<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AP aware - how is it supposed to work? in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87464#M9375</link>
    <description>&lt;P&gt;Hi all.&lt;/P&gt; &lt;P&gt;I’m wondering how “AP aware” feature is supposed to work. Is anybody using it and could share how it should be configured and intended to be used?&lt;/P&gt; &lt;P&gt;Thanks,&lt;/P&gt; &lt;P&gt;Flavio.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jan 2020 15:18:00 GMT</pubDate>
    <dc:creator>Flavio</dc:creator>
    <dc:date>2020-01-09T15:18:00Z</dc:date>
    <item>
      <title>AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87464#M9375</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt; &lt;P&gt;I’m wondering how “AP aware” feature is supposed to work. Is anybody using it and could share how it should be configured and intended to be used?&lt;/P&gt; &lt;P&gt;Thanks,&lt;/P&gt; &lt;P&gt;Flavio.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 15:18:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87464#M9375</guid>
      <dc:creator>Flavio</dc:creator>
      <dc:date>2020-01-09T15:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87465#M9376</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;here a KB article about the feature…&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/EMC-How-to-enable-the-AP-Aware-Feature-in-EMC-s-Policy-Manager" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/EMC-How-to-enable-the-AP-Aware-Feature-in-EMC-s-Policy-Manager&lt;/A&gt;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;-Ron&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 15:51:57 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87465#M9376</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2020-01-09T15:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87466#M9377</link>
      <description>&lt;P&gt;Hi Ronald.&lt;/P&gt; &lt;P&gt;That I already found - but that’s not explaining how to apply it and in what situation it is really useful. I’d like to have some examples…&lt;/P&gt; &lt;P&gt;Thanks,&lt;/P&gt; &lt;P&gt;Flavio.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 16:05:03 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87466#M9377</guid>
      <dc:creator>Flavio</dc:creator>
      <dc:date>2020-01-09T16:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87467#M9378</link>
      <description>&lt;P&gt;Hi Flavio,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;you use the feature if you do authentication (e.g. 802.1X) on the switch ports.&lt;/P&gt; &lt;P&gt;Because most of the time you would use a &lt;A href="mailto:bridge@AP" target="_blank" rel="nofollow noreferrer noopener"&gt;bridge@AP&lt;/A&gt;&amp;nbsp;topology for WLAN APs = clients break out directly at the AP port that would mean that the client needs to be authenticated on the WLAN AND on the switch port.&lt;/P&gt; &lt;P&gt;As a double authentication doesn’t make much sense you’d use AP aware to “disable” authentication on the switch port that has a AP connected to it.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Hope that makes sense.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;-Ron&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 17:11:56 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87467#M9378</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2020-01-09T17:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87468#M9379</link>
      <description>&lt;P&gt;Hi Ron, thanks for explaining.&lt;/P&gt; &lt;P&gt;I do dot1x in fact on all my switch ports, and until today I did exclude the ports where an AP is connected from dot1x authentication. I configured statically the untagged VLAN for the control/management traffic of the AP and added the tagged VLANs for the SSIDs (Bridge@AP topology used).&lt;/P&gt; &lt;P&gt;The WLAN clients actually authenticate via dot1x on the WLAN, but I also do have some PSK SSIDs. I know don’t really understand how I would apply the “AP aware” feature in my scenario: what should the role do, besides “AP aware” enabling? And if I’d like to be able to connect an AP wherever I want, I would authenticate all APs with MAC address and assign the correct untagged and tagged VLANs to that port with a role specific to APs? Am I on the correct path?&lt;/P&gt; &lt;P&gt;Thanks,&lt;/P&gt; &lt;P&gt;Flavio.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 17:40:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87468#M9379</guid>
      <dc:creator>Flavio</dc:creator>
      <dc:date>2020-01-09T17:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87469#M9380</link>
      <description>&lt;P&gt;Hi Flavio,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;if you use 802.1X on your switch port and you have an &lt;A href="mailto:Bridge@AP" target="_blank" rel="nofollow noreferrer noopener"&gt;Bridge@AP&lt;/A&gt; topology, then you can see all wireless clients MAC addresses on the switchport, too. Meaning: if you have your AP connected to port 1 on your switch you will see the MAC address of the AP as well as several MAC addresses of all WiFi clients connected to that AP.&lt;/P&gt; &lt;P&gt;The switch now “tries” to authenticate all wireless clients, too - even though they are already authenticated by the AP. Meaning: your clients would be authenticated twice - once on the AP and a second time on the switch. This (of course) is quite stupid and just introduces more issues.&lt;/P&gt; &lt;P&gt;Therefore you enable the “AP aware” feature in NAC. If “AP aware” is enabled only your AP gets authenticated via 802.1X on the switch port and not the wireless clients. AP aware (sort of) turns off 802.1X once your AP has been authenticated on the switch.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Kind regards&lt;/P&gt; &lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 22:36:02 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87469#M9380</guid>
      <dc:creator>CWurm</dc:creator>
      <dc:date>2020-01-09T22:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87470#M9381</link>
      <description>&lt;P&gt;Flavio, yes you are on the right track. You can authenticate your APs with mac auth, if you utilize NAC, then this is done with an end system group.&amp;nbsp; Setup the role the APs to use with AP-Aware, setup your vlans you want tagged on your tagged egress list on your role and when an AP is plugged in, it authenticates and the AP-Aware setting only allows one device to auth, which would be your ap.&amp;nbsp; If you didn’t use AP-Aware, clients in a bridged at AP topology would also try to authenticate and it would be a battle of authentication between wireless controller and wired switches, not a pleasant experience for the end user.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;AP-Aware also works with 3rd party APs, doesn’t have to be Extreme APs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 04:20:54 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87470#M9381</guid>
      <dc:creator>Brian_Anderson1</dc:creator>
      <dc:date>2020-01-10T04:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87471#M9382</link>
      <description>&lt;P&gt;When you configure the policy with the “AP Aware” setting and you look at the CLI configuration on the switch you’ll see an “Auth-Override” flag on the end of the policy configuration.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;A policy with “Auth-Override” flag will result in a termination of all existing policies on the switch port, and no additional clients will have a session established or be authenticated on that switch port. All traffic will essentially pass through that existing policy session that was created with the auth-override flag, so as already explained the policy with “AP-Aware” enabled must allow all necessary traffic (802.1q VLANs)&amp;nbsp;to clients behind the AP.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Double auth causes issues with residual&amp;nbsp;policy sessions (If two policy end points are configured to “Unregistered” for captive portal when NAC re-authenticates it can’t change both policies at once so one will stick around and cause a portal loop), re-authentication storms, and confusing end system events. You’ll see stuff like iphones on a wired port. As Brain indicates, generally not a pleasant experience.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;ERS/VSP has a similar technology called “MHSA” Multi-Host Single Authentication that is similar.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 05:56:53 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87471#M9382</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2020-01-10T05:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87472#M9383</link>
      <description>&lt;P&gt;Hi Brian - thanks for your reply. Are you the Brian Anderson who is involved in a FortiNAC setup in Switzerland?&lt;/P&gt; &lt;P&gt;F.&lt;/P&gt;  &amp;nbsp;</description>
      <pubDate>Fri, 10 Jan 2020 21:52:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87472#M9383</guid>
      <dc:creator>Flavio</dc:creator>
      <dc:date>2020-01-10T21:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87473#M9384</link>
      <description>&lt;P&gt;Unfortunately not.&amp;nbsp; Not that I wouldn’t mind working with FortiNAC , but unfortunately haven’t been to Switzerland .&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 22:28:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87473#M9384</guid>
      <dc:creator>Brian_Anderson1</dc:creator>
      <dc:date>2020-01-10T22:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87474#M9385</link>
      <description>&lt;P&gt;OK - just the same identical name &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt; &lt;P&gt;F.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 22:51:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87474#M9385</guid>
      <dc:creator>Flavio</dc:creator>
      <dc:date>2020-01-10T22:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87475#M9386</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt; &lt;P&gt;here is some information also:&amp;nbsp;&lt;A href="https://www.dropbox.com/s/88izhy825p0xy6w/UniversalPort%20With%20Intro.mp4?dl=0" target="_blank" rel="nofollow noreferrer noopener"&gt;https://www.dropbox.com/s/88izhy825p0xy6w/UniversalPort%20With%20Intro.mp4?dl=0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 17:21:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87475#M9386</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2020-02-19T17:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: AP aware - how is it supposed to work?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87476#M9387</link>
      <description>&lt;P&gt;Thanks - our Swiss Extreme SE shared this with me as well &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt; &lt;P&gt;F.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 18:20:29 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-how-is-it-supposed-to-work/m-p/87476#M9387</guid>
      <dc:creator>Flavio</dc:creator>
      <dc:date>2020-02-19T18:20:29Z</dc:date>
    </item>
  </channel>
</rss>

