<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AP Aware and radius proxy troubleshooting in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-and-radius-proxy-troubleshooting/m-p/87671#M9396</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I'm trying to use NAC as a proxy utilizing AP aware to forward the requests onto the NPS (I would prefer to go directly to LDAP but need to troubleshoot this first before trying a new setup).&lt;BR /&gt;&lt;BR /&gt;The current setup I have is: &lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;305C AP connected to X440-G2, the X440-G2 is being managed by XIQ-SE/NAC.&lt;/LI&gt;
&lt;LI&gt;Settings for the policy = "TCI Overwrite = Enabled", "Access Control = Permit traffic", "AP Aware = Enabled", "Vlan egress = mgmt untagged and Wireless VLANs tagged"&lt;/LI&gt;
&lt;LI&gt;Port policy is successfully applying to the port by MAC-auth for the AP
&lt;UL&gt;
&lt;LI&gt;|PID |Name |RS|PVID|NSI |CoS|MIR|STDOA|T U|prec |aSum |dSum |web|&lt;BR /&gt;|21 |Role-WiFi-APs |A |4095|none | | | YY|YY | | |InUse| |&lt;/LI&gt;
&lt;LI&gt;XOS-PoS.34 # show policy profile 21&lt;BR /&gt;Profile Index :21&lt;BR /&gt;Profile Name :Role-WiFi-APs&lt;BR /&gt;Row Status :active&lt;BR /&gt;Port VID Status :enabled&lt;BR /&gt;Port VID Override :4095&lt;BR /&gt;CoS Status :disabled&lt;BR /&gt;CoS :0&lt;BR /&gt;Web Redirect Index :0&lt;BR /&gt;Disable ingress port :disabled&lt;BR /&gt;Replace TCI Status :enabled&lt;BR /&gt;Auth Override Status :enabled&lt;BR /&gt;NSI :none&lt;BR /&gt;Tagged Egress :50,60-61,65-68,73&lt;BR /&gt;Untagged Egress :10&lt;BR /&gt;Forbidden Egress :&lt;BR /&gt;Rule Precedence :1-2,10,29,12,32,13,33,14-15,34,16,35,17,36,18,37,19,23,20-22,25,31&lt;BR /&gt;:MACSource (1), MACDest (2), IPv6Dest (10),&lt;BR /&gt;:Application (29), IPSource (12), IPSourceL4Range (32),&lt;BR /&gt;:IPDest (13), IPDestL4Range (33), IPFrag (14),&lt;BR /&gt;:UDPSrcPort (15), UDPSrcPortRange (34),&lt;BR /&gt;:UDPDestPort (16), UDPDestPortRange (35),&lt;BR /&gt;:TCPSrcPort (17), TCPSrcPortRange (36),&lt;BR /&gt;:TCPDestPort (18), TCPDestPortRange (37), ICMPType (19),&lt;BR /&gt;:ICMP6Type (23), TTL (20), IPTOS (21), IPProto (22),&lt;BR /&gt;:Ether (25), Port (31)&lt;BR /&gt;Admin Profile Usage :none&lt;BR /&gt;Oper Profile Usage :30&lt;BR /&gt;Dynamic Profile Usage :30&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;NAC AAA Setup
&lt;UL&gt;
&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="287b0b717cc54154b728082baaca598b.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3454iBA1513BF3FDCA9CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="287b0b717cc54154b728082baaca598b.png" alt="287b0b717cc54154b728082baaca598b.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;The NPS servers have had the engine IPs added as radius clients&lt;/LI&gt;
&lt;LI&gt;The NPS connection requests and Network policies remain the same as what I'm using to authenticate wireless clients directly (I'm currently not using the NAC as a proxy)&lt;/LI&gt;
&lt;LI&gt;The test AP is configured in Cloud_IQ to authenticate against the NAC engine
&lt;UL&gt;
&lt;LI&gt;They are using Filter-ID which remains the same on the test AP and NPS as the current production setup.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;The AP is added into NAC as a switch passing Cloud-IQ attribute (this part I did awhile back and could be a cause of my problems)
&lt;UL&gt;
&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="fa05c69c599644bdb4204ee581ca9dfd.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6049iC9C49D202880368F/image-size/large?v=v2&amp;amp;px=999" role="button" title="fa05c69c599644bdb4204ee581ca9dfd.png" alt="fa05c69c599644bdb4204ee581ca9dfd.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;I have rules to match wireless location and various user groups
&lt;UL&gt;
&lt;LI&gt;User groups are Radius user groups with Filter-ID matching both Cloud-IQ and NPS&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Access control/Netlogin is setup on the device and port level to auth 802.1x/MAC&lt;/LI&gt;
&lt;LI&gt;Currently my ZTP push is having an issue where radius settings are not being loaded
&lt;UL&gt;
&lt;LI&gt;I have manually added configuration for radius to the switch but this could be a cause.
&lt;UL&gt;
&lt;LI&gt;XOS-PoS.1 # sh configuration detail | include radius&lt;BR /&gt;configure radius netlogin 1 server 10.10.222.104 1812 client-ip 10.10.222.102 vr VR-Default&lt;BR /&gt;configure radius 1 shared-secret encrypted "#$O2iMVwWC4ZDH9JdrgqI3vzG5/6g=="&lt;BR /&gt;configure radius netlogin 2 server 10.10.222.105 1812 client-ip 10.10.222.102 vr VR-Default&lt;BR /&gt;configure radius 2 shared-secret encrypted "#$i8HhFzT4sKw4GY4/AVGdfgD68mpdg=="&lt;BR /&gt;configure radius-accounting netlogin 1 server 10.10.222.104 1813 client-ip 10.10.222.102 vr VR-Default&lt;BR /&gt;configure radius-accounting 1 shared-secret encrypted "#$DePuVDnJYgdfgpm0TuV7ksQy/5A=="&lt;BR /&gt;configure radius-accounting 1 timeout 10&lt;BR /&gt;configure radius-accounting netlogin 2 server 10.10.222.105 1813 client-ip 10.10.222.102 vr VR-Default&lt;BR /&gt;configure radius-accounting 2 shared-secret encrypted "#$cE4VPPI94EdfgEddX7/r0VSMawlg=="&lt;BR /&gt;enable radius&lt;BR /&gt;enable radius mgmt-access&lt;BR /&gt;enable radius netlogin&lt;BR /&gt;configure radius timeout 3&lt;BR /&gt;configure radius retries 3&lt;BR /&gt;disable radius-accounting&lt;BR /&gt;disable radius-accounting netlogin&lt;BR /&gt;configure radius-accounting mgmt-access timeout 3&lt;BR /&gt;configure radius-accounting netlogin timeout 3&lt;BR /&gt;disable radius dynamic-authorization&lt;BR /&gt;configure radius tls ocsp on&lt;BR /&gt;configure radius tls tcp-user-timeout default&lt;BR /&gt;configure radius authorization tokens 2&lt;BR /&gt;configure netlogin mac authentication database-order radius local&lt;BR /&gt;configure netlogin web-based authentication database-order radius local&lt;BR /&gt;configure netlogin dot1x radius-accounting on&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;BR /&gt;Notes&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;I've had this working a couple of time while testing various configurations but both times I've tried something else and when reverting I've been unable to have it working again.&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;It was last working a couple of days ago before I tried setting up LDAP direct instead. During that configuration it seemed to be stuck being unable to authenticate me, when I reverted the settings the same LDAP error persisted until I factory reset the switch and started again.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;With this configuration sh FDB didn't have a MAC associated this morning, it has stayed on there after doing various changes today (I was still able to ping the AP)&lt;/LI&gt;
&lt;LI&gt;I'm able to use the AP directly to NPS when changing the Cloud-IQ Radius servers and removing AP Aware&lt;/LI&gt;
&lt;LI&gt;Nothing is seen in the switch logs on this setup when devices try to authenticate on wireless (I'm assuming this is correct since the AP would be doing the auth and not the switch)&lt;/LI&gt;
&lt;LI&gt;The PCAP from the AP doesn't seem to have any responses.&lt;/LI&gt;
&lt;LI&gt;The PCAP from the engine shows the auth packets coming in, I would expect to see packets going to the NPS servers but nothing is there.
&lt;UL&gt;
&lt;LI&gt;This makes me think the authentication is no longer forwarding.&lt;/LI&gt;
&lt;LI&gt;I'm unsure where to look to troubleshoot this (or if that's expected behavior for some reason)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;The NPS servers have no auth request events from me.&lt;/LI&gt;
&lt;/UL&gt;
&lt;BR /&gt;I'm happy to learn more and give details on anything but I'm currently going around in circles and assume I'm not aware of or overlooking something.&lt;BR /&gt;&lt;BR /&gt;Thank you.</description>
    <pubDate>Thu, 03 Mar 2022 05:17:36 GMT</pubDate>
    <dc:creator>Adam13</dc:creator>
    <dc:date>2022-03-03T05:17:36Z</dc:date>
    <item>
      <title>AP Aware and radius proxy troubleshooting</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-and-radius-proxy-troubleshooting/m-p/87671#M9396</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I'm trying to use NAC as a proxy utilizing AP aware to forward the requests onto the NPS (I would prefer to go directly to LDAP but need to troubleshoot this first before trying a new setup).&lt;BR /&gt;&lt;BR /&gt;The current setup I have is: &lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;305C AP connected to X440-G2, the X440-G2 is being managed by XIQ-SE/NAC.&lt;/LI&gt;
&lt;LI&gt;Settings for the policy = "TCI Overwrite = Enabled", "Access Control = Permit traffic", "AP Aware = Enabled", "Vlan egress = mgmt untagged and Wireless VLANs tagged"&lt;/LI&gt;
&lt;LI&gt;Port policy is successfully applying to the port by MAC-auth for the AP
&lt;UL&gt;
&lt;LI&gt;|PID |Name |RS|PVID|NSI |CoS|MIR|STDOA|T U|prec |aSum |dSum |web|&lt;BR /&gt;|21 |Role-WiFi-APs |A |4095|none | | | YY|YY | | |InUse| |&lt;/LI&gt;
&lt;LI&gt;XOS-PoS.34 # show policy profile 21&lt;BR /&gt;Profile Index :21&lt;BR /&gt;Profile Name :Role-WiFi-APs&lt;BR /&gt;Row Status :active&lt;BR /&gt;Port VID Status :enabled&lt;BR /&gt;Port VID Override :4095&lt;BR /&gt;CoS Status :disabled&lt;BR /&gt;CoS :0&lt;BR /&gt;Web Redirect Index :0&lt;BR /&gt;Disable ingress port :disabled&lt;BR /&gt;Replace TCI Status :enabled&lt;BR /&gt;Auth Override Status :enabled&lt;BR /&gt;NSI :none&lt;BR /&gt;Tagged Egress :50,60-61,65-68,73&lt;BR /&gt;Untagged Egress :10&lt;BR /&gt;Forbidden Egress :&lt;BR /&gt;Rule Precedence :1-2,10,29,12,32,13,33,14-15,34,16,35,17,36,18,37,19,23,20-22,25,31&lt;BR /&gt;:MACSource (1), MACDest (2), IPv6Dest (10),&lt;BR /&gt;:Application (29), IPSource (12), IPSourceL4Range (32),&lt;BR /&gt;:IPDest (13), IPDestL4Range (33), IPFrag (14),&lt;BR /&gt;:UDPSrcPort (15), UDPSrcPortRange (34),&lt;BR /&gt;:UDPDestPort (16), UDPDestPortRange (35),&lt;BR /&gt;:TCPSrcPort (17), TCPSrcPortRange (36),&lt;BR /&gt;:TCPDestPort (18), TCPDestPortRange (37), ICMPType (19),&lt;BR /&gt;:ICMP6Type (23), TTL (20), IPTOS (21), IPProto (22),&lt;BR /&gt;:Ether (25), Port (31)&lt;BR /&gt;Admin Profile Usage :none&lt;BR /&gt;Oper Profile Usage :30&lt;BR /&gt;Dynamic Profile Usage :30&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;NAC AAA Setup
&lt;UL&gt;
&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="287b0b717cc54154b728082baaca598b.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3454iBA1513BF3FDCA9CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="287b0b717cc54154b728082baaca598b.png" alt="287b0b717cc54154b728082baaca598b.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;The NPS servers have had the engine IPs added as radius clients&lt;/LI&gt;
&lt;LI&gt;The NPS connection requests and Network policies remain the same as what I'm using to authenticate wireless clients directly (I'm currently not using the NAC as a proxy)&lt;/LI&gt;
&lt;LI&gt;The test AP is configured in Cloud_IQ to authenticate against the NAC engine
&lt;UL&gt;
&lt;LI&gt;They are using Filter-ID which remains the same on the test AP and NPS as the current production setup.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;The AP is added into NAC as a switch passing Cloud-IQ attribute (this part I did awhile back and could be a cause of my problems)
&lt;UL&gt;
&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="fa05c69c599644bdb4204ee581ca9dfd.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6049iC9C49D202880368F/image-size/large?v=v2&amp;amp;px=999" role="button" title="fa05c69c599644bdb4204ee581ca9dfd.png" alt="fa05c69c599644bdb4204ee581ca9dfd.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;I have rules to match wireless location and various user groups
&lt;UL&gt;
&lt;LI&gt;User groups are Radius user groups with Filter-ID matching both Cloud-IQ and NPS&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Access control/Netlogin is setup on the device and port level to auth 802.1x/MAC&lt;/LI&gt;
&lt;LI&gt;Currently my ZTP push is having an issue where radius settings are not being loaded
&lt;UL&gt;
&lt;LI&gt;I have manually added configuration for radius to the switch but this could be a cause.
&lt;UL&gt;
&lt;LI&gt;XOS-PoS.1 # sh configuration detail | include radius&lt;BR /&gt;configure radius netlogin 1 server 10.10.222.104 1812 client-ip 10.10.222.102 vr VR-Default&lt;BR /&gt;configure radius 1 shared-secret encrypted "#$O2iMVwWC4ZDH9JdrgqI3vzG5/6g=="&lt;BR /&gt;configure radius netlogin 2 server 10.10.222.105 1812 client-ip 10.10.222.102 vr VR-Default&lt;BR /&gt;configure radius 2 shared-secret encrypted "#$i8HhFzT4sKw4GY4/AVGdfgD68mpdg=="&lt;BR /&gt;configure radius-accounting netlogin 1 server 10.10.222.104 1813 client-ip 10.10.222.102 vr VR-Default&lt;BR /&gt;configure radius-accounting 1 shared-secret encrypted "#$DePuVDnJYgdfgpm0TuV7ksQy/5A=="&lt;BR /&gt;configure radius-accounting 1 timeout 10&lt;BR /&gt;configure radius-accounting netlogin 2 server 10.10.222.105 1813 client-ip 10.10.222.102 vr VR-Default&lt;BR /&gt;configure radius-accounting 2 shared-secret encrypted "#$cE4VPPI94EdfgEddX7/r0VSMawlg=="&lt;BR /&gt;enable radius&lt;BR /&gt;enable radius mgmt-access&lt;BR /&gt;enable radius netlogin&lt;BR /&gt;configure radius timeout 3&lt;BR /&gt;configure radius retries 3&lt;BR /&gt;disable radius-accounting&lt;BR /&gt;disable radius-accounting netlogin&lt;BR /&gt;configure radius-accounting mgmt-access timeout 3&lt;BR /&gt;configure radius-accounting netlogin timeout 3&lt;BR /&gt;disable radius dynamic-authorization&lt;BR /&gt;configure radius tls ocsp on&lt;BR /&gt;configure radius tls tcp-user-timeout default&lt;BR /&gt;configure radius authorization tokens 2&lt;BR /&gt;configure netlogin mac authentication database-order radius local&lt;BR /&gt;configure netlogin web-based authentication database-order radius local&lt;BR /&gt;configure netlogin dot1x radius-accounting on&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;BR /&gt;Notes&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;I've had this working a couple of time while testing various configurations but both times I've tried something else and when reverting I've been unable to have it working again.&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;It was last working a couple of days ago before I tried setting up LDAP direct instead. During that configuration it seemed to be stuck being unable to authenticate me, when I reverted the settings the same LDAP error persisted until I factory reset the switch and started again.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;With this configuration sh FDB didn't have a MAC associated this morning, it has stayed on there after doing various changes today (I was still able to ping the AP)&lt;/LI&gt;
&lt;LI&gt;I'm able to use the AP directly to NPS when changing the Cloud-IQ Radius servers and removing AP Aware&lt;/LI&gt;
&lt;LI&gt;Nothing is seen in the switch logs on this setup when devices try to authenticate on wireless (I'm assuming this is correct since the AP would be doing the auth and not the switch)&lt;/LI&gt;
&lt;LI&gt;The PCAP from the AP doesn't seem to have any responses.&lt;/LI&gt;
&lt;LI&gt;The PCAP from the engine shows the auth packets coming in, I would expect to see packets going to the NPS servers but nothing is there.
&lt;UL&gt;
&lt;LI&gt;This makes me think the authentication is no longer forwarding.&lt;/LI&gt;
&lt;LI&gt;I'm unsure where to look to troubleshoot this (or if that's expected behavior for some reason)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;The NPS servers have no auth request events from me.&lt;/LI&gt;
&lt;/UL&gt;
&lt;BR /&gt;I'm happy to learn more and give details on anything but I'm currently going around in circles and assume I'm not aware of or overlooking something.&lt;BR /&gt;&lt;BR /&gt;Thank you.</description>
      <pubDate>Thu, 03 Mar 2022 05:17:36 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/ap-aware-and-radius-proxy-troubleshooting/m-p/87671#M9396</guid>
      <dc:creator>Adam13</dc:creator>
      <dc:date>2022-03-03T05:17:36Z</dc:date>
    </item>
  </channel>
</rss>

