<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Default Role on port prevents communication with access switch IP in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/default-role-on-port-prevents-communication-with-access-switch/m-p/45841#M6248</link>
    <description>FYI, upgrade to 22.5.1.7patch1-2 solved the issue.</description>
    <pubDate>Wed, 05 Dec 2018 16:28:00 GMT</pubDate>
    <dc:creator>Tomasz</dc:creator>
    <dc:date>2018-12-05T16:28:00Z</dc:date>
    <item>
      <title>Default Role on port prevents communication with access switch IP</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/default-role-on-port-prevents-communication-with-access-switch/m-p/45840#M6247</link>
      <description>Hello there,&lt;BR /&gt;
&lt;BR /&gt;
I am currently playing a little bit with Policy &amp;amp; NAC for EXOS through XMC.&lt;BR /&gt;
I have created a user role called XYZ with Contain to VLAN as a default action, no rules within. Did that also with default deny + rule to allow ICMP.&lt;BR /&gt;
The case is, when a port default role is set via Policy manager section in XMC (what I confirm when doing show config policy in EXOS), connected client device cannot ping the VLAN IP address on that switch.&lt;BR /&gt;
&lt;BR /&gt;
Configuration:&lt;BR /&gt;
Switch_A is 172.16.11.103/24 on VLAN 11. VLAN 11 is not set to port manually but enforced via static policy role (and it works). Access port in VLAN 11 as untagged. It also contains uplink port as tagged. &lt;BR /&gt;
Core_A is 172.16.11.1/24 on VLAN 11, downlink to access switch included as tagged and ipforwarding for different purposes.&lt;BR /&gt;
&lt;BR /&gt;
When a client connected to role-applied port it can ping to Core_A, but cannot ping to Switch_A (timeout).&lt;BR /&gt;
EXOS version 22.4.1.4.&lt;BR /&gt;
&lt;BR /&gt;
Any assistance here would be much appreciated, thanks!&lt;BR /&gt;
&lt;BR /&gt;
Kind regards,&lt;BR /&gt;
Tomasz&lt;BR /&gt;</description>
      <pubDate>Thu, 22 Nov 2018 23:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/default-role-on-port-prevents-communication-with-access-switch/m-p/45840#M6247</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2018-11-22T23:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: Default Role on port prevents communication with access switch IP</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/default-role-on-port-prevents-communication-with-access-switch/m-p/45841#M6248</link>
      <description>FYI, upgrade to 22.5.1.7patch1-2 solved the issue.</description>
      <pubDate>Wed, 05 Dec 2018 16:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/default-role-on-port-prevents-communication-with-access-switch/m-p/45841#M6248</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2018-12-05T16:28:00Z</dc:date>
    </item>
  </channel>
</rss>

