<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC Zones - design question in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44821#M6022</link>
    <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
i wanna setup NAC Zones, locations/switches being the selector. Got about 20 locations to reflect in Zones, and about 20 for dieferent endsystem classifications across all locations. Because  the Zones are applied by NAC rules only, this would result in a very questionable amount of NAC rules. Ist there any other way to use zones just by switch location?</description>
    <pubDate>Fri, 02 Oct 2015 11:19:00 GMT</pubDate>
    <dc:creator>mp2014</dc:creator>
    <dc:date>2015-10-02T11:19:00Z</dc:date>
    <item>
      <title>NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44821#M6022</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
i wanna setup NAC Zones, locations/switches being the selector. Got about 20 locations to reflect in Zones, and about 20 for dieferent endsystem classifications across all locations. Because  the Zones are applied by NAC rules only, this would result in a very questionable amount of NAC rules. Ist there any other way to use zones just by switch location?</description>
      <pubDate>Fri, 02 Oct 2015 11:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44821#M6022</guid>
      <dc:creator>mp2014</dc:creator>
      <dc:date>2015-10-02T11:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44822#M6023</link>
      <description>Hi ,&lt;BR /&gt;
&lt;BR /&gt;
I hope this below steps would help you to configure zones.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-To-Configure-a-Location-in-NAC-For-Zone" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-To-Configure-a-Location-in-NAC-For-Zon...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Suresh.B&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 02 Oct 2015 13:17:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44822#M6023</guid>
      <dc:creator>Bharathiraja__S</dc:creator>
      <dc:date>2015-10-02T13:17:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44823#M6024</link>
      <description>this article is regarding wireless zones. I'm refering to endsytem zones in nac, standard wired devices. My problem ist just the amount of NAC rules needed.&lt;BR /&gt;
Goal is to use these zones to make only specific endsystems visible for administrator of a location.&lt;BR /&gt;</description>
      <pubDate>Fri, 02 Oct 2015 14:07:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44823#M6024</guid>
      <dc:creator>mp2014</dc:creator>
      <dc:date>2015-10-02T14:07:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44824#M6025</link>
      <description>This should not be a big problem. I currently have about 900 rule matrix entries in my customers NAC. We there also use zones for the same reason. But zones did NOT expand your rule matrix, you have to add the zone to the users and groups AND to the rule matrix entries. Users are only viewable there (in OneView) AFTER they are authenticated with a zones fittet rule matrix. No panic about a bigger count of rules in the Rulematrix </description>
      <pubDate>Fri, 04 Mar 2016 16:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44824#M6025</guid>
      <dc:creator>Rainer_Adam</dc:creator>
      <dc:date>2016-03-04T16:36:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44825#M6026</link>
      <description>At first you have to enable the row "zone" in the RuleMatrix to make it view and accessable.....&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="951ede9ac26746cdb0c11b6dacd04b91_RackMultipart20160304-40778-1kq78is-nac_zone_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1534i496AE0AEFCE80935/image-size/large?v=v2&amp;amp;px=999" role="button" title="951ede9ac26746cdb0c11b6dacd04b91_RackMultipart20160304-40778-1kq78is-nac_zone_inline.png" alt="951ede9ac26746cdb0c11b6dacd04b91_RackMultipart20160304-40778-1kq78is-nac_zone_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 04 Mar 2016 16:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44825#M6026</guid>
      <dc:creator>Rainer_Adam</dc:creator>
      <dc:date>2016-03-04T16:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44826#M6027</link>
      <description>And then add "simply" the ID of your Zone, in this example "4", this makes the through this rule matrix line authenticated client viewable in Oneview....&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="be7ddfa8ca28450996bdbc1a0a576bc7_RackMultipart20160304-40771-jxiw4-nac_zone_details_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1367i63300024C7232C8E/image-size/large?v=v2&amp;amp;px=999" role="button" title="be7ddfa8ca28450996bdbc1a0a576bc7_RackMultipart20160304-40771-jxiw4-nac_zone_details_inline.png" alt="be7ddfa8ca28450996bdbc1a0a576bc7_RackMultipart20160304-40771-jxiw4-nac_zone_details_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2016 16:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44826#M6027</guid>
      <dc:creator>Rainer_Adam</dc:creator>
      <dc:date>2016-03-04T16:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44827#M6028</link>
      <description>thanks for reply - this is like we do this now. But its a lot work to do so much rules. And on any new endsystem classification wishes, i need to adjust rules for any department...&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Mar 2016 12:15:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44827#M6028</guid>
      <dc:creator>mp2014</dc:creator>
      <dc:date>2016-03-11T12:15:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44828#M6029</link>
      <description>I don't know what you really need, in my customers case there are departments all over there biggest location and there is no limit to witch switch they connect to, it depends on there end-system-group. So a client of end-system "A" will always be authenticated to the same vlan unequal to witch switch they are connected, execpt the switch is in a different location (where we have a different vlan infrastructure). &lt;BR /&gt;
&lt;BR /&gt;
I would recommend you to create a excel sheet where you define witch user groups (end-system-groups) are allowed to move between location and to witch vlan they should be authenticated. &lt;BR /&gt;
&lt;BR /&gt;
Per vlan you need one rule matrix entry, that is not depending on a zone management. Zone's can be add additionally to each rule matrix entry. You only have to create and define the zones and users / groups the should be able to manage and add this to the rule-matrix entry where they are authenticated.&lt;BR /&gt;
&lt;BR /&gt;
Are you having different "managers" for clients within the same vlan? Then I would understand what you mean, but if different "managers" have to admit different vlan's this is really easy. &lt;BR /&gt;
&lt;BR /&gt;
If you need more details please contact me directly. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Mar 2016 14:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44828#M6029</guid>
      <dc:creator>Rainer_Adam</dc:creator>
      <dc:date>2016-03-11T14:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44829#M6030</link>
      <description>the &lt;B&gt;&lt;I&gt;only &lt;/I&gt;&lt;/B&gt;criteria for which end-system belongs to which manager is the switch/port location, not the vlan or end-system group. So this is why it looks tricky to me to achieve this...&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Mar 2016 18:18:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44829#M6030</guid>
      <dc:creator>mp2014</dc:creator>
      <dc:date>2016-03-11T18:18:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44830#M6031</link>
      <description>I am sorry, I delete my last answer to you, I was wrong. &lt;BR /&gt;
&lt;BR /&gt;
Are you having moving users that on some days are connected to switch A and on other days to Switch B or are the users static to there switches?&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Mar 2016 19:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44830#M6031</guid>
      <dc:creator>Rainer_Adam</dc:creator>
      <dc:date>2016-03-11T19:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44831#M6032</link>
      <description>The point is that the Zones only works with end-system-groups. So therefor you had to create end-system-groups based on your switch locations. So these mac addresses you can easy get from the NAC Manager by using a filter to the switch ip, then export it and import the mac addresses to each end-system-group.&lt;BR /&gt;
&lt;BR /&gt;
Best if you choose names that are likly for your switches.&lt;BR /&gt;
&lt;BR /&gt;
Create your zone managers in the Zone management and then you have to edit your current rule Matrix entries and add the correct zone to each "manager" (=user). &lt;BR /&gt;
&lt;BR /&gt;
The "managers" should now be able to add a user to his end-system-group if a client connects to his switch based on the entry in the rule matrix line for this.</description>
      <pubDate>Fri, 11 Mar 2016 19:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44831#M6032</guid>
      <dc:creator>Rainer_Adam</dc:creator>
      <dc:date>2016-03-11T19:36:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44832#M6033</link>
      <description>But, what should this managers have to be done? Allow "unknown" MAC addresses? Whats the reason for you to involve theme for this job?  For me there is somegthing missing for a fully understanding.</description>
      <pubDate>Fri, 11 Mar 2016 20:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44832#M6033</guid>
      <dc:creator>Rainer_Adam</dc:creator>
      <dc:date>2016-03-11T20:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Zones - design question</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44833#M6034</link>
      <description>the only purpose for this is to make local end systems visible to local admins (admins of the end systems, not networking) via oneview. All real network administration tasks are done by central IT departement admins.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 11 Mar 2016 21:14:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-zones-design-question/m-p/44833#M6034</guid>
      <dc:creator>mp2014</dc:creator>
      <dc:date>2016-03-11T21:14:00Z</dc:date>
    </item>
  </channel>
</rss>

