<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: LDAP host validation - Reverse DNS lookup in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ldap-host-validation-reverse-dns-lookup/m-p/47010#M6527</link>
    <description>Hello,  &lt;BR /&gt;
  There is no alternative that I know of for this other than to get the DHCP server issue resolved.  NAC will first resolve the End System's IP after an authentication, then its conducts the reverse lookup to DNS, in order to get the FQDN.  If that data is not accurate then the rule will fail.&lt;BR /&gt;
&lt;BR /&gt;
There is an article in the knowledge-base for  hostname resolution.  You can use this to determine if the FQDN of the End  System is being reported to NAC by the DNS server / reverse lookup process:  &lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/NAC-Troubleshooting-Tips-Debug-Incorrect-or-Missing-Hostname-Information/?q=nac+tips&amp;amp;#38;l=en_US&amp;amp;#38;fs=Search&amp;amp;#38;pn=1" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/NAC-Troubleshooting-Tips-Debug-Incorrect-o...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
&lt;BR /&gt;
Scott Keene&lt;BR /&gt;
NMS/NAC Support&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Thu, 23 Feb 2017 01:10:00 GMT</pubDate>
    <dc:creator>Keene__Scott</dc:creator>
    <dc:date>2017-02-23T01:10:00Z</dc:date>
    <item>
      <title>LDAP host validation - Reverse DNS lookup</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ldap-host-validation-reverse-dns-lookup/m-p/47009#M6526</link>
      <description>Hi,  &lt;BR /&gt;
&lt;BR /&gt;
  As described by Yacobucci, Ryan &lt;A href="https://community.extremenetworks.com/extreme/topics/nac-restricting-access-for-nondomain-devices" target="_blank" rel="nofollow noreferrer noopener"&gt;https://community.extremenetworks.com/extreme/topics/nac-restricting-access-for-nondomain-devices&lt;/A&gt;. DNS reverse lookup takes part of LDAP host validation.&lt;BR /&gt;
&lt;BR /&gt;
  however, I’m doing a huge NAC deployment (about 2000 wireless devices connected to IdentiFi network). The rule defined to validade users and computers in the AD are not working and i figured out the DNS reverse zones are not being updated by the DHCP. Is there any alternative to avoid reverse DNS lookup? &lt;BR /&gt;
&lt;BR /&gt;
  Many thanks for all.&lt;BR /&gt;
&lt;BR /&gt;
  &lt;BR /&gt;
&lt;BR /&gt;
  Luís Oliveira&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Feb 2017 17:17:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ldap-host-validation-reverse-dns-lookup/m-p/47009#M6526</guid>
      <dc:creator>Luis_Oliveira</dc:creator>
      <dc:date>2017-02-14T17:17:00Z</dc:date>
    </item>
    <item>
      <title>RE: LDAP host validation - Reverse DNS lookup</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ldap-host-validation-reverse-dns-lookup/m-p/47010#M6527</link>
      <description>Hello,  &lt;BR /&gt;
  There is no alternative that I know of for this other than to get the DHCP server issue resolved.  NAC will first resolve the End System's IP after an authentication, then its conducts the reverse lookup to DNS, in order to get the FQDN.  If that data is not accurate then the rule will fail.&lt;BR /&gt;
&lt;BR /&gt;
There is an article in the knowledge-base for  hostname resolution.  You can use this to determine if the FQDN of the End  System is being reported to NAC by the DNS server / reverse lookup process:  &lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/NAC-Troubleshooting-Tips-Debug-Incorrect-or-Missing-Hostname-Information/?q=nac+tips&amp;amp;#38;l=en_US&amp;amp;#38;fs=Search&amp;amp;#38;pn=1" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/NAC-Troubleshooting-Tips-Debug-Incorrect-o...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
&lt;BR /&gt;
Scott Keene&lt;BR /&gt;
NMS/NAC Support&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 23 Feb 2017 01:10:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ldap-host-validation-reverse-dns-lookup/m-p/47010#M6527</guid>
      <dc:creator>Keene__Scott</dc:creator>
      <dc:date>2017-02-23T01:10:00Z</dc:date>
    </item>
    <item>
      <title>RE: LDAP host validation - Reverse DNS lookup</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ldap-host-validation-reverse-dns-lookup/m-p/47011#M6528</link>
      <description>Many Thanks Keene,&lt;BR /&gt;
&lt;BR /&gt;
We are now using agent-based assessment to validate if the host belongs to the domain. It works fine for windows laptops. They have also macOS laptops registered in the domain. Do you know how to validate these ones using the assessment agent?&lt;BR /&gt;
Many thanks once again&lt;BR /&gt;
&lt;BR /&gt;
Luís Oliveira&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Mar 2017 17:20:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ldap-host-validation-reverse-dns-lookup/m-p/47011#M6528</guid>
      <dc:creator>Luis_Oliveira</dc:creator>
      <dc:date>2017-03-02T17:20:00Z</dc:date>
    </item>
  </channel>
</rss>

