<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x clients transition to MAC auth and back again, every hour? in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78541#M8807</link>
    <description>&lt;P&gt;Thanks Z,&lt;/P&gt;  &lt;P&gt;So I think I have translated this to being the fact that netlogin is showing both a 802.1x and MAC auth for the same device, with obviously 802.1x is taking precedence.&lt;/P&gt;  &lt;P&gt;The re-auth for both auth types is set to 3600 seconds.&lt;/P&gt;  &lt;P&gt;The end-system events is probably showing the audit logs&amp;nbsp;of these going through re-authentication&amp;nbsp;for each authentication type, 1 hour apart, there being a 19 minute difference between the two.&lt;/P&gt;  &lt;P&gt;Whats probably happening is&amp;nbsp;the time between a MAC re-auth and then a 802.1x re-auth (19 minutes) is showing up in the aduit as a MAC Auth, but the reality is the switch always remains authenticated using 802.1x.&lt;/P&gt;  &lt;P&gt;Do you think that sums it up?&lt;/P&gt;  &lt;P&gt;Cheers&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2020 18:54:02 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2020-06-30T18:54:02Z</dc:date>
    <item>
      <title>802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78530#M8796</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;  &lt;P&gt;Hoping someone can help me explain the behaviour below and say either if it is normal or a means to correct it.&lt;/P&gt;  &lt;P&gt;It seems that every hour a re-authentication of 802.1x is triggered, that process initially introduces a MAC auth that temporarily hits the default catch all rule that we have yet to flip into a deny rule.&lt;/P&gt;  &lt;P&gt;After that it then re-authenticates correctly using EAP-TLS until the next hour?&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2bd96e42b65345fb8b814ff78508ced5_9780cd70-5406-4c5d-a8ef-a55dad8793eb.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1277i46B98E7607F93CE4/image-size/large?v=v2&amp;amp;px=999" role="button" title="2bd96e42b65345fb8b814ff78508ced5_9780cd70-5406-4c5d-a8ef-a55dad8793eb.png" alt="2bd96e42b65345fb8b814ff78508ced5_9780cd70-5406-4c5d-a8ef-a55dad8793eb.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Many thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 22:47:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78530#M8796</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2020-06-25T22:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78531#M8797</link>
      <description>&lt;P&gt;Is this wired?&amp;nbsp; If so, do you have reauth settings setup on your ports for every hour?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 02:51:10 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78531#M8797</guid>
      <dc:creator>Brian_Anderson1</dc:creator>
      <dc:date>2020-06-26T02:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78532#M8798</link>
      <description>&lt;P&gt;Hi Brian,&lt;/P&gt;  &lt;P&gt;Thanks for answering.&lt;/P&gt;  &lt;P&gt;Yes, it is wired and both MAC and 802.1x are set to re-auth at 3600 seconds, which I expected would&amp;nbsp;explain&amp;nbsp;the 1 hour, and the cycle it goes for that configuration could&amp;nbsp;be natural?&amp;nbsp;&lt;/P&gt;  &lt;P&gt;It doesn’t seem efficient or possibly correct&amp;nbsp;switching between authentication methods and temporarily , albeit briefly, move to&amp;nbsp;a catchall rule because of it.&lt;/P&gt;  &lt;P&gt;The port has both a PC that is .1x capable and a phone that isn’t, hence both.&lt;/P&gt;  &lt;P&gt;If that catch all rule was a deny / reject rule I’m not sure what the result would be?&lt;/P&gt;  &lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 04:38:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78532#M8798</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2020-06-26T04:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78533#M8799</link>
      <description>&lt;P&gt;Wonder if the answer is in this thread where Zdenek mentions IMHO.&lt;/P&gt;  &lt;P&gt;&lt;A href="https://extreme.connectedcommunity.org/communities/community-home/digestviewer/view-question?ContributedContentKey=23d583df-9007-487f-b499-40e984ca8e22&amp;amp;CommunityKey=d4b57428-7c7e-4bce-886a-356352ffa2c0&amp;amp;tab=digestviewer" target="_self" rel="noreferrer"&gt;https://community.extremenetworks.com/extrememanagement-230297/802-1x-rejected-then-being-approved-via-mac-auth-7824102&lt;/A&gt;&lt;/P&gt;  &lt;P&gt;Possibly it is just the end-system going through its steps of re-auth which will include a MAC auth and I’m required to add a rule that will deny it for some reason.&lt;/P&gt;  &lt;P&gt;Maybe when the default catch all rule is moved to deny this will help?&lt;/P&gt;  &lt;P&gt;Maybe it doesn’t matter?&lt;/P&gt;  &lt;P&gt;I imagine there would be a slight drop in service at that time as the policy roles shift?&lt;/P&gt;  &lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 04:50:50 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78533#M8799</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2020-06-26T04:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78534#M8800</link>
      <description>&lt;P&gt;Only one session is applied. The default behavior is that MACauth is not applied if 802.1x is applied.&lt;/P&gt;  &lt;P&gt;Are you sure there is a macauth authorization applied during the Dot1x reauth?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 22:53:36 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78534#M8800</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2020-06-29T22:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78535#M8801</link>
      <description>&lt;P&gt;Hi Zdenek,&lt;/P&gt;  &lt;P&gt;Thanks for replying.&lt;/P&gt;  &lt;P&gt;Answer is, no, I’m not sure. Just seeing the results as in the End-System events as shown above and wondering:&lt;/P&gt;  &lt;OL&gt;&lt;LI&gt;Is that normal?&lt;/LI&gt; 	&lt;LI&gt;Why exhibit that behaviour (if normal), as on surface its seems&amp;nbsp;to suggest a momentary MAC auth and ‘Default NAC Profile’ assignment before moving back to 802.1x?&lt;/LI&gt; 	&lt;LI&gt;If not normal, what do I do to fix it?&lt;/LI&gt; &lt;/OL&gt;&lt;P&gt;Many thanks,&lt;/P&gt;  &lt;P&gt;Martin&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 23:08:31 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78535#M8801</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2020-06-29T23:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78536#M8802</link>
      <description>&lt;P&gt;Hi Martin.&lt;/P&gt;  &lt;P&gt;in the ES table you will not see the change = you should not see the change in the switch either.&lt;/P&gt;  &lt;P&gt;in the ES history table you should see everything what happens = for auditing and debugging purpose.&lt;/P&gt;  &lt;P&gt;example what you can see:&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;the ES table is authenticated and “accept” for 802.1X&lt;/LI&gt; 	&lt;LI&gt;in the ES history you can see the authentication is rejected or even disconnected for the mac auth session&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 00:24:59 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78536#M8802</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2020-06-30T00:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78537#M8803</link>
      <description>&lt;P&gt;Hi Z,&lt;/P&gt;  &lt;P&gt;Ok, let me validate the MAC session is actually rejected or disconnected&amp;nbsp;as that screenshot isn’t showing the whole picture.&lt;/P&gt;  &lt;P&gt;Will try and post back shortly.&lt;/P&gt;  &lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 00:30:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78537#M8803</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2020-06-30T00:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78538#M8804</link>
      <description>&lt;P&gt;I’ve attached the full detail of the End-System events.&amp;nbsp;&lt;/P&gt;  &lt;P&gt;This same pattern is happening on every 802.1x client by the way, but it does on the surface seem to show it legitimately going through a&amp;nbsp;MAC auth, being accepted via the Default Catch All NAC rule.&lt;/P&gt;  &lt;P&gt;Need to back this up I guess, by seeing if this mirrors whats happening on the switch also?&lt;/P&gt;  &lt;P&gt;There is no reject being applied for MAC auth devices at this time, the tap hasn’t yet been turned off i.e. the Default Catch All rule is still set with the Default NAC Profile that is permit&amp;nbsp;- would that have anything to do with it? Must the device hit some kind of reject on MAC auth?&lt;/P&gt;  &lt;P&gt;Still, can’t explain why a 802.1x client will show a MAC authentication?&lt;/P&gt;  &lt;P&gt;All the PC’s have had sleep mode disabled via GPO, so that’s&amp;nbsp;not it?&lt;/P&gt;  &lt;P&gt;Worth me opening a case?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 01:11:59 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78538#M8804</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2020-06-30T01:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78539#M8805</link>
      <description>&lt;P&gt;So decided to watch the netlogin session on the switch.&lt;/P&gt;  &lt;P&gt;The cycle in the end-system events&amp;nbsp;seems to be:&lt;/P&gt;  &lt;OL&gt;&lt;LI&gt;Shows authenticated with 802.1x for 1hr&lt;/LI&gt; 	&lt;LI&gt;Switches to showing authenticated with MAC for 19 mins&lt;/LI&gt; 	&lt;LI&gt;Cycle starts again&lt;/LI&gt; &lt;/OL&gt;&lt;P&gt;I watched the whole process and the below session remained the same throughout:&lt;/P&gt;  &lt;PRE&gt;&lt;CODE&gt;Slot-1 BHR-East-2ndFlr.2 # show netlogin session mac-address ec:b1:d7:6c:94:f8&lt;BR /&gt;Multiple authentication session entries&lt;BR /&gt;---------------------------------------&lt;BR /&gt;&lt;BR /&gt;Port            : 1:5         Station address   : ec:b1:d7:6c:94:f8 &lt;BR /&gt;Auth status     : success     Last attempt      : Sat Jun 27 04:16:19 2020      &lt;BR /&gt;Agent type      : dot1x       Session applied   : true&lt;BR /&gt;Server type     : radius      VLAN-Tunnel-Attr  : None&lt;BR /&gt;Policy index    : 11          Policy name       : Allow All Data (active)&lt;BR /&gt;Session timeout : 0           Session duration  : 2 days, 16:41:25              &lt;BR /&gt;Idle timeout    : 300         Idle time         : 0:00:00                       &lt;BR /&gt;Auth-Override   : disabled    Termination time  : Not Terminated&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Port            : 1:5         Station address   : ec:b1:d7:6c:94:f8 &lt;BR /&gt;Auth status     : success     Last attempt      : Mon Mar  9 10:54:53 2020      &lt;BR /&gt;Agent type      : mac         Session applied   : false&lt;BR /&gt;Server type     : radius      VLAN-Tunnel-Attr  : None&lt;BR /&gt;Policy index    : 16          Policy name       : Enterprise User (active)&lt;BR /&gt;Session timeout : 0           Session duration  : 112 days, 10:02:51            &lt;BR /&gt;Idle timeout    : 300         Idle time         : 0:00:00                       &lt;BR /&gt;Auth-Override   : disabled    Termination time  : Not Terminated&lt;BR /&gt;&lt;/CODE&gt;&lt;/PRE&gt;  &lt;P&gt;The station address is showing auth status success for both MAC and 802.1x, with 802.1x taking precedence.&lt;/P&gt;  &lt;P&gt;The policy name Enterprise User is whats being assigned by the currently permit Default Catch All rule. Soon this will be disabled, so should show up denied.&lt;/P&gt;  &lt;P&gt;The end-system events seemed to show up as the following sequence:&lt;/P&gt;  &lt;UL&gt;&lt;LI&gt;On the hour the first two lines of MAC(PAP) showed up&lt;/LI&gt; 	&lt;LI&gt;19 minutes later the 3rd MAC(PAP) lined showed that includes the IP address&lt;/LI&gt; 	&lt;LI&gt;Straight after the 3 lines of 802.1x(EAP-TLS) showed up&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;So it seems to conclude that the actual session for the device on the switch never changes, so begs the question why XMC is showing otherwise?&lt;/P&gt;  &lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 04:28:50 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78539#M8805</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2020-06-30T04:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78540#M8806</link>
      <description>&lt;P&gt;Hi Martin.&lt;/P&gt;  &lt;P&gt;you can see the 802.1X takes the precedence =&amp;nbsp;&lt;STRONG&gt;Session applied : true&lt;/STRONG&gt;&lt;/P&gt;  &lt;P&gt;OneView →&amp;nbsp;Control →&amp;nbsp;End-Systems: In the top table there should be the&amp;nbsp;“actual state” = you see dot1x authentication, IP, ….&lt;/P&gt;  &lt;P&gt;If you select the end-system then in the bottom you see end-system events and Health Results = there you see also not active sessions and “audit” of what happens = IP resolution, hostname detection, re-authentications…&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 05:09:50 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78540#M8806</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2020-06-30T05:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78541#M8807</link>
      <description>&lt;P&gt;Thanks Z,&lt;/P&gt;  &lt;P&gt;So I think I have translated this to being the fact that netlogin is showing both a 802.1x and MAC auth for the same device, with obviously 802.1x is taking precedence.&lt;/P&gt;  &lt;P&gt;The re-auth for both auth types is set to 3600 seconds.&lt;/P&gt;  &lt;P&gt;The end-system events is probably showing the audit logs&amp;nbsp;of these going through re-authentication&amp;nbsp;for each authentication type, 1 hour apart, there being a 19 minute difference between the two.&lt;/P&gt;  &lt;P&gt;Whats probably happening is&amp;nbsp;the time between a MAC re-auth and then a 802.1x re-auth (19 minutes) is showing up in the aduit as a MAC Auth, but the reality is the switch always remains authenticated using 802.1x.&lt;/P&gt;  &lt;P&gt;Do you think that sums it up?&lt;/P&gt;  &lt;P&gt;Cheers&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 18:54:02 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78541#M8807</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2020-06-30T18:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78542#M8808</link>
      <description>&lt;P&gt;Hi Martin.&lt;/P&gt;  &lt;P&gt;yes, I agree with your statements/summarization.&lt;/P&gt;  &lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 19:20:49 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78542#M8808</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2020-06-30T19:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x clients transition to MAC auth and back again, every hour?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78543#M8809</link>
      <description>&lt;P&gt;Great, Thanks Z.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 19:23:07 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/802-1x-clients-transition-to-mac-auth-and-back-again-every-hour/m-p/78543#M8809</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2020-06-30T19:23:07Z</dc:date>
    </item>
  </channel>
</rss>

