<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC: 2 domains. What is best practice to be able to add a 2nd ldap connection to the other domain controller. (in another network) in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-2-domains-what-is-best-practice-to-be-able-to-add-a-2nd-ldap/m-p/91948#M9616</link>
    <description>&lt;P&gt;Thanks for your feedback Stefan.&lt;BR /&gt;I am planning 802.1x authentication, why should I need PKI’s?&lt;BR /&gt;Are you able to send me a screenshot where exactly to define the username or hostname please?&lt;BR /&gt;Cannot find it...&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;NAC does&amp;nbsp;not need to have another interface in that other vlan, where the other Domain controller is in?&amp;nbsp; I have to set this up&amp;nbsp;by routing I assume then?&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2021 21:05:34 GMT</pubDate>
    <dc:creator>Sacha_Brys</dc:creator>
    <dc:date>2021-07-14T21:05:34Z</dc:date>
    <item>
      <title>NAC: 2 domains. What is best practice to be able to add a 2nd ldap connection to the other domain controller. (in another network)</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-2-domains-what-is-best-practice-to-be-able-to-add-a-2nd-ldap/m-p/91946#M9614</link>
      <description>&lt;P&gt;I have a customer with two different domain names.&lt;/P&gt;&lt;P&gt;So they have a few domain controllers, each belonging to his domain.&lt;/P&gt;&lt;P&gt;I am setting up Extreme cloud IQ site engine with NAC&lt;/P&gt;&lt;P&gt;NAC: 2 domains. What is best practice to be able to add a 2nd ldap connection to the other domain controller. (in another network).&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;greetz&lt;/P&gt;&lt;P&gt;Sacha&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 18:43:41 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-2-domains-what-is-best-practice-to-be-able-to-add-a-2nd-ldap/m-p/91946#M9614</guid>
      <dc:creator>Sacha_Brys</dc:creator>
      <dc:date>2021-07-14T18:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: NAC: 2 domains. What is best practice to be able to add a 2nd ldap connection to the other domain controller. (in another network)</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-2-domains-what-is-best-practice-to-be-able-to-add-a-2nd-ldap/m-p/91947#M9615</link>
      <description>&lt;P&gt;In the AAA config you can define which LDAP-config should be used based on the username or hostname.&lt;BR /&gt;e.g.:&lt;BR /&gt;Domain1\* → use LDAP config “Domain1”&lt;BR /&gt;Domain2\* → use LDAP config “Domain2”&lt;/P&gt;&lt;P&gt;Do you also plan to do 802.1x authentication and have 2 PKIs in use?&lt;/P&gt;&lt;P&gt;Best regards&lt;BR /&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 19:04:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-2-domains-what-is-best-practice-to-be-able-to-add-a-2nd-ldap/m-p/91947#M9615</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2021-07-14T19:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: NAC: 2 domains. What is best practice to be able to add a 2nd ldap connection to the other domain controller. (in another network)</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-2-domains-what-is-best-practice-to-be-able-to-add-a-2nd-ldap/m-p/91948#M9616</link>
      <description>&lt;P&gt;Thanks for your feedback Stefan.&lt;BR /&gt;I am planning 802.1x authentication, why should I need PKI’s?&lt;BR /&gt;Are you able to send me a screenshot where exactly to define the username or hostname please?&lt;BR /&gt;Cannot find it...&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;NAC does&amp;nbsp;not need to have another interface in that other vlan, where the other Domain controller is in?&amp;nbsp; I have to set this up&amp;nbsp;by routing I assume then?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 21:05:34 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-2-domains-what-is-best-practice-to-be-able-to-add-a-2nd-ldap/m-p/91948#M9616</guid>
      <dc:creator>Sacha_Brys</dc:creator>
      <dc:date>2021-07-14T21:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAC: 2 domains. What is best practice to be able to add a 2nd ldap connection to the other domain controller. (in another network)</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-2-domains-what-is-best-practice-to-be-able-to-add-a-2nd-ldap/m-p/91949#M9617</link>
      <description>&lt;P&gt;Hello Sacha,&lt;/P&gt;&lt;P&gt;if you are using 802.1x with EAP-TLS, then the NAC can validate the certificates of the clients. Hence the question whether the certificates are created by one or two PKIs. With PEAP, however, client certificates are not necessary.&lt;/P&gt;&lt;P&gt;You do not need a second interface the LDAP and Radius communication is layer 3.&lt;/P&gt;&lt;P&gt;Below a picture of the AAA config. The users mentioned by Stefan are in column 2. In the picture you can see a * which matches every username.&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="151d69b8ab9c408abd8d4c32973136a3_609d7756-0e66-400e-9c01-ba3827111634.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4430i2A109AA1CB24CDC6/image-size/large?v=v2&amp;amp;px=999" role="button" title="151d69b8ab9c408abd8d4c32973136a3_609d7756-0e66-400e-9c01-ba3827111634.png" alt="151d69b8ab9c408abd8d4c32973136a3_609d7756-0e66-400e-9c01-ba3827111634.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 02:43:31 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/nac-2-domains-what-is-best-practice-to-be-able-to-add-a-2nd-ldap/m-p/91949#M9617</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-07-15T02:43:31Z</dc:date>
    </item>
  </channel>
</rss>

