<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Netlogin unwanted MAC is authenticated locally in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38018#M4543</link>
    <description>Okay, I revoke the last one.&lt;BR /&gt;
The issue is still active, even with 15.3.5.2-patch1-14.&lt;BR /&gt;
&lt;BR /&gt;
I will open up a GTAC case with our external partner&lt;BR /&gt;
&lt;BR /&gt;
BR&lt;BR /&gt;
Chacko</description>
    <pubDate>Wed, 16 Aug 2017 13:04:00 GMT</pubDate>
    <dc:creator>Chacko</dc:creator>
    <dc:date>2017-08-16T13:04:00Z</dc:date>
    <item>
      <title>Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38008#M4533</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
I'm a little bit confused:&lt;BR /&gt;
We are using netlogin for a year and it's working like you would expect it:&lt;BR /&gt;
A unknown MAC address shows up on the switch, is getting blocked and reported in EMS.&lt;BR /&gt;
&lt;BR /&gt;
But now, I have a unwanted MAC address, which is authenticated locally, but is reported as rejected in EMS - but the switch authenticates the user and assign to the granted VLAN.&lt;BR /&gt;
&lt;BR /&gt;
Here is the netlogin config:&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;#&lt;BR /&gt;
# Module netLogin configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure netlogin vlan AUTH&lt;BR /&gt;
enable netlogin mac&lt;BR /&gt;
configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48&lt;BR /&gt;
configure netlogin mac timers reauth-period 7200&lt;BR /&gt;
enable netlogin ports 1:10-48,2:10-2:48 mac&lt;BR /&gt;
configure netlogin ports 1:10-48,2:10-2:48 mode mac-based-vlans&lt;BR /&gt;
configure netlogin ports 1:10-48,2:10-2:48 no-restart&lt;BR /&gt;
enable netlogin authentication service-unavailable vlan ports 1:10-48,2:10-2:48&lt;BR /&gt;
configure netlogin authentication service-unavailable vlan office ports 1:10-48,2:10-2:48&lt;/BLOCKQUOTE&gt;Radius is working, the switch is a X450e-48p (stacked) with EXOS 15.3.2.11&lt;BR /&gt;
&lt;BR /&gt;
I'm happy for feedback&lt;BR /&gt;
&lt;BR /&gt;
Best Regards&lt;BR /&gt;
Chacko</description>
      <pubDate>Thu, 10 Aug 2017 18:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38008#M4533</guid>
      <dc:creator>Chacko</dc:creator>
      <dc:date>2017-08-10T18:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38009#M4534</link>
      <description>Hi Chacko,&lt;BR /&gt;
&lt;BR /&gt;
Can you post the "show netlogin port  and "show log" which has the login success message?</description>
      <pubDate>Tue, 15 Aug 2017 11:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38009#M4534</guid>
      <dc:creator>Karthik_Mohando</dc:creator>
      <dc:date>2017-08-15T11:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38010#M4535</link>
      <description>Hi Karthik,&lt;BR /&gt;
&lt;BR /&gt;
here is the output:&lt;BR /&gt;
# sh netlogin port 2:20&lt;BR /&gt;
Port                          : 2:20&lt;BR /&gt;
Port Restart                  : Disabled&lt;BR /&gt;
Allow Egress                  : None&lt;BR /&gt;
Vlan                          : AUTH&lt;BR /&gt;
Authentication                : mac-based&lt;BR /&gt;
Port State                    : Enabled&lt;BR /&gt;
Guest Vlan                    : Disabled&lt;BR /&gt;
Auth Failure Vlan             : Disabled&lt;BR /&gt;
Auth Service-Unavailable Vlan : Enabled&lt;BR /&gt;
MAC                IP address       Authenticated     Type    ReAuth-Timer   User&lt;BR /&gt;
-----------------------------------------------&lt;BR /&gt;
(B) - Client entry Blackholed in FDB&lt;BR /&gt;
Port                          : 2:20&lt;BR /&gt;
Port Restart                  : Disabled&lt;BR /&gt;
Allow Egress                  : None&lt;BR /&gt;
Vlan                          : office&lt;BR /&gt;
Authentication                : mac-based&lt;BR /&gt;
Port State                    : Enabled&lt;BR /&gt;
Guest Vlan                    : Disabled&lt;BR /&gt;
Auth Failure Vlan             : Disabled&lt;BR /&gt;
Auth Service-Unavailable Vlan : Enabled&lt;BR /&gt;
MAC                IP address       Authenticated     Type    ReAuth-Timer   User&lt;BR /&gt;
10:4f:a8:XX:XX:XX  0.0.0.0          Yes, Locally      MAC     7197           104FA8XXXXXX&lt;BR /&gt;
-----------------------------------------------&lt;BR /&gt;
(B) - Client entry Blackholed in FDB &lt;BR /&gt;
And the log&lt;BR /&gt;
 &lt;I&gt; Network Login MAC user 104FA8XXXXXX logged in MAC 10:4F:A8:XX:XX:XX port 2:20 VLAN(s) "office", authentication Locally&lt;BR /&gt;
 &lt;I&gt; Port 2:20 link UP at speed 100 Mbps and full-duplex&lt;/I&gt;&lt;/I&gt;</description>
      <pubDate>Tue, 15 Aug 2017 11:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38010#M4535</guid>
      <dc:creator>Chacko</dc:creator>
      <dc:date>2017-08-15T11:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38011#M4536</link>
      <description>Chacko,&lt;BR /&gt;
&lt;BR /&gt;
Is it possible to post the screenshot of the rejection message in the EMS?&lt;BR /&gt;
&lt;BR /&gt;
Can you check if this MAC address is not present as local user in the switch itself? &lt;BR /&gt;
The command is "show netlogin local-users" &lt;BR /&gt;
&lt;BR /&gt;
In case if you have a radius server configured can you pose the "show config aaa" and does the radius request passed before the switch decided to do a local authentication? you can see this from the "show log" in case if the radius requests are failing</description>
      <pubDate>Tue, 15 Aug 2017 12:11:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38011#M4536</guid>
      <dc:creator>Karthik_Mohando</dc:creator>
      <dc:date>2017-08-15T12:11:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38012#M4537</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
sorry, I misspelled it - I meant EMC (management center):&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="a5fd841055734239a2c2724a2a2677a3_RackMultipart20170815-107289-9q4zs-sc_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5480iCE735CCB9262A9CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="a5fd841055734239a2c2724a2a2677a3_RackMultipart20170815-107289-9q4zs-sc_inline.png" alt="a5fd841055734239a2c2724a2a2677a3_RackMultipart20170815-107289-9q4zs-sc_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
First line is the configuration for our NAC appliances, so that policy is underneath the "allow if MAC and end-system group xxx"-policies.&lt;BR /&gt;
Second line is the output in access control -&amp;gt; rejected end systems.&lt;BR /&gt;
&lt;BR /&gt;
Radius is properly configured, the priority is default (radius, local), the local MAC users are empty.&lt;BR /&gt;
&lt;BR /&gt;
There are no other log-entries related to authentication as soon as the ports comes up.&lt;BR /&gt;
All the other netlogin devices are working fine on that switch and I can say to 100%, that the MAC address is not known in our Access Control database (first I built a script for checking it, and second, the right policy is chosen, so the MAC cannot be inside our end-system groups.&lt;BR /&gt;
&lt;BR /&gt;
BR&lt;BR /&gt;
Chacko&lt;BR /&gt;</description>
      <pubDate>Tue, 15 Aug 2017 12:11:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38012#M4537</guid>
      <dc:creator>Chacko</dc:creator>
      <dc:date>2017-08-15T12:11:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38013#M4538</link>
      <description>Hi Chacko,&lt;BR /&gt;
&lt;BR /&gt;
If the MAC is authenticated by EMC then we will see a different log message but by looking at the log message which you have shared the authentication has been processed locally by the switch&lt;BR /&gt;
&lt;BR /&gt;
 &lt;I&gt; Network Login MAC user 104FA8XXXXXX logged in MAC 10:4F:A8:XX:XX:XX port 2:20 VLAN(s) "office", authentication &lt;B&gt;&lt;U&gt;Locally&lt;/U&gt;&lt;/B&gt;  &lt;BR /&gt;
&lt;BR /&gt;
I wanted to check if the local user database has this mac address or not and that can be checked using the command "show netlogin local-users" in the switch. &lt;BR /&gt;
&lt;BR /&gt;&lt;/I&gt;</description>
      <pubDate>Tue, 15 Aug 2017 12:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38013#M4538</guid>
      <dc:creator>Karthik_Mohando</dc:creator>
      <dc:date>2017-08-15T12:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38014#M4539</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
okay, I can follow you: &lt;BR /&gt;
Here is the output;&lt;BR /&gt;
Slot-1 sw # sh netlogin local-users&lt;BR /&gt;
Netlogin Local User Name  Extended-VLAN VSA              Security Profile&lt;BR /&gt;
------------------------  -----------------------------  ----------------------&lt;BR /&gt;
Slot-1 sw #So the local database is empty.&lt;BR /&gt;
&lt;BR /&gt;
BR&lt;BR /&gt;
Chacko</description>
      <pubDate>Tue, 15 Aug 2017 12:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38014#M4539</guid>
      <dc:creator>Chacko</dc:creator>
      <dc:date>2017-08-15T12:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38015#M4540</link>
      <description>Hi Chacko,&lt;BR /&gt;
&lt;BR /&gt;
I would request you to pursue this issue with GTAC case as this needs further investigation.&lt;BR /&gt;
15.3 version has already reached end of engineering hence it would be best to upgrade to the latest patch in 15.3 (15.3.5.2-patch1-14) and check if the issue is getting resolved before opening up the ticket. &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 15 Aug 2017 13:10:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38015#M4540</guid>
      <dc:creator>Karthik_Mohando</dc:creator>
      <dc:date>2017-08-15T13:10:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38016#M4541</link>
      <description>Hi Karthik,&lt;BR /&gt;
&lt;BR /&gt;
I updated the switch over night and so far, the problem hasn't occured again.&lt;BR /&gt;
I hope there is no general netlogin problem in this software release - but the summit *50 will be out of contract next year anyway.&lt;BR /&gt;
&lt;BR /&gt;
Thanks for your help&lt;BR /&gt;
&lt;BR /&gt;
Best Regards&lt;BR /&gt;
Chacko</description>
      <pubDate>Tue, 15 Aug 2017 13:10:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38016#M4541</guid>
      <dc:creator>Chacko</dc:creator>
      <dc:date>2017-08-15T13:10:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38017#M4542</link>
      <description>Hi Chacko,&lt;BR /&gt;
&lt;BR /&gt;
Thanks for getting back on this, good to see that the issue is not seen. &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 16 Aug 2017 13:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38017#M4542</guid>
      <dc:creator>Karthik_Mohando</dc:creator>
      <dc:date>2017-08-16T13:04:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin unwanted MAC is authenticated locally</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38018#M4543</link>
      <description>Okay, I revoke the last one.&lt;BR /&gt;
The issue is still active, even with 15.3.5.2-patch1-14.&lt;BR /&gt;
&lt;BR /&gt;
I will open up a GTAC case with our external partner&lt;BR /&gt;
&lt;BR /&gt;
BR&lt;BR /&gt;
Chacko</description>
      <pubDate>Wed, 16 Aug 2017 13:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-unwanted-mac-is-authenticated-locally/m-p/38018#M4543</guid>
      <dc:creator>Chacko</dc:creator>
      <dc:date>2017-08-16T13:04:00Z</dc:date>
    </item>
  </channel>
</rss>

