<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Delete and Add RADIUS-Cisco attributes in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-and-add-radius-cisco-attributes/m-p/89256#M9506</link>
    <description>&lt;P&gt;Hi Ryan,&lt;/P&gt; &lt;P&gt;Thanks for posting back so quickly.&lt;/P&gt; &lt;P&gt;Also for the information, that’s great they are there&amp;nbsp;as makes it a little easier. That article looks familiar now, thanks.&lt;/P&gt; &lt;P&gt;As for the attributes I believe they need to be deleted, that’s how they are configured in the current system so would need to replicate,&lt;/P&gt; &lt;P&gt;It is using proxy RADIUS, so my assumption is either they are being omitted because the information is wished not to be shared, or the other end doesn’t like them…&amp;nbsp;the former being my guess?&lt;/P&gt; &lt;P&gt;The configuration uses a common SSID for multiple different forms of authentication processing, local and proxy, so are probably being used in some form for something else.&lt;/P&gt; &lt;P&gt;So deleting sounds like a possibility but perhaps not a simple one?&lt;/P&gt; &lt;P&gt;Cheers,&lt;/P&gt; &lt;P&gt;Martin&lt;/P&gt;</description>
    <pubDate>Thu, 28 Nov 2019 05:49:07 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2019-11-28T05:49:07Z</dc:date>
    <item>
      <title>Delete and Add RADIUS-Cisco attributes</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-and-add-radius-cisco-attributes/m-p/89254#M9504</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt; &lt;P&gt;I’ve been tasked with replacing another vendors NAC solution with an Extreme one, like for like.&lt;/P&gt; &lt;P&gt;One of the configuration elements is to inject, deleting&amp;nbsp;and adding the following outbound attributes:&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;RADIUS Dictionary | Attribute | Type | Operation | New Value&lt;BR /&gt; RADIUS-Cisco Airespace | Airespace-802.1p-Tag | Unsigned Interget 32 | DELETE&lt;BR /&gt; RADIUS-Cisco Airespace | Airespace-Interfance-Name | String | DELETE&lt;BR /&gt; RADIUS-Cisco Airespace | Airespance-Wlan-Id | Unsigned Interget 32 | DELETE&lt;BR /&gt; RADIUS-Cisco | cisco-av-pair | String | DELETE&lt;BR /&gt; RADIUS-Cisco Airespace | Airespace-Interace-Name | String | ADD | SomeWord&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;The configuration section to do this is shown below:&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="eaab7b77a21f402197d5e120678ccff0_ae66158e-d337-409a-b300-b75a3fe03d92.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3825iAFF98555D4880008/image-size/large?v=v2&amp;amp;px=999" role="button" title="eaab7b77a21f402197d5e120678ccff0_ae66158e-d337-409a-b300-b75a3fe03d92.png" alt="eaab7b77a21f402197d5e120678ccff0_ae66158e-d337-409a-b300-b75a3fe03d92.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="eaab7b77a21f402197d5e120678ccff0_5b5e3a3e-0b4e-4ef5-b5a5-78c55743333f.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4405i617821F33A7038B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="eaab7b77a21f402197d5e120678ccff0_5b5e3a3e-0b4e-4ef5-b5a5-78c55743333f.png" alt="eaab7b77a21f402197d5e120678ccff0_5b5e3a3e-0b4e-4ef5-b5a5-78c55743333f.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;So the two problems I have is:&lt;/P&gt; &lt;UL&gt;&lt;LI&gt;I don’t see a canned attribute for Cisco Airespace?&lt;/LI&gt; &lt;LI&gt;Can see how to substitute, but how do you delete?&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Sure in the past I’ve created my own attributes, but it has been a while. Still leaves the question about deleting attributes?&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Appreciate any advise in advance.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2019 00:45:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-and-add-radius-cisco-attributes/m-p/89254#M9504</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-11-28T00:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Delete and Add RADIUS-Cisco attributes</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-and-add-radius-cisco-attributes/m-p/89255#M9505</link>
      <description>&lt;P&gt;Hey Martin,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Check this article out:&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-NAC-for-custom-radius-attributes" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-NAC-for-custom-radius-attributes&lt;/A&gt;&lt;/P&gt; &lt;P&gt;It looks like we have those defined specifically for the “Airespace” vendor.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;root@NAC2.nacabucci.com:/opt/nac/radius/share/freeradius$ cat dictionary.airespace&lt;BR /&gt; # -*- text -*-&lt;BR /&gt; # Copyright (C) 2015 The FreeRADIUS Server project and contributors&lt;BR /&gt; #&lt;BR /&gt; # &amp;nbsp; &amp;nbsp; &amp;nbsp; As found on the net.&lt;BR /&gt; #&lt;BR /&gt; # &amp;nbsp; &amp;nbsp; &amp;nbsp; $Id: 5d952f9bb26324e61f139aef9ae9e552ed36dcb9 $&lt;BR /&gt; #&lt;BR /&gt; VENDOR &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Airespace &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 14179&lt;/P&gt; &lt;P&gt;BEGIN-VENDOR &amp;nbsp; &amp;nbsp;Airespace&lt;BR /&gt; ATTRIBUTE &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Wlan-Id &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 &amp;nbsp; &amp;nbsp; &amp;nbsp; integer&lt;BR /&gt; ATTRIBUTE &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-QOS-Level &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2 &amp;nbsp; &amp;nbsp; &amp;nbsp; integer&lt;BR /&gt; ATTRIBUTE &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-DSCP &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3 &amp;nbsp; &amp;nbsp; &amp;nbsp; integer&lt;BR /&gt; ATTRIBUTE &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-8021p-Tag &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4 &amp;nbsp; &amp;nbsp; &amp;nbsp; integer&lt;BR /&gt; ATTRIBUTE &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-Interface-Name &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;5 &amp;nbsp; &amp;nbsp; &amp;nbsp; string&lt;BR /&gt; ATTRIBUTE &amp;nbsp; &amp;nbsp; &amp;nbsp; Airespace-ACL-Name &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6 &amp;nbsp; &amp;nbsp; &amp;nbsp; string&lt;/P&gt; &lt;P&gt;VALUE &amp;nbsp; Airespace-QOS-Level &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Bronze &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;3&lt;BR /&gt; VALUE &amp;nbsp; Airespace-QOS-Level &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Silver &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&lt;BR /&gt; VALUE &amp;nbsp; Airespace-QOS-Level &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Gold &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1&lt;BR /&gt; VALUE &amp;nbsp; Airespace-QOS-Level &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Platinum &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2&lt;/P&gt; &lt;P&gt;END-VENDOR Airespace&lt;BR /&gt; &amp;nbsp;&lt;/P&gt; &lt;P&gt;I suspect they are the same.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Can you give an example for the delete portion? If NAC is acting as the terminating RADIUS server we won’t need to delete any attribute, we just won’t add it.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;If you’re in a proxy RADIUS environment the default action on a profile is to “Replace RADIUS attributes”. So if an AVP is defined in NAC it will replace any of the same attribute returned from the proxy RADIUS server.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;If you want to completed delete an AVP and not replace it with anything, that is a situation we’ll have to talk further about as NAC can only delete attributes that it will replace.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;As far as injecting an attribute NAC can inject RADIUS attributes to be proxied to other servers.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Thanks&lt;/P&gt; &lt;P&gt;-Ryan&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2019 04:22:40 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-and-add-radius-cisco-attributes/m-p/89255#M9505</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2019-11-28T04:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Delete and Add RADIUS-Cisco attributes</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-and-add-radius-cisco-attributes/m-p/89256#M9506</link>
      <description>&lt;P&gt;Hi Ryan,&lt;/P&gt; &lt;P&gt;Thanks for posting back so quickly.&lt;/P&gt; &lt;P&gt;Also for the information, that’s great they are there&amp;nbsp;as makes it a little easier. That article looks familiar now, thanks.&lt;/P&gt; &lt;P&gt;As for the attributes I believe they need to be deleted, that’s how they are configured in the current system so would need to replicate,&lt;/P&gt; &lt;P&gt;It is using proxy RADIUS, so my assumption is either they are being omitted because the information is wished not to be shared, or the other end doesn’t like them…&amp;nbsp;the former being my guess?&lt;/P&gt; &lt;P&gt;The configuration uses a common SSID for multiple different forms of authentication processing, local and proxy, so are probably being used in some form for something else.&lt;/P&gt; &lt;P&gt;So deleting sounds like a possibility but perhaps not a simple one?&lt;/P&gt; &lt;P&gt;Cheers,&lt;/P&gt; &lt;P&gt;Martin&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2019 05:49:07 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-and-add-radius-cisco-attributes/m-p/89256#M9506</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-11-28T05:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Delete and Add RADIUS-Cisco attributes</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-and-add-radius-cisco-attributes/m-p/89257#M9507</link>
      <description>&lt;P&gt;Hi Ryan,&lt;/P&gt;&lt;P&gt;Have an additional question on this topic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The deletion and insertion (or replace, depending how you look at it) of attributes is required when proxying the request, which is defined here:&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="76865ad4ae384feb96cb283ae0075918_371b03a9-db86-4b2e-a1f1-2aceefb6d788.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1907iF45F00E2DE2E5A93/image-size/large?v=v2&amp;amp;px=999" role="button" title="76865ad4ae384feb96cb283ae0075918_371b03a9-db86-4b2e-a1f1-2aceefb6d788.png" alt="76865ad4ae384feb96cb283ae0075918_371b03a9-db86-4b2e-a1f1-2aceefb6d788.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The section in part, mentioned above I believe is the other direct, when ExtremeControl intercepts and relays the authentication request back to the&amp;nbsp;originating RADIUS server, which is configured here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="76865ad4ae384feb96cb283ae0075918_339bcd91-4e8d-407a-b846-b4edde0ca763.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5501iE3335F17780C8BF8/image-size/large?v=v2&amp;amp;px=999" role="button" title="76865ad4ae384feb96cb283ae0075918_339bcd91-4e8d-407a-b846-b4edde0ca763.png" alt="76865ad4ae384feb96cb283ae0075918_339bcd91-4e8d-407a-b846-b4edde0ca763.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;So the question is the latter would replace the AVP attributes with whatever I have configured, but what I actually need is to either only send specified attributes to the proxied server or remove / delete what's being sent via the originating RADIUS server.&lt;/P&gt;&lt;P&gt;The configuration is:&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="76865ad4ae384feb96cb283ae0075918_8dcd638b-8339-4de6-b27d-3c3b6ac40c9c.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1420i64475859CF73FE18/image-size/large?v=v2&amp;amp;px=999" role="button" title="76865ad4ae384feb96cb283ae0075918_8dcd638b-8339-4de6-b27d-3c3b6ac40c9c.png" alt="76865ad4ae384feb96cb283ae0075918_8dcd638b-8339-4de6-b27d-3c3b6ac40c9c.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which implies it is only injecting (appending), rather then replacing?&lt;/P&gt;&lt;P&gt;Don’t suppose you know either way, primarily I need to do then following when forwarding to Proxied RADIUS server:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;•&amp;nbsp;&amp;nbsp; &amp;nbsp;Attrib: Airspace-802.1p-TAG&lt;BR /&gt;•&amp;nbsp;&amp;nbsp; &amp;nbsp;Attrib: Airspace-Interface-Name&lt;BR /&gt;•&amp;nbsp;&amp;nbsp; &amp;nbsp;Attrib: Airespace-WLAN-Id&lt;BR /&gt;•&amp;nbsp;&amp;nbsp; &amp;nbsp;Atrrib: cisco-av-pair&lt;/P&gt;&lt;P&gt;Add the following attributes&lt;/P&gt;&lt;P&gt;•&amp;nbsp;&amp;nbsp; &amp;nbsp;Attrib: Airspave-Interface-Name&lt;BR /&gt;•&amp;nbsp;&amp;nbsp; &amp;nbsp;Attrib New Value: viaem&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 18:23:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/delete-and-add-radius-cisco-attributes/m-p/89257#M9507</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2021-03-02T18:23:19Z</dc:date>
    </item>
  </channel>
</rss>

