<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: How to create a single SSID with multiple vlans ? in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35622#M4064</link>
    <description>On the VNS page of the wireless controller you have (from top to bottom) : Global , Sites, Virtual Networks, WLAN Sevices , Roles , Class of Service , Topologies . &lt;BR /&gt;
CoS is Class of Service . &lt;BR /&gt;
Roles and Class of Service can be configured right on the wireless controller , or on Extreme Management (in the Policy section) and pushed to the Wireless Controller . If you configure CoS first on wireless Controller , it will prevent ExtremeManagement to push and override it . Ideally if you start using Policy from ExtremeManagement , do not touch Roles and Class of Services on the controller - do all you changes on ExtremeManagement Policy instead.</description>
    <pubDate>Wed, 13 Sep 2017 20:33:00 GMT</pubDate>
    <dc:creator>Ostrovsky__Yury</dc:creator>
    <dc:date>2017-09-13T20:33:00Z</dc:date>
    <item>
      <title>How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35610#M4052</link>
      <description>Hi all,&lt;BR /&gt;
&lt;BR /&gt;
I have deployed a Netsight server, a Extreme NAC server and a c5210 wireless controller.&lt;BR /&gt;
&lt;BR /&gt;
&lt;U&gt;On the Wireless controller side&lt;/U&gt;:&lt;BR /&gt;
I created a WLAN service with authentication mode 802.1x which is using a single radius server (Extreme NAC IA-A-20) for auth &amp;amp; acct. &lt;BR /&gt;
&lt;BR /&gt;
I also created a role with default action:&lt;BR /&gt;
Access Control: containment VLAN&lt;BR /&gt;
VLAN: vlan212 &lt;BR /&gt;
&lt;BR /&gt;
Clicked Advanced &amp;gt;&amp;gt; Added vlan212, vlan300, vlan211 to be used. I have not defined any policy rules.&lt;BR /&gt;
&lt;BR /&gt;
Then I defined a VNS to bind this WLAN service to this Role when user is authenticated.&lt;BR /&gt;
&lt;BR /&gt;
&lt;U&gt;On the NAC side&lt;/U&gt;:&lt;BR /&gt;
&lt;BR /&gt;
I added the EWC to access control engine as "Extreme identiFi Wireless".&lt;BR /&gt;
&lt;BR /&gt;
I created two policy roles. One of them is configured to contain to vlan211 and the other is configured to contain to vlan300.&lt;BR /&gt;
&lt;U&gt;&lt;BR /&gt;
Note&lt;/U&gt;: when I try to enforce domain data to wireless controller, "&lt;I&gt;cannot remove active Role -XXXX- from EWC ...&lt;/I&gt;" error occurs.&lt;BR /&gt;
&lt;BR /&gt;
Then I have tested with two wireless clients. I can see that both clients are assigned to these different NAC profiles successfully. But they are assigned to same vlan212.  &lt;BR /&gt;
&lt;BR /&gt;
Is it possible to assign clients with different NAC profiles to different Vlans on the same SSID ?&lt;BR /&gt;
&lt;BR /&gt;
Thanks.</description>
      <pubDate>Wed, 13 Sep 2017 19:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35610#M4052</guid>
      <dc:creator>Yakup_Erdol</dc:creator>
      <dc:date>2017-09-13T19:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35611#M4053</link>
      <description>Hi Yakup , &lt;BR /&gt;
You can assing different VLANs in one of this two methods :&lt;BR /&gt;
- Sending different Policy which bounded to specific topology on the Wireless Controller (e.g. Policy1 on controller configured to "Contain to VLAN100" , Policy2 on controller configured to "Contain to VLAN200" . ) So based on some criteria , ExtremeNAC will send different Policy , then controller will assign different Topology (therefore VLAN) to the user&lt;BR /&gt;
- Second method is using the same policy , but sending Tunneled Attributes . For doing that , change the "Extreme identiFi Wireless" (when you were adding switch to the NAC) to "RFC3580- VLANID &amp;amp; Extreme IdentiFi Wireless" , in this case together with FilterID (Policy name) the tunneled attributes will come to controller .</description>
      <pubDate>Wed, 13 Sep 2017 20:14:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35611#M4053</guid>
      <dc:creator>Ostrovsky__Yury</dc:creator>
      <dc:date>2017-09-13T20:14:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35612#M4054</link>
      <description>Hi Yury,&lt;BR /&gt;
&lt;BR /&gt;
I am confused. Do you mean "WLAN service" by Topology ? If yes, how will EWC decide which 801.x authenticated user use which topology ? &lt;BR /&gt;
&lt;BR /&gt;
Thanks.</description>
      <pubDate>Wed, 13 Sep 2017 20:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35612#M4054</guid>
      <dc:creator>Yakup_Erdol</dc:creator>
      <dc:date>2017-09-13T20:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35613#M4055</link>
      <description>No , not WLAN service by topology . I meant Role (sometimes refered as Policy). NAC sending back the Filter-ID which is exactly matching the Role name configured on the controller. This role can be bounded to particular Topology (which is the VLAN for you).</description>
      <pubDate>Wed, 13 Sep 2017 20:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35613#M4055</guid>
      <dc:creator>Ostrovsky__Yury</dc:creator>
      <dc:date>2017-09-13T20:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35614#M4056</link>
      <description>I will try it tomorrow. Thanks again.</description>
      <pubDate>Wed, 13 Sep 2017 20:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35614#M4056</guid>
      <dc:creator>Yakup_Erdol</dc:creator>
      <dc:date>2017-09-13T20:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35615#M4057</link>
      <description>Hi Yury, &lt;BR /&gt;
&lt;BR /&gt;
Firstly, I have to confess that I could not understand how to configure the first method on the wireless controller. Because as I know, a VNS can only bind a WLAN service to only two different Roles (non-authenticated / authenticated). &lt;BR /&gt;
&lt;BR /&gt;
Anyway, I tried my best and deleted all custom made CoS and Roles on the EWC, then enforced domain policies from Netsight successfully. Then I configured the VNS as below:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-84620-1jv9982-8021x_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/944iB41A4999DDE1B98B/image-size/large?v=v2&amp;amp;px=999" role="button" title="167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-84620-1jv9982-8021x_inline.jpg" alt="167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-84620-1jv9982-8021x_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Then, I tested this configuration by connecting two different clients to the same SSID (test-8021x) simultaneously: one of the clients assigned to "Vlan211" and the other assigned to "Vlan311" which are not related to "NOT_Domain_PC" role. They are just assigned to Vlans that NAC sends as radius attributes :&lt;BR /&gt;
&lt;BR /&gt;
Test client-1 Authentication session:&lt;I&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-55200-tl5rc-8021x-2_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1418i87807B6B9EEB2077/image-size/large?v=v2&amp;amp;px=999" role="button" title="167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-55200-tl5rc-8021x-2_inline.png" alt="167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-55200-tl5rc-8021x-2_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Test client-2 Authentication session:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-128099-8uj7eu-8021x-3_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2888iE875DEE596FEAD36/image-size/large?v=v2&amp;amp;px=999" role="button" title="167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-128099-8uj7eu-8021x-3_inline.png" alt="167e5f5a11884a72a7c5c44edb54924d_RackMultipart20170914-128099-8uj7eu-8021x-3_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
I understand from this test that no matter what is chosen in the "Default Roles  &amp;gt;&amp;gt; Authenticated" field, clients are assigned according to radius attribute that NAC sends. &lt;BR /&gt;
&lt;BR /&gt;
Is it right ?&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
&lt;/I&gt;</description>
      <pubDate>Wed, 13 Sep 2017 20:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35615#M4057</guid>
      <dc:creator>Yakup_Erdol</dc:creator>
      <dc:date>2017-09-13T20:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35616#M4058</link>
      <description>Technically, you don't need to do anything else on controller. You already pushing the Policies to controller. Whatever you define on controller as 'default action' does not matter since NAC will override it based on user authentication. That's why it called 'dynamic policy assignment'. Its the same way as dynamic VLAN assignment, just using different VSA attributes ( FilterID instead of tunneled attributes). But looks like you are on a right path.</description>
      <pubDate>Wed, 13 Sep 2017 20:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35616#M4058</guid>
      <dc:creator>Ostrovsky__Yury</dc:creator>
      <dc:date>2017-09-13T20:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35617#M4059</link>
      <description>Thank you very much Yury. All these informations really helped me a lot.</description>
      <pubDate>Wed, 13 Sep 2017 20:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35617#M4059</guid>
      <dc:creator>Yakup_Erdol</dc:creator>
      <dc:date>2017-09-13T20:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35618#M4060</link>
      <description>And why "&lt;I&gt;cannot remove active Role -XXXX- from EWC ...&lt;/I&gt;" error occurs when enforcing the policy on Netsight ?&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 13 Sep 2017 20:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35618#M4060</guid>
      <dc:creator>Yakup_Erdol</dc:creator>
      <dc:date>2017-09-13T20:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35619#M4061</link>
      <description>I strongly advice you to pay an Extreme Partner to do it for you / show you the basic functions during the installation.&lt;BR /&gt;
&lt;BR /&gt;
Here a list for your country...&lt;BR /&gt;
&lt;A href="http://www.extremenetworks.com/partners/find-a-partner/location/Europe-Middle-East-Africa/TR/?show-p.." target="_blank" rel="nofollow noreferrer noopener"&gt;http://www.extremenetworks.com/partners/find-a-partner/location/Europe-Middle-East-Africa/TR/?show-p...&lt;/A&gt;.&lt;BR /&gt;
&lt;BR /&gt;
Or you'd attend the official training for wirless and NAC...&lt;BR /&gt;
&lt;A href="http://www.extremenetworks.com/education/courses/" target="_blank" rel="nofollow noreferrer noopener"&gt;http://www.extremenetworks.com/education/courses/&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
BR,&lt;BR /&gt;
Ron</description>
      <pubDate>Wed, 13 Sep 2017 20:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35619#M4061</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2017-09-13T20:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35620#M4062</link>
      <description>You are trying to use Policy from the ExtremeManagement . Most probably you already have some CoSes configured on the controller which prevent pushing the policies to . Clean up (just delete) all the custom made CoSes you have on controller , then you can try to push Policy again from ExtremeManagement. &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 13 Sep 2017 20:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35620#M4062</guid>
      <dc:creator>Ostrovsky__Yury</dc:creator>
      <dc:date>2017-09-13T20:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35621#M4063</link>
      <description>Sorry again. Would you explain what "CoSes" is ?</description>
      <pubDate>Wed, 13 Sep 2017 20:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35621#M4063</guid>
      <dc:creator>Yakup_Erdol</dc:creator>
      <dc:date>2017-09-13T20:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35622#M4064</link>
      <description>On the VNS page of the wireless controller you have (from top to bottom) : Global , Sites, Virtual Networks, WLAN Sevices , Roles , Class of Service , Topologies . &lt;BR /&gt;
CoS is Class of Service . &lt;BR /&gt;
Roles and Class of Service can be configured right on the wireless controller , or on Extreme Management (in the Policy section) and pushed to the Wireless Controller . If you configure CoS first on wireless Controller , it will prevent ExtremeManagement to push and override it . Ideally if you start using Policy from ExtremeManagement , do not touch Roles and Class of Services on the controller - do all you changes on ExtremeManagement Policy instead.</description>
      <pubDate>Wed, 13 Sep 2017 20:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35622#M4064</guid>
      <dc:creator>Ostrovsky__Yury</dc:creator>
      <dc:date>2017-09-13T20:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to create a single SSID with multiple vlans ?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35623#M4065</link>
      <description>I thought it was the plural form of "CoSe" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Thanks for the great explanation.</description>
      <pubDate>Wed, 13 Sep 2017 20:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/how-to-create-a-single-ssid-with-multiple-vlans/m-p/35623#M4065</guid>
      <dc:creator>Yakup_Erdol</dc:creator>
      <dc:date>2017-09-13T20:33:00Z</dc:date>
    </item>
  </channel>
</rss>

