<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: LSNAT and NAC Config in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/lsnat-and-nac-config/m-p/47805#M6700</link>
    <description>I have had that setup before, works well.  I was going to try to use LSNAT because I wanted to LB our AD servers also, and I want to use NAC as a test.  Basically, we have had several DC outages and it takes a little while for NAC to try another AD server for authentication.  So LSNAT would take care of that and also spread the load out over our AD infrastructure so all auths aren't hitting our primary AD DC.  I am about to turn 802.1x on everywhere, so LDAP auths are about to go way, way up.  Just want to make sure everything is evenly distributed and failures are transparent to users before we flip the 802.1x switch on all wired ports.  Otherwise, 802.1x in my testing is working flawlessly.</description>
    <pubDate>Tue, 16 Feb 2016 09:19:00 GMT</pubDate>
    <dc:creator>Jeremy_Gibbs</dc:creator>
    <dc:date>2016-02-16T09:19:00Z</dc:date>
    <item>
      <title>LSNAT and NAC Config</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/lsnat-and-nac-config/m-p/47803#M6698</link>
      <description>There use to be a discussion on the hub about LSNAT and NAC but I can't find it.  I am attempting to setup LSNAT to load balance between our 4 NAC appliances with 9,000 end systems.  Anyway, if nothing is available, once I get a working config, I will post it so it can help others set this up.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Feb 2016 03:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/lsnat-and-nac-config/m-p/47803#M6698</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2016-02-16T03:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: LSNAT and NAC Config</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/lsnat-and-nac-config/m-p/47804#M6699</link>
      <description>Jeremy,&lt;BR /&gt;
&lt;BR /&gt;
You can actually set up RADIUS load balancing right on the EXOS or EOS switch as well. It can also be configured through NAC Manager in the Configuration tab. See attached picture. There is also a section in the NAC User Guide that covers configuring Load Balancing.&lt;BR /&gt;
&lt;BR /&gt;
Tyler&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;A href="https://d1uyvls174j03l.cloudfront.net/extremenetworks-us/attachment/RackMultipart20160216-65251-e1btuq-Screen_Shot_2016-02-15_at_8.42.45_PM_inline.png" rel="image" class="fancybox"&gt;&lt;IMG src="https://d1uyvls174j03l.cloudfront.net/extremenetworks-us/attachment/RackMultipart20160216-65251-e1btuq-Screen_Shot_2016-02-15_at_8.42.45_PM_inline.png" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;A href="https://d1uyvls174j03l.cloudfront.net/extremenetworks-us/attachment/RackMultipart20160216-119519-14a41sm-Screen_Shot_2016-02-15_at_8.42.52_PM_inline.png" rel="image" class="fancybox"&gt;&lt;IMG src="https://d1uyvls174j03l.cloudfront.net/extremenetworks-us/attachment/RackMultipart20160216-119519-14a41sm-Screen_Shot_2016-02-15_at_8.42.52_PM_inline.png" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Feb 2016 08:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/lsnat-and-nac-config/m-p/47804#M6699</guid>
      <dc:creator>TylerMarcotte</dc:creator>
      <dc:date>2016-02-16T08:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: LSNAT and NAC Config</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/lsnat-and-nac-config/m-p/47805#M6700</link>
      <description>I have had that setup before, works well.  I was going to try to use LSNAT because I wanted to LB our AD servers also, and I want to use NAC as a test.  Basically, we have had several DC outages and it takes a little while for NAC to try another AD server for authentication.  So LSNAT would take care of that and also spread the load out over our AD infrastructure so all auths aren't hitting our primary AD DC.  I am about to turn 802.1x on everywhere, so LDAP auths are about to go way, way up.  Just want to make sure everything is evenly distributed and failures are transparent to users before we flip the 802.1x switch on all wired ports.  Otherwise, 802.1x in my testing is working flawlessly.</description>
      <pubDate>Tue, 16 Feb 2016 09:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/lsnat-and-nac-config/m-p/47805#M6700</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2016-02-16T09:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: LSNAT and NAC Config</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/lsnat-and-nac-config/m-p/47806#M6701</link>
      <description>Hi Jeremy&lt;BR /&gt;
&lt;BR /&gt;
We've played around with this and implemented below which worked for us. &lt;BR /&gt;
&lt;BR /&gt;
 probe ping icmp&lt;BR /&gt;
  description "check server availability"&lt;BR /&gt;
  inservice&lt;BR /&gt;
  exit&lt;BR /&gt;
!&lt;BR /&gt;
 ip slb real-server access unrestricted&lt;BR /&gt;
!&lt;BR /&gt;
 ip slb serverfarm "name"&lt;BR /&gt;
  real x.x.x.x port 1812&lt;BR /&gt;
   faildetect probe one ping&lt;BR /&gt;
   inservice &lt;BR /&gt;
   exit&lt;BR /&gt;
  real x.x.x.xx port 1812&lt;BR /&gt;
   faildetect probe one ping&lt;BR /&gt;
   inservice &lt;BR /&gt;
   exit&lt;BR /&gt;
  exit&lt;BR /&gt;
!&lt;BR /&gt;
 ip slb vserver "name"&lt;BR /&gt;
  virtual y.y.y.y udp 1812&lt;BR /&gt;
  serverfarm "name"&lt;BR /&gt;
  udp-one-shot &lt;BR /&gt;
  inservice &lt;BR /&gt;
  exit&lt;BR /&gt;
!&lt;BR /&gt;
!&lt;BR /&gt;
&lt;BR /&gt;
Let me know how it works out. &lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Francois&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Feb 2016 22:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/lsnat-and-nac-config/m-p/47806#M6701</guid>
      <dc:creator>Francois_Scheun</dc:creator>
      <dc:date>2016-02-16T22:19:00Z</dc:date>
    </item>
  </channel>
</rss>

