<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: XMC 8.5.6.17 and Aruba 2920 in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49118#M7017</link>
    <description>Hello
&lt;PRE class="tw-data-text tw-text-large tw-ta" data-placeholder="Traduzione" id="tw-target-text" style="text-align: left;" dir="ltr"&gt;&lt;SPAN class="Y2IQFc" lang="en"&gt;Hello,&lt;BR /&gt;The tests continue.
I created a rule on NAC under Switch --&amp;gt; Radius Attributes to send&lt;BR /&gt;Tunnel-Private-Group-Id=%VLAN_ID% --&amp;gt; Vlan Id 2&lt;BR /&gt;Tunnel-Type=13&lt;BR /&gt;Tunnel-Medium-Type=6&lt;BR /&gt;Egress-VLANID=%CUSTOM1% --&amp;gt; Aruba wants hex format ( 0x310002 )&lt;BR /&gt;
The radius sends it as per attached file but the switch responds with this error :&lt;BR /&gt; error. MAC 001AE8548248 port 1 VLAN-Id 0 or unknown.&lt;BR /&gt;&lt;BR /&gt;Giuseppe&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 15 Mar 2022 15:42:00 GMT</pubDate>
    <dc:creator>Giuseppe_Montan</dc:creator>
    <dc:date>2022-03-15T15:42:00Z</dc:date>
    <item>
      <title>XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49109#M7008</link>
      <description>Good Morning, is possible use XMC as NAC to control Aruba switches ?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Giuseppe</description>
      <pubDate>Mon, 14 Feb 2022 17:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49109#M7008</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2022-02-14T17:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49110#M7009</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;As long as the switches are standards based we should be able to integrate with them. We have an integration guide for use with Aruba Wireless controllers but I don't think we have a guide for integration with Aruba switches.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are they actually Aruba switches or are they HP? I do have an old NAC and HP Procure integration guide that may be relevant?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 23:08:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49110#M7009</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2022-02-14T23:08:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49111#M7010</link>
      <description>Thanks for your reply,&lt;BR /&gt;The customer has Aruba 2920.&lt;BR /&gt;At the moment I use SNMP V2 ( only for test ), I receive error whan I try to activate authentication on port / device.&lt;BR /&gt;
&lt;PRE class="tw-data-text tw-text-large tw-ta" data-placeholder="Traduzione" id="tw-target-text" style="text-align: left;" dir="ltr"&gt;&lt;SPAN class="Y2IQFc" lang="en"&gt;Any help would be appreciated&lt;BR /&gt;&lt;BR /&gt;Thankg&lt;BR /&gt;Giuseppe&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 15 Feb 2022 00:47:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49111#M7010</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2022-02-15T00:47:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49112#M7011</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;How are you trying to activate authentication and what is the error that you see?&lt;/P&gt;
&lt;P&gt;Keep in mind that since the device is not Extreme a lot of the automation and configuration that is built into the XMC/NAC product is not going to be able to configure the Aruba 2920 on the fly.&lt;/P&gt;
&lt;P&gt;
&lt;/P&gt;&lt;P&gt;You'll have to enable authentication, configure RADIUS server and point it to NAC. Then build out the switch in NAC to process RADIUS, build out the rules engine, policy profiles and AVP mappings.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 00:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49112#M7011</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2022-02-15T00:58:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49113#M7012</link>
      <description>I have configured the switch to authenticate itself on NAC, Error.docx show what I see.&lt;BR /&gt;Thanks&lt;BR /&gt;Giuseppe</description>
      <pubDate>Tue, 15 Feb 2022 10:14:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49113#M7012</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2022-02-15T10:14:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49114#M7013</link>
      <description>Ok, I found a 1st error on ARUBA SWITCHES.&lt;BR /&gt;&lt;BR /&gt;From Aruba the NAC is not reacheable but if I do a ping I can reach the NAC.&lt;BR /&gt;&lt;BR /&gt;Giuseppe&lt;BR /&gt;</description>
      <pubDate>Tue, 15 Feb 2022 13:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49114#M7013</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2022-02-15T13:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49115#M7014</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Regarding Error.docx: You appear to be trying to enable authentication or control the device through the "Policy" screen. This will not work as the Aruba switch is a 3rd party device. The referenced errors are because the SNMP OIDs and API call do not exist on the Aruba switch.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If anything I would consider it a bug that you can add the device into a policy domain at all. I would have guessed XMC would not allow it based on it being an unsupported switch.&lt;BR /&gt;&lt;BR /&gt;The issue where "NAC is not reachable" but is reachable with ping: Is this an error message that is thrown for a specific service, like RADIUS, on the Aruba?&lt;/P&gt;
&lt;P&gt;If ping is reachable, what is the Aruba switch trying to do that causes the error the NAC is not reachable error? RADIUS? SNMP?&lt;BR /&gt;&lt;BR /&gt;Because this is a 3rd party platform a lot of the automation that is available in XMC will not be available for use.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This is what you can expect to be able to do:&amp;nbsp;&lt;/P&gt;
&lt;STRONG&gt;DEVICES:&lt;/STRONG&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;Monitor the device/Perform basic historical statistic collection as long as the switch supports MIB2.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Backup/Archive the device, but I do not know if we have a native script built to backup the switch. There is one for HP, but you'd have to view it to see if it would work on the Aruba.&lt;/LI&gt;
&lt;/UL&gt;
&lt;STRONG&gt;POLICY:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;Control --&amp;gt; Policy: Nothing in this tab should work. You shouldn't even be able to assign the device a policy domain to attempt to manage the device at all.&lt;/LI&gt;
&lt;/UL&gt;
&lt;STRONG&gt;ACCESS CONTROL:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp;You should add the switch into the "Switches" tab to make it an authorized RADIUS client, but NAC will not be able to dynamically configure RADIUS. Set the "Auth. Access Type" to "Manual" when you add a switch.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;A predefined RADIUS attributes scheme for Aruba doesn't exist. If using RFC 3580 there is a canned configuration. You may need to build a custom attributes scheme based on what the Aruba switch needs for attributes.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;If using RFC 3576/5176 a sysObjectId mapping or override needs to be set per switch to identify how reauthentication should occur.&lt;/LI&gt;
&lt;/UL&gt;
&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan</description>
      <pubDate>Tue, 15 Feb 2022 16:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49115#M7014</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2022-02-15T16:23:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49116#M7015</link>
      <description>&lt;PRE class="tw-data-text tw-text-large tw-ta" data-placeholder="Traduzione" id="tw-target-text" dir="ltr"&gt;&lt;SPAN class="Y2IQFc" lang="en"&gt;Thanks for the reply. at the moment I was able to authenticate a cctv and an access point via macaddress via RFC3580. What if I need to pass a tagged vlan to the switch? Is it possible in your opinion?
It would be useful if you want to connect a phone.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Thanks&lt;BR /&gt;Giuseppe&lt;/PRE&gt;</description>
      <pubDate>Fri, 18 Feb 2022 17:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49116#M7015</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2022-02-18T17:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49117#M7016</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;RFC 3580 is for use with untagged egress. There is no way to indicate a tagged egress using RFC 3580 from my experience.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll need to see if the switch can support RFC 4675&lt;BR /&gt;&lt;BR /&gt;https://datatracker.ietf.org/doc/html/rfc4675&lt;BR /&gt;&lt;BR /&gt;Most Extreme gear has a "policy" concept where we can use filter-id to invoke a policy that is configured to tag/untag accordingly, we do have VSP or ERS that supports RFC 3675.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Sat, 19 Feb 2022 20:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49117#M7016</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2022-02-19T20:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49118#M7017</link>
      <description>Hello
&lt;PRE class="tw-data-text tw-text-large tw-ta" data-placeholder="Traduzione" id="tw-target-text" style="text-align: left;" dir="ltr"&gt;&lt;SPAN class="Y2IQFc" lang="en"&gt;Hello,&lt;BR /&gt;The tests continue.
I created a rule on NAC under Switch --&amp;gt; Radius Attributes to send&lt;BR /&gt;Tunnel-Private-Group-Id=%VLAN_ID% --&amp;gt; Vlan Id 2&lt;BR /&gt;Tunnel-Type=13&lt;BR /&gt;Tunnel-Medium-Type=6&lt;BR /&gt;Egress-VLANID=%CUSTOM1% --&amp;gt; Aruba wants hex format ( 0x310002 )&lt;BR /&gt;
The radius sends it as per attached file but the switch responds with this error :&lt;BR /&gt; error. MAC 001AE8548248 port 1 VLAN-Id 0 or unknown.&lt;BR /&gt;&lt;BR /&gt;Giuseppe&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 15 Mar 2022 15:42:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49118#M7017</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2022-03-15T15:42:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49119#M7018</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Unfortunately I can't see the attached file you sent in.&amp;nbsp; One issue I think you may be running into is that you're missing the tunnel tag for tunnel-private-group-id:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Tunnel-Private-Group-Id=%VLAN_ID%:%VLAN_TUNNEL_TAG%&lt;BR /&gt;&lt;BR /&gt;Per RFC 3580:&amp;nbsp;&lt;/P&gt;
&lt;PRE class="newpage"&gt;   When Tunnel attributes are sent, it is necessary to fill in the Tag
   field.  As noted in &lt;/PRE&gt;
&lt;P&gt;&lt;A href="https://datatracker.ietf.org/doc/html/rfc2868#section-3.1" target="_blank" rel="noopener"&gt;[RFC2868], section&amp;nbsp;3.1&lt;/A&gt;&lt;/P&gt;
&lt;PRE class="newpage"&gt;      The Tag field is one octet in length and is intended to provide a
      means of grouping attributes in the same packet which refer to the
      same tunnel.  Valid values for this field are 0x01 through 0x1F,
      inclusive.  If the Tag field is unused, it MUST be zero (0x00)&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;Can you send a screenshot of the hex output for the Egress-VLAN AVP?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 18:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49119#M7018</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2022-03-16T18:36:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49120#M7019</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;As it was mentioned before RFC 3580 does not support assignments of tagged VLANs to authenticated client/device. In case of Aruba switch you can use RFC 4675. The attribute Egress-VLANID needs a proper value:&amp;nbsp;&lt;BR /&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;first 8 bits specify "tagging": 0x31 for tagged VLAN or 0x32 for untagged VLAN&lt;/LI&gt;
&lt;LI&gt;12 bits are always 0x000&lt;/LI&gt;
&lt;LI&gt;12 bits defined your VLAN&lt;/LI&gt;
&lt;/UL&gt;
all values above are in HEX&lt;BR /&gt;&lt;BR /&gt;e.g. to get VLAN 17 tagged you need - 0x31000011 (means 0x31 - tagged, 0x000 padding, 0x11 - VLAN 17 converted from decimal to HEX)&lt;BR /&gt;&lt;BR /&gt;Now the trick is that you have to send it to switch as decimal value so 0x31000011 have to be converted back to decimal which is 822083601 &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;so your attribute should look like: Egress-VLANID=822083601&lt;BR /&gt;&lt;BR /&gt;Good luck&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Piotr</description>
      <pubDate>Thu, 17 Mar 2022 16:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49120#M7019</guid>
      <dc:creator>Piotr_Szolkowsk</dc:creator>
      <dc:date>2022-03-17T16:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: XMC 8.5.6.17 and Aruba 2920</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49121#M7020</link>
      <description>----SOLVED-----&lt;BR /&gt;Good Morning&lt;BR /&gt;Finally I have found the way to use the NAC to authtenticate devices on Aruba2920 or newer&lt;BR /&gt;&lt;BR /&gt;CONTROL --&amp;gt; ACCESSCONTROL --&amp;gt; ENGINE --&amp;gt; SWITCHES --&amp;gt; RADIUS ATTRIBUTES&lt;BR /&gt;&lt;BR /&gt;Tunnel-Private-Group-Id=%VLAN_ID%&lt;BR /&gt;Tunnel-Type=13:%CUSTOM1% &lt;BR /&gt;Tunnel-Medium-Type=6:%CUSTOM1%&amp;nbsp; &lt;BR /&gt;Egress-VLAN-Name=%CUSTOM1% &lt;BR /&gt;Egress-VLANID=%CUSTOM1%&lt;BR /&gt;&lt;BR /&gt;CUSTOM1 can be 1VLANNAME for tagged port and 2vlanname for untagged port&lt;BR /&gt;&lt;BR /&gt;Thanks for your support&lt;BR /&gt;&lt;BR /&gt;have a nice day&lt;BR /&gt;Giuseppe&lt;BR /&gt;</description>
      <pubDate>Thu, 31 Mar 2022 12:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-8-5-6-17-and-aruba-2920/m-p/49121#M7020</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2022-03-31T12:35:00Z</dc:date>
    </item>
  </channel>
</rss>

