<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Netlogin MAC-based auth problems in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48119#M6773</link>
    <description>Ilya,&lt;BR /&gt;
&lt;BR /&gt;
I guess you are almost there.&lt;BR /&gt;
I could see that the AAA module do not have a Radius server configured for Netlogin.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-Mac-based-Netlogin-with-Radius" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-Mac-based-Netlogin-with-R...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
AAA configuration from the article. &lt;BR /&gt;
&lt;BR /&gt;
&lt;U&gt;Switch Radius configuration:&lt;/U&gt;&lt;UL&gt; 
&lt;LI&gt;configure radius netlogin primary server &lt;RADIUS server="" ip=""&gt; client-ip &lt;SOURCE ip="" for="" radius="" request="" from="" switch=""&gt; 
&lt;/SOURCE&gt;&lt;/RADIUS&gt;&lt;/LI&gt;&lt;LI&gt;configure radius netlogin primary shared-secret &lt;SECRET&gt; 
&lt;/SECRET&gt;&lt;/LI&gt;&lt;LI&gt;enable radius netlogin&lt;/LI&gt;&lt;/UL&gt;Or have you already configured the Radius server ("show config aaa") ?&lt;BR /&gt;
&lt;BR /&gt;
since you do not want any action taken by NAC you also need to add the port to intended VLAN (ISP mode).&lt;BR /&gt;
&lt;BR /&gt;
I hope this helps...</description>
    <pubDate>Sat, 27 May 2017 21:35:00 GMT</pubDate>
    <dc:creator>Karthik_Mohando</dc:creator>
    <dc:date>2017-05-27T21:35:00Z</dc:date>
    <item>
      <title>Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48109#M6763</link>
      <description>Hello, everybody,&lt;BR /&gt;
&lt;BR /&gt;
I've got a recommendation from Extreme's empoloyee (he is really expert!) to configure netlogin mac-based auth. (I need it to bring more data like Device Type and Operationg System from identity-management on Summits to Netsight. NAC is also involved).&lt;BR /&gt;
&lt;BR /&gt;
He said:&lt;BR /&gt;
&lt;BR /&gt;
"For  MAC-auth your users does not need to enter anything at all – they just  connecting to the network as usual and NAC automatically does the mac-auth (for  visibility purpose only) . When you add “switch” into the NAC switch database ,  you can select “no attribute to send back” , in this case MAC-auth happens but  no policy will be applied to the port , so clients connected as usual but NAC  knows everything about the client and provide this details in NMS  screens/reports."&lt;BR /&gt;
&lt;BR /&gt;
How can I configure that "MAC-auth for visibility purpose only"? I've tried to do so many times and every time switch just blocks a port when I attach any device...&lt;BR /&gt;
&lt;BR /&gt;
Please, help! Does somebody understand how exactly should I do configure mac-based netlogin auth on summit taking into the consideration the recommendation above?&lt;BR /&gt;
&lt;BR /&gt;
Many thanks in advance,&lt;BR /&gt;
&lt;BR /&gt;
Ilya&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 26 May 2017 23:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48109#M6763</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2017-05-26T23:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48110#M6764</link>
      <description>Please post your current switch configuration.</description>
      <pubDate>Sat, 27 May 2017 00:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48110#M6764</guid>
      <dc:creator>Matthew_Helm1</dc:creator>
      <dc:date>2017-05-27T00:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48111#M6765</link>
      <description>Hello, Matthew,&lt;BR /&gt;
&lt;BR /&gt;
thanks, here it is (below). In such configuration the device works fine. There isn't anything related to netlogin mac-based auth now (I removed it).&lt;BR /&gt;
&lt;BR /&gt;
X430-48t.3 # show configuration&lt;BR /&gt;
#&lt;BR /&gt;
# Module devmgr configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure snmp sysContact "support@extremenetworks.com, +1 888 257 3000"&lt;BR /&gt;
configure sys-recovery-level switch reset&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module vlan configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure vlan default delete ports all&lt;BR /&gt;
configure vr VR-Default delete ports 1-52&lt;BR /&gt;
configure vr VR-Default add ports 1-52&lt;BR /&gt;
configure vlan default delete ports 8,13,48,50&lt;BR /&gt;
enable jumbo-frame ports all&lt;BR /&gt;
create vlan "VLAN10"&lt;BR /&gt;
configure vlan VLAN10 tag 10&lt;BR /&gt;
create vlan "VLAN1024"&lt;BR /&gt;
create vlan "VLAN1025"&lt;BR /&gt;
create vlan "vlan3139"&lt;BR /&gt;
configure vlan vlan3139 tag 3139&lt;BR /&gt;
enable sharing 46 grouping 46,48 algorithm address-based L3 lacp&lt;BR /&gt;
configure vlan Default add ports 1-7,9-12,14-47,49,51-52 untagged&lt;BR /&gt;
configure vlan VLAN10 add ports 44,49 tagged&lt;BR /&gt;
configure vlan vlan3139 add ports 49 tagged&lt;BR /&gt;
configure vlan vlan3139 add ports 8,13 untagged&lt;BR /&gt;
configure vlan Default ipaddress 192.168.13.5 255.255.254.0&lt;BR /&gt;
configure vlan VLAN10 ipaddress 10.10.10.55 255.255.255.0&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module fdb configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module rtmgr configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure iproute add default 192.168.13.3&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module mcmgr configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure forwarding ipmc lookup-key mac-vlan&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module aaa configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure account admin encrypted "$5$uni7jv$Dr65.wIgsf7XteqWQtqJrhwYtDzB0lsiHNn&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module acl configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module cfgmgr configuration.&lt;BR /&gt;
#&lt;BR /&gt;
enable cli-config-logging&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module dosprotect configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module dot1ag configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module eaps configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module edp configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module elrp configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module ems configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure syslog add 192.168.13.246:514 vr VR-Mgmt local7&lt;BR /&gt;
enable log target syslog 192.168.13.246:514 vr VR-Mgmt local7&lt;BR /&gt;
configure log target syslog 192.168.13.246:514 vr VR-Mgmt local7 filter DefaultF&lt;BR /&gt;
configure log target syslog 192.168.13.246:514 vr VR-Mgmt local7 match Any&lt;BR /&gt;
configure log target syslog 192.168.13.246:514 vr VR-Mgmt local7 format timestam&lt;BR /&gt;
configure syslog add 192.168.13.246:514 vr VR-Default local0&lt;BR /&gt;
enable log target syslog 192.168.13.246:514 vr VR-Default local0&lt;BR /&gt;
configure log target syslog 192.168.13.246:514 vr VR-Default local0 filter Defau&lt;BR /&gt;
configure log target syslog 192.168.13.246:514 vr VR-Default local0 match Any&lt;BR /&gt;
configure log target syslog 192.168.13.246:514 vr VR-Default local0 format times&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module epm configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module erps configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module esrp configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module etmon configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module exsshd configuration.&lt;BR /&gt;
#&lt;BR /&gt;
enable ssh2&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module hal configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module idMgr configuration.&lt;BR /&gt;
#&lt;BR /&gt;
enable identity-management&lt;BR /&gt;
configure identity-management add ports 1-48,50-52&lt;BR /&gt;
configure identity-management kerberos snooping add server 192.168.13.20&lt;BR /&gt;
configure identity-management kerberos snooping add server 192.168.13.51&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module ipSecurity configuration.&lt;BR /&gt;
#&lt;BR /&gt;
enable ip-security dhcp-snooping vlan Default port 1-52 violation-action none&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module lacp configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module lldp configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module mrp configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module netLogin configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module netTools configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure dns-client add name-server 192.168.13.20 vr VR-Default&lt;BR /&gt;
configure bootprelay add 192.168.13.251 vr VR-Default&lt;BR /&gt;
enable bootprelay ipv4 vlan Default&lt;BR /&gt;
configure bootprelay vlan Default add 192.168.13.251&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module poe configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module snmpMaster configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure snmpv3 add user "user" engine-id 80:00:07:7c:03:00:04:96:98:0e:bc autha:23:da:23:d7:23:e8:3f:23:d8:21:23:c7:5c:23:95:39 privacy privacy-encrypted loca:c7:5c:23:95:39&lt;BR /&gt;
configure snmpv3 add user "snmpuser" engine-id 80:00:07:7c:03:00:04:96:98:0e:bc 23??79:57:23??6d:24:23:7d:23:b1 privacy privacy-encrypted localized-key 75:2&lt;BR /&gt;
configure snmpv3 add group "NAC" user "snmpuser" sec-model usm&lt;BR /&gt;
configure snmpv3 add access "NAC" sec-model usm sec-level priv read-view "intern&lt;BR /&gt;
configure snmpv3 add mib-view "internet" subtree 1.0/80 type included&lt;BR /&gt;
configure snmpv3 add target-addr "informtarget" param "informparam" ipaddress 19&lt;BR /&gt;
configure snmpv3 add target-params "informparam" user "user" mp-model snmpv3 sec&lt;BR /&gt;
configure snmpv3 add notify "defaultinform" tag "defaultinform" type inform&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module stp configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module techSupport configuration.&lt;BR /&gt;
#&lt;BR /&gt;
enable tech-support collector&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module telnetd configuration.&lt;BR /&gt;
#&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module thttpd configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure ssl certificate hash-algorithm sha512&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
# Module xmlc configuration.&lt;BR /&gt;
#&lt;BR /&gt;
create xml-notification target netsight_192.168.13.248 url &lt;A href="https://192.168.13.24" target="_blank" rel="nofollow noreferrer noopener"&gt;https://192.168.13.24&lt;/A&gt;&lt;BR /&gt;
configure xml-notification target netsight_192.168.13.248 user ssadmin encrypted&lt;BR /&gt;
configure xml-notification target netsight_192.168.13.248 from 192.168.13.5&lt;BR /&gt;
enable xml-notification netsight_192.168.13.248&lt;BR /&gt;
configure xml-notification target netsight_192.168.13.248 add idMgr&lt;BR /&gt;
X430-48t.4 #&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sat, 27 May 2017 00:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48111#M6765</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2017-05-27T00:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48112#M6766</link>
      <description>Maybe you need to set netlogin auth optional instead of required.&lt;BR /&gt;
&lt;BR /&gt;
configure netlogin port 1:36 authentication mode optional&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sat, 27 May 2017 01:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48112#M6766</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2017-05-27T01:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48113#M6767</link>
      <description>Thanks, Jeremy...&lt;BR /&gt;
&lt;BR /&gt;
I think "configure netlogin port 1:36 authentication mode optional" isn't enough... Should it be some more configuration strings? I think, it must.</description>
      <pubDate>Sat, 27 May 2017 01:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48113#M6767</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2017-05-27T01:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48114#M6768</link>
      <description>can you run  show netlogin session port...  The command is similar to that but will show the status of the device.</description>
      <pubDate>Sat, 27 May 2017 01:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48114#M6768</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2017-05-27T01:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48115#M6769</link>
      <description>&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="61e33b30697b4356ac07a617456e9caa_RackMultipart20170527-50151-1ge6zrb-IMG_0714_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1407i100F83788B93C29D/image-size/large?v=v2&amp;amp;px=999" role="button" title="61e33b30697b4356ac07a617456e9caa_RackMultipart20170527-50151-1ge6zrb-IMG_0714_inline.png" alt="61e33b30697b4356ac07a617456e9caa_RackMultipart20170527-50151-1ge6zrb-IMG_0714_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 27 May 2017 01:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48115#M6769</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2017-05-27T01:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48116#M6770</link>
      <description>Hello, Jeremy,&lt;BR /&gt;
&lt;BR /&gt;
I have not such commands in 16.1.2.14 on X430:&lt;BR /&gt;
&lt;BR /&gt;
X430-48t.10 # configure netlogin port 17 ?&lt;BR /&gt;
  allow           Allow traffic, even when not authenticated&lt;BR /&gt;
  mode            Configure port operation mode&lt;BR /&gt;
  no-restart      Do not restart the port when all clients unauthenticate&lt;BR /&gt;
  restart         Restart the port when all clients unauthenticate&lt;BR /&gt;
* X430-48t.10 # configure netlogin port 17&lt;BR /&gt;
&lt;BR /&gt;
Is this an equal - configure netlogin port 17 allow egress-traffic all_cast ?&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sat, 27 May 2017 01:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48116#M6770</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2017-05-27T01:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48117#M6771</link>
      <description>I have some config changes now:&lt;BR /&gt;
&lt;BR /&gt;
create vlan "NTLG"&lt;BR /&gt;
&lt;BR /&gt;
# Module netLogin configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure netlogin move-fail-action authenticate&lt;BR /&gt;
configure netlogin vlan NTLG&lt;BR /&gt;
enable netlogin mac&lt;BR /&gt;
enable netlogin ports 17 mac&lt;BR /&gt;
configure netlogin ports 17 mode mac-based-vlans&lt;BR /&gt;
configure netlogin ports 17 no-restart&lt;BR /&gt;
configure netlogin ports 17 allow egress-traffic all_cast&lt;BR /&gt;
&lt;BR /&gt;
After these changes I got to log:&lt;BR /&gt;
&lt;BR /&gt;
05/27/2017 13:04:31.17 &lt;I&gt; Authentication failed for Network Login MAC user F4:6D:04:1B:D0:9B Mac F4:6D:04:1B:D0:9B port 17&lt;BR /&gt;
05/27/2017 13:04:31.17 &lt;NL.MAC.MACLISTEMPTY&gt; Mac authentication was initiated, but mac-list for virtual router VR-Default is empty&lt;BR /&gt;
&lt;BR /&gt;
Should I add all ports to NTLG vlan as tagged?&lt;BR /&gt;
&lt;BR /&gt;&lt;/NL.MAC.MACLISTEMPTY&gt;&lt;/I&gt;</description>
      <pubDate>Sat, 27 May 2017 01:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48117#M6771</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2017-05-27T01:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48118#M6772</link>
      <description>The final changes:&lt;BR /&gt;
&lt;BR /&gt;
# Module netLogin configuration.&lt;BR /&gt;
#&lt;BR /&gt;
configure netlogin move-fail-action authenticate&lt;BR /&gt;
configure netlogin vlan NTLG&lt;BR /&gt;
enable netlogin mac&lt;BR /&gt;
configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48 ports 17&lt;BR /&gt;
enable netlogin ports 17 mac&lt;BR /&gt;
configure netlogin ports 17 mode mac-based-vlans&lt;BR /&gt;
configure netlogin ports 17 no-restart&lt;BR /&gt;
configure netlogin ports 17 allow egress-traffic all_cast&lt;BR /&gt;
* X430-48t.41 #&lt;BR /&gt;
&lt;BR /&gt;
The message about MacListEmpty is gone, but it's stll:&lt;BR /&gt;
&lt;BR /&gt;
05/27/2017 13:11:16.16 &lt;I&gt; Authentication failed for Network Login MAC user F46D041BD09B Mac F4:6D:04:1B:D0:9B port 17&lt;BR /&gt;
&lt;BR /&gt;
But it seems like the port isn't blocked now (I am out of the office and try remotely)&lt;BR /&gt;
&lt;BR /&gt;&lt;/I&gt;</description>
      <pubDate>Sat, 27 May 2017 01:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48118#M6772</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2017-05-27T01:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48119#M6773</link>
      <description>Ilya,&lt;BR /&gt;
&lt;BR /&gt;
I guess you are almost there.&lt;BR /&gt;
I could see that the AAA module do not have a Radius server configured for Netlogin.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-Mac-based-Netlogin-with-Radius" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-Mac-based-Netlogin-with-R...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
AAA configuration from the article. &lt;BR /&gt;
&lt;BR /&gt;
&lt;U&gt;Switch Radius configuration:&lt;/U&gt;&lt;UL&gt; 
&lt;LI&gt;configure radius netlogin primary server &lt;RADIUS server="" ip=""&gt; client-ip &lt;SOURCE ip="" for="" radius="" request="" from="" switch=""&gt; 
&lt;/SOURCE&gt;&lt;/RADIUS&gt;&lt;/LI&gt;&lt;LI&gt;configure radius netlogin primary shared-secret &lt;SECRET&gt; 
&lt;/SECRET&gt;&lt;/LI&gt;&lt;LI&gt;enable radius netlogin&lt;/LI&gt;&lt;/UL&gt;Or have you already configured the Radius server ("show config aaa") ?&lt;BR /&gt;
&lt;BR /&gt;
since you do not want any action taken by NAC you also need to add the port to intended VLAN (ISP mode).&lt;BR /&gt;
&lt;BR /&gt;
I hope this helps...</description>
      <pubDate>Sat, 27 May 2017 21:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48119#M6773</guid>
      <dc:creator>Karthik_Mohando</dc:creator>
      <dc:date>2017-05-27T21:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48120#M6774</link>
      <description>Hello, Karthik,&lt;BR /&gt;
&lt;BR /&gt;
thanks for your reply. I haven't RADIUS configured yet. Is it really required? Could it be local authentication?&lt;BR /&gt;
&lt;BR /&gt;
Could you please explain this in more details - "since you do not want any action taken by NAC you also need to add the port to intended VLAN (ISP mode)." - what do you mean?&lt;BR /&gt;
&lt;BR /&gt;
Many thanks in advance,&lt;BR /&gt;
&lt;BR /&gt;
Ilya&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sat, 27 May 2017 21:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48120#M6774</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2017-05-27T21:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48121#M6775</link>
      <description>Hi Ilya, &lt;BR /&gt;
&lt;BR /&gt;
Local database can also be used for MAC authentication without Radius server. In the case of using local database of switch, you need following configurations:&lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;configure netlogin mac authentication database-order local&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;create netlogin local-user "&lt;CAPITAL mac="" address=""&gt;" ""&lt;BR /&gt;
&lt;BR /&gt;
ex&amp;gt; create netlogin local-user "507B9DD58ECE" "507B9DD58ECE"&lt;BR /&gt;
&lt;/CAPITAL&gt;&lt;/I&gt;&lt;BR /&gt;
You have configured "NTLG" VLAN as netlogin VLAN and it means that NTLG VLAN will be used for unauthenticated clients. You need to assign a VLAN to be used for MAC authenticated clients via one of either two ways in below:&lt;BR /&gt;
(Let say the MAC authenticated clients should be assigned into VLAN3139)&lt;BR /&gt;
&lt;BR /&gt;
i. Pre-configure the VLAN on the port 17&lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;configure vlan VLAN3139 add port 17&lt;/I&gt;&lt;BR /&gt;
&lt;BR /&gt;
Port 17 will be assigned to VLAN3139 after MAC authentication.&lt;BR /&gt;
&lt;BR /&gt;
ii. Use VLAN-VSA&lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;configure netlogin local-user "&lt;MAC address=""&gt; vlan-vsa [tagged | untagged] VLAN3139&lt;/MAC&gt;&lt;/I&gt;&lt;BR /&gt;
&lt;BR /&gt;
Since you configured port mode as "mac-based-vlan" (not port-based-vlan), I think that using VLAN-VSA would be proper way for the mode.&lt;BR /&gt;
&lt;BR /&gt;
I hope this helps...</description>
      <pubDate>Sat, 27 May 2017 21:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48121#M6775</guid>
      <dc:creator>David_Choi</dc:creator>
      <dc:date>2017-05-27T21:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48122#M6776</link>
      <description>Hello, David,&lt;BR /&gt;
&lt;BR /&gt;
thank you!&lt;BR /&gt;
&lt;BR /&gt;
Do you mean that to make MAC-based auth feature work I should manually create MAC database of all devices which use the switch?&lt;BR /&gt;
&lt;BR /&gt;
It condtradicts a bit with what other Extreme's employee said: &lt;BR /&gt;
&lt;BR /&gt;
"&lt;I&gt;For MAC-auth your users does not need to enter anything at all – they just connecting to the network as usual and NAC automatically does the mac-auth (for visibility purpose only)&lt;/I&gt;"&lt;BR /&gt;
&lt;BR /&gt;
Thanks!</description>
      <pubDate>Sat, 27 May 2017 21:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48122#M6776</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2017-05-27T21:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48123#M6777</link>
      <description>Hi Ilya,&lt;BR /&gt;
&lt;BR /&gt;
I meant the MAC-based auth using local-database case. You can also use MAC address prefix (i.e. particular MAC OUI) as below URL:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-Configure/?q=netlogin+oui&amp;amp;#38;l=en_US&amp;amp;#38;c=Extreme_Software%3AExtremeXOS_EXOS&amp;amp;#38;fs=Search&amp;amp;#38;pn=1" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-Configure/?q=netlogin+oui&amp;amp;l=en_...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
The mention you referred from other Extreme's employee is just about NAC and the view of client. MAC auth based on local-database is not also required anything to be entered by client.&lt;BR /&gt;
Only difference is that the user is authenticated by where switch local (local-database) or NAC or RADIUS for the user's MAC address.&lt;BR /&gt;</description>
      <pubDate>Sat, 27 May 2017 21:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48123#M6777</guid>
      <dc:creator>David_Choi</dc:creator>
      <dc:date>2017-05-27T21:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48124#M6778</link>
      <description>Hi Ilya,&lt;BR /&gt;
&lt;BR /&gt;
to use NAC for increased visibility via MAC "authentication", you need to configure optional MAC authentication (netlogin) on the port with NAC as RADIUS server. Thus the switch will send the MAC address of a connected end system to NAC. With authentication optional, the end system will be allowed onto the network even if it is not (yet) known by NAC.&lt;BR /&gt;
&lt;BR /&gt;
Erik</description>
      <pubDate>Mon, 29 May 2017 15:12:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/48124#M6778</guid>
      <dc:creator>Erik_Auerswald</dc:creator>
      <dc:date>2017-05-29T15:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: RE: Netlogin MAC-based auth problems</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/113146#M12304</link>
      <description>&lt;P&gt;Were you ever able to solve the netlogin issue? I have the same issue with netlogin on my switch using MAC authenticaiton to a radius server.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Info:nl.ClientAuthFailure&amp;gt; Authentication failed for Network Login MAC user XX:XX:XX:XX:XX:XX Mac XX:XX:XX:XX:XX:XX port 1:8&lt;BR /&gt;&amp;lt;Erro:nl.mac.MacListEmpty&amp;gt; Mac authentication was initiated, but mac-list for virtual router VR-Default is empty&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 20:09:43 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netlogin-mac-based-auth-problems/m-p/113146#M12304</guid>
      <dc:creator>kebenoit</dc:creator>
      <dc:date>2024-09-17T20:09:43Z</dc:date>
    </item>
  </channel>
</rss>

