR /&gt;
create vlan NACauth&lt;BR /&gt;
configure netlogin vlan NACauth&lt;BR /&gt;
enable netlogin dot1x mac &lt;BR /&gt;
configure netlogin authentication protocol-order dot1x mac web-based&lt;BR /&gt;
configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48 password voxmac&lt;BR /&gt;
enable netlogin ports 1-23 dot1x &lt;BR /&gt;
enable netlogin ports 1-23 mac &lt;BR /&gt;
configure netlogin ports 1-23 mode mac-based-vlans&lt;BR /&gt;
configure netlogin ports 1-23 no-restart&lt;BR /&gt;</description>
      <pubDate>Thu, 22 Dec 2016 03:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34227#M3786</guid>
      <dc:creator>Sandeep_Sriniva</dc:creator>
      <dc:date>2016-12-22T03:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin for NAC not working on Extreme x440 and x430 Switches</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34228#M3787</link>
      <description>Are you enabling authentication on the ports? &lt;BR /&gt;
&lt;BR /&gt;
configure netlogin port 1-23 authentication mode optional&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 22 Dec 2016 03:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34228#M3787</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2016-12-22T03:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin for NAC not working on Extreme x440 and x430 Switches</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34229#M3788</link>
      <description>There is no such command in EXOS 16.x&lt;BR /&gt;
&lt;BR /&gt;
Is there any analog for it?&lt;BR /&gt;
&lt;BR /&gt;
Thanks</description>
      <pubDate>Thu, 22 Dec 2016 03:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34229#M3788</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2016-12-22T03:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin for NAC not working on Extreme x440 and x430 Switches</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34230#M3789</link>
      <description>Yes, we are enabling the authentication on the Ports we have 5 vlans and once the MAC address is reflected on the Netsight we move them to particular group.&lt;BR /&gt;
&lt;BR /&gt;
Example - I have connected laptop on port 20 and vlan 20 has to assigned after I move it to the group in Netsight, this is not working until the vlan 20 is configured on the switch.&lt;BR /&gt;
&lt;BR /&gt;
Netsight should override the switch configuration, we have G2 switches which are working perfectly fine.</description>
      <pubDate>Thu, 22 Dec 2016 03:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34230#M3789</guid>
      <dc:creator>Sandeep_Sriniva</dc:creator>
      <dc:date>2016-12-22T03:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin for NAC not working on Extreme x440 and x430 Switches</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34231#M3790</link>
      <description>I'm using a 460G2, but the config should be the same.      In the end I added the switches to nac mgr as manual switches and did the following config in cli:        # Module netLogin configuration.  #  enable netlogin dot1x mac  configure netlogin authentication protocol-order dot1x mac web-based  enable netlogin ports 1:1-48 dot1x  enable netlogin ports 1:1-48 mac  configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48 encrypted &lt;SNIP&gt;  configure netlogin mac timers reauth-period 90  configure netlogin mac username format hyphenated      # Module aaa configuration.  #    configure radius netlogin primary server &lt;NAC ip=""&gt; 1812 client-ip &lt;SWITCH ip=""&gt; vr VR-Default  configure radius netlogin primary shared-secret encrypted &lt;SNIP&gt;  configure radius netlogin secondary server &lt;NAC ip=""&gt; 1812 client-ip &lt;SWITCH ip=""&gt; vr VR-Default  configure radius netlogin secondary shared-secret encrypted &lt;SNIP&gt;  configure radius-accounting netlogin primary server &lt;NAC ip=""&gt; 1813 client-ip &lt;SWITCH ip=""&gt; vr VR-Default  configure radius-accounting netlogin primary shared-secret encrypted &lt;SNIP&gt;  configure radius-accounting netlogin secondary server &lt;NAC ip=""&gt; 1813 client-ip &lt;SWITCH ip=""&gt;  configure radius timeout 20  configure radius mgmt-access timeout 20  configure radius netlogin timeout 20  enable radius-accounting  disable radius-accounting mgmt-access  enable radius-accounting netlogin&lt;/SWITCH&gt;&lt;/NAC&gt;&lt;/SNIP&gt;&lt;/SWITCH&gt;&lt;/NAC&gt;&lt;/SNIP&gt;&lt;/SWITCH&gt;&lt;/NAC&gt;&lt;/SNIP&gt;&lt;/SWITCH&gt;&lt;/NAC&gt;&lt;/SNIP&gt;</description>
      <pubDate>Thu, 22 Dec 2016 04:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34231#M3790</guid>
      <dc:creator>Keith_Obermeier</dc:creator>
      <dc:date>2016-12-22T04:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin for NAC not working on Extreme x440 and x430 Switches</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34232#M3791</link>
      <description>Did you see a error message like the below one in the switch...&lt;BR /&gt;
&lt;BR /&gt;
# show log&lt;BR /&gt;
&lt;BR /&gt;
12/21/2016 23:25:18.73 &lt;NL.INVALIDVLANTAGVSA&gt; VLAN Tag 234 specified in Radius VSA does not exist on the switch or cannot be created. Please verify RADIUS configuration&lt;BR /&gt;
&lt;BR /&gt;&lt;/NL.INVALIDVLANTAGVSA&gt;</description>
      <pubDate>Thu, 22 Dec 2016 04:32:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34232#M3791</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2016-12-22T04:32:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin for NAC not working on Extreme x440 and x430 Switches</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34233#M3792</link>
      <description>That should do the trick...&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://documentation.extremenetworks.com/exos_22.1/exos_21_1/netlogin/c_configuring-dynamic-vlans-for-network-login.shtml" target="_blank" rel="nofollow noreferrer noopener"&gt;http://documentation.extremenetworks.com/exos_22.1/exos_21_1/netlogin/c_configuring-dynamic-vlans-fo...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
# enable the switch to create/delete VLANs d&lt;BR /&gt;
configure netlogin dynamic-vlan enable&lt;BR /&gt;
&lt;BR /&gt;
# enable the switch to create/delete the VLAN tagged on the uplink - in this example on port#1&lt;BR /&gt;
# only needed if you'd like to have the VLAN also on the uplink&lt;BR /&gt;
configure netlogin dynamic-vlan uplink-ports 1&lt;BR /&gt;
&lt;BR /&gt;
* X430-48t.62 # sh log12/21/2016 23:55:28.49 &lt;I&gt; Network Login MAC user 14DAE9EC029F logged in MAC 14:DA:E9:EC:02:9F port 33 VLAN(s) "SYS_VLAN_0234", authentication Radius&lt;BR /&gt;
12/21/2016 23:55:28.26 &lt;I&gt; Port 33 link UP at speed 1 Gbps and full-duplex&lt;BR /&gt;
&lt;BR /&gt;&lt;/I&gt;&lt;/I&gt;</description>
      <pubDate>Thu, 22 Dec 2016 04:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34233#M3792</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2016-12-22T04:58:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin for NAC not working on Extreme x440 and x430 Switches</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34234#M3793</link>
      <description>Here are logs...&lt;BR /&gt;
12/22/2016 10:24:53.41 &lt;STP.INBPDU.DROP&gt; Port=47: No associated STP port fo                                                                                        r STP Domain tag 1 (Rate-limited)12/22/2016 10:24:47.43 &lt;I&gt; Authentication failed for Net                                                                                        work Login 802.1x user host/TRYNTA02                           Mac 6C:0B:84:08:B7:DE port                                                                                         12&lt;BR /&gt;
12/22/2016 10:24:45.40 &lt;I&gt; Login passed for user admin through t                                                                                        elnet (10.210.1.241)&lt;BR /&gt;
12/22/2016 10:24:41.41 &lt;STP.INBPDU.DROP&gt; Port=47: No associated STP port fo                                                                                        r STP Domain tag 1 (Rate-limited)&lt;BR /&gt;
12/22/2016 10:24:29.84 &lt;I&gt; Authentication failed for Net                                                                                        work Login 802.1x user host/CANNTA05                           Mac 6C:AE:8B:0B:DF:51 port                                                                                         14&lt;BR /&gt;
12/22/2016 10:24:29.41 &lt;STP.INBPDU.DROP&gt; Port=47: No associated STP port fo                                                                                        r STP Domain tag 1 (Rate-limited)&lt;BR /&gt;
12/22/2016 10:24:23.14 &lt;I&gt; Authentication failed for Net                                                                                        work Login 802.1x user host/VGNTA02                           Mac 6C:AE:8B:0B:DF:C5 port 3                                                                                        3&lt;BR /&gt;
12/22/2016 10:24:17.41 &lt;STP.INBPDU.DROP&gt; Port=47: No associated STP port fo                                                                                        r STP Domain tag 1 (Rate-limited)&lt;BR /&gt;
12/22/2016 10:24:05.40 &lt;STP.INBPDU.DROP&gt; Port=47: No associated STP port fo                                                                                        r STP Domain tag 1 (Rate-limited)&lt;BR /&gt;
12/22/2016 10:24:04.37 &lt;I&gt; Authentication failed for Net                                                                                        work Login 802.1x user host/CANNTA03                           Mac 6C:AE:8B:0B:E5:05 port                                                                                         4&lt;BR /&gt;
12/22/2016 10:24:01.71 &lt;I&gt; Authentication failed for Net                                                                                        work Login 802.1x user host/CANNTA02                           Mac 6C:AE:8B:0B:E3:DE port                                                                                         25&lt;BR /&gt;
12/22/2016 10:23:58.83 &lt;I&gt; Authentication failed for Net                                                                                        work Login 802.1x user host/CANNTA08                           Mac 6C:AE:8B:0B:E3:B3 port                                                                                         26&lt;BR /&gt;
&lt;BR /&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/STP.INBPDU.DROP&gt;&lt;/STP.INBPDU.DROP&gt;&lt;/I&gt;&lt;/STP.INBPDU.DROP&gt;&lt;/I&gt;&lt;/STP.INBPDU.DROP&gt;&lt;/I&gt;&lt;/I&gt;&lt;/STP.INBPDU.DROP&gt;</description>
      <pubDate>Thu, 22 Dec 2016 17:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34234#M3793</guid>
      <dc:creator>Sandeep_Sriniva</dc:creator>
      <dc:date>2016-12-22T17:27:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin for NAC not working on Extreme x440 and x430 Switches</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34235#M3794</link>
      <description>Finally found out the mistake, which applying policy on the switch I had selected VLAN_Name instead of VLAN_ID after changing it, enforced the policy and tested. Its working !!! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 23 Dec 2016 17:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-for-nac-not-working-on-extreme-x440-and-x430-switches/m-p/34235#M3794</guid>
      <dc:creator>Sandeep_Sriniva</dc:creator>
      <dc:date>2016-12-23T17:50:00Z</dc:date>
    </item>
  </channel>
</rss>

