<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't select user groups in authentication mapping in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77590#M8699</link>
    <description>In the EAC you can configure the authentication rules in the AAA section. in one of those rules (Management Login) I want to configure an user group .&lt;BR /&gt;
&lt;BR /&gt;
According to the help file ,should this be possible.&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;User/MAC/Host&lt;/B&gt;&lt;BR /&gt;
Select the &lt;B&gt;Pattern&lt;/B&gt; radio button and enter the username, MAC address, or hostname that the end-system must match for this mapping. Or, select the &lt;B&gt;Group&lt;/B&gt; radio button and select a user group or end-system group from the drop-down list. If you enter a MAC address, you can use a colon (:) or a dash (-) as an address delimiter, but not a period (.).&lt;BR /&gt;
&lt;BR /&gt;
The only groups I can select are End-System Groups.&lt;BR /&gt;
&lt;BR /&gt;
How can I select an user groups ?&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="95f5949fad57431fbb3f3437aa290353_d5b4e711-4d8a-419c-85fb-53efacc30081.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/216i666A4D75975E5559/image-size/large?v=v2&amp;amp;px=999" role="button" title="95f5949fad57431fbb3f3437aa290353_d5b4e711-4d8a-419c-85fb-53efacc30081.jpg" alt="95f5949fad57431fbb3f3437aa290353_d5b4e711-4d8a-419c-85fb-53efacc30081.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="95f5949fad57431fbb3f3437aa290353_58a38fc5-77fb-4725-a854-5348873a063c.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4926i3E1F870E1288267F/image-size/large?v=v2&amp;amp;px=999" role="button" title="95f5949fad57431fbb3f3437aa290353_58a38fc5-77fb-4725-a854-5348873a063c.jpg" alt="95f5949fad57431fbb3f3437aa290353_58a38fc5-77fb-4725-a854-5348873a063c.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2019 16:47:39 GMT</pubDate>
    <dc:creator>JohanHendrikx</dc:creator>
    <dc:date>2019-08-08T16:47:39Z</dc:date>
    <item>
      <title>Can't select user groups in authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77590#M8699</link>
      <description>In the EAC you can configure the authentication rules in the AAA section. in one of those rules (Management Login) I want to configure an user group .&lt;BR /&gt;
&lt;BR /&gt;
According to the help file ,should this be possible.&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;User/MAC/Host&lt;/B&gt;&lt;BR /&gt;
Select the &lt;B&gt;Pattern&lt;/B&gt; radio button and enter the username, MAC address, or hostname that the end-system must match for this mapping. Or, select the &lt;B&gt;Group&lt;/B&gt; radio button and select a user group or end-system group from the drop-down list. If you enter a MAC address, you can use a colon (:) or a dash (-) as an address delimiter, but not a period (.).&lt;BR /&gt;
&lt;BR /&gt;
The only groups I can select are End-System Groups.&lt;BR /&gt;
&lt;BR /&gt;
How can I select an user groups ?&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="95f5949fad57431fbb3f3437aa290353_d5b4e711-4d8a-419c-85fb-53efacc30081.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/216i666A4D75975E5559/image-size/large?v=v2&amp;amp;px=999" role="button" title="95f5949fad57431fbb3f3437aa290353_d5b4e711-4d8a-419c-85fb-53efacc30081.jpg" alt="95f5949fad57431fbb3f3437aa290353_d5b4e711-4d8a-419c-85fb-53efacc30081.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="95f5949fad57431fbb3f3437aa290353_58a38fc5-77fb-4725-a854-5348873a063c.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4926i3E1F870E1288267F/image-size/large?v=v2&amp;amp;px=999" role="button" title="95f5949fad57431fbb3f3437aa290353_58a38fc5-77fb-4725-a854-5348873a063c.jpg" alt="95f5949fad57431fbb3f3437aa290353_58a38fc5-77fb-4725-a854-5348873a063c.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 16:47:39 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77590#M8699</guid>
      <dc:creator>JohanHendrikx</dc:creator>
      <dc:date>2019-08-08T16:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select user groups in authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77591#M8700</link>
      <description>Extra information: I cann't select LDAP user groups that are created.</description>
      <pubDate>Fri, 09 Aug 2019 15:05:06 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77591#M8700</guid>
      <dc:creator>JohanHendrikx</dc:creator>
      <dc:date>2019-08-09T15:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select user groups in authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77592#M8701</link>
      <description>Hello Johan,&lt;BR /&gt;
&lt;BR /&gt;
LDAP usergroups can only be used in the AAA with authentication type "Registration (Auth&amp;amp;Admin)".&lt;BR /&gt;
&lt;BR /&gt;
Are you looking to send management authentications to a different authentication server based on LDAP group membership, or prevent access based on group membership?&lt;BR /&gt;
&lt;BR /&gt;
If you're looking to prevent access based on LDAP membership the way you would do that is create a rule in the rules engine with LDAP usergroup that had an accept with appropriate management access AVPs, and below this rule create another rule for all management requests to would deny. &lt;BR /&gt;
&lt;BR /&gt;
That way unless you're part of the LDAP group configured in the first rule you'll fall into a deny role. &lt;BR /&gt;
&lt;BR /&gt;
Let me know if this is what you're looking for.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
-Ryan</description>
      <pubDate>Sun, 11 Aug 2019 00:51:02 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77592#M8701</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2019-08-11T00:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select user groups in authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77593#M8702</link>
      <description>I've made roles and tested a connection to a swtich and a connection to an EWC controller.&lt;BR /&gt;
&lt;BR /&gt;
Both systems have the same EAC controlers.&lt;BR /&gt;
 &lt;BR /&gt;
When connecting to the  EWC with  wrong credentials , the connection is refused.&lt;BR /&gt;
When I do the test to a switch I can loging and have user rights.&lt;BR /&gt;
&lt;BR /&gt;
Did I forgot something?</description>
      <pubDate>Thu, 15 Aug 2019 16:37:41 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77593#M8702</guid>
      <dc:creator>JohanHendrikx</dc:creator>
      <dc:date>2019-08-15T16:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select user groups in authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77594#M8703</link>
      <description>I"d have to take a look at the configuration.&lt;BR /&gt;
&lt;BR /&gt;
If you look at the Alarms &amp;amp; Events --&amp;gt; Events --&amp;gt; Type of "NAC" or "Access Control Engine".&lt;BR /&gt;
&lt;BR /&gt;
When you login to the switch and the controller take a look at those events. Did they hit the same rule?&lt;BR /&gt;
&lt;BR /&gt;
Does the rule they hit indicate they were returned a "reject"?&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
-Ryan</description>
      <pubDate>Sat, 17 Aug 2019 23:17:02 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77594#M8703</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2019-08-17T23:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select user groups in authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77595#M8704</link>
      <description>Results&lt;BR /&gt;
Management login to switch 10.2.112.211.           No Access granted for User: x326000, due to NAC Filter-Id: Enterasys:version=1:policy=Deny Access, Profile: Registration Denied Access NAC Profile Authentication Protocol: PAP, Request Attributes - Service-Type: 1, User-Name: x326000, Calling-Station-Id: 00-00-00-00-00-00, NAS-IP-Address: 10.2.112.211, OPENFLOW_DATAPATH_ID: 19706979330, NAS-Identifier: SW-A11, Called-Station-Id: 00-04-96-A0-A4-02, NAS-Port-Type: 5, NAS-Port: 0, Source-Address: 10.2.112.211 - Response Attributes - Filter-Id: Enterasys:version=1:policy=Deny Access - This is an administrative request because the MAC is zeros: 00-00-00-00-00-00, username is not null and no EAP-Message, MS-CHAP-Challenge or Tunnel-Client-Endpoint is present.&lt;BR /&gt;
&lt;BR /&gt;
Management login to wireless controller 10.2.112.3. No Access granted for User: x326000, due to NAC Service-Type: null,                           Profile: Registration Denied Access NAC Profile Authentication Protocol: PAP, Request Attributes - Service-Type: 7, User-Name: x326000, NAS-IP-Address: 10.2.114.1, NAS-Identifier: EWC, NAS-Port-Type: 5, NAS-Port: 0, Source-Address: 10.2.112.3 - Response Attributes - Filter-Id: Enterasys:version=1:policy=Deny Access, Login-LAT-Port: 0 - This is an administrative request because the MAC is null, username is not null and no EAP-Message, MS-CHAP-Challenge or Tunnel-Client-Endpoint is present.</description>
      <pubDate>Wed, 21 Aug 2019 13:30:09 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77595#M8704</guid>
      <dc:creator>JohanHendrikx</dc:creator>
      <dc:date>2019-08-21T13:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select user groups in authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77596#M8705</link>
      <description>The switch might be allowing you in just because the Access was "Accept". Can you change the "Denied Access NAC profile" and set it to "Reject authentication requests". &lt;BR /&gt;
&lt;BR /&gt;
It will be the option at the top of the profile.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
-Ryan</description>
      <pubDate>Wed, 21 Aug 2019 19:31:09 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77596#M8705</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2019-08-21T19:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select user groups in authentication mapping</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77597#M8706</link>
      <description>Ryan, this works. Thanks for the solution</description>
      <pubDate>Wed, 21 Aug 2019 20:19:40 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/can-t-select-user-groups-in-authentication-mapping/m-p/77597#M8706</guid>
      <dc:creator>JohanHendrikx</dc:creator>
      <dc:date>2019-08-21T20:19:40Z</dc:date>
    </item>
  </channel>
</rss>

