<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Netsight - Monitoring only in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-monitoring-only/m-p/92203#M9637</link>
    <description>Hi Marcus,&lt;BR /&gt;
&lt;BR /&gt;
&lt;OL&gt; 
&lt;LI&gt;You can configure the switch ports to use "optional authentication." The switch ports allow devices onto the network irrespective of authentication success or failure, but NAC has all the end-system information it learns from authentication. 
&lt;/LI&gt;&lt;LI&gt;You have described the "silent device" problem, see &lt;A href="https://extreme.connectedcommunity.org/communities/community-home/digestviewer/viewthread?MessageKey=d43cbadb-dfb1-45ff-aa1e-57dfc9f5b631&amp;amp;CommunityKey=70134b43-8d05-4bf7-8d9e-979e14e85bb4&amp;amp;tab=digestviewer#bmd43cbadb-dfb1-45ff-aa1e-57dfc9f5b631" target="_blank" rel="nofollow noreferrer noopener"&gt;https://community.extremenetworks.com/aaa-radius-230508/mac-authentication-dynamic-vlans-and-silent-devices-7612836&lt;/A&gt; for a lot of info. I like the idea of monitoring the end-systems so that the MAC address is refreshed often enough. 
&lt;/LI&gt;&lt;/OL&gt;
Thanks,&lt;BR /&gt;
Erik</description>
    <pubDate>Thu, 12 Sep 2019 18:51:46 GMT</pubDate>
    <dc:creator>Erik_Auerswald</dc:creator>
    <dc:date>2019-09-12T18:51:46Z</dc:date>
    <item>
      <title>Netsight - Monitoring only</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-monitoring-only/m-p/92202#M9636</link>
      <description>Hi @all,&lt;BR /&gt;
&lt;BR /&gt;
Since two months we are using Netsight NAC. Before was our NAC managed by macmon (www.macmon.eu).&lt;BR /&gt;
&lt;BR /&gt;
macmon procedere:&lt;BR /&gt;
Macmon scan every minute the switch for a change. In this case macmon changed the vlan into the right one (authorized device) or into a quarantaene vlan (unauthorized device).&lt;BR /&gt;
There was also possible to add switches into macmon for documentation. So macmon doesn't change anything on the switch. It was only in a "scanning mode". In this mode we added also Switches in the datacenter. So we have all mac-addresses in our company in one system!&lt;BR /&gt;
&lt;BR /&gt;
In netsight we have our NAC as mac-based configured. And now we searched also for a solution to add some switches or ports in the scanning mode.&lt;BR /&gt;
&lt;BR /&gt;
First for our datacenter switches, and the other problem is. That we have some audio devices in a vlan which is not routed. This devices are old and have the problem to publish his mac-address only by reboot the device. After a certain time it doesn't publish the mac address and the switch lost the address on the port and so it switch back to the naclogin-vlan.&lt;BR /&gt;
&lt;BR /&gt;
THANKS for your ideas!&lt;BR /&gt;
Marcus</description>
      <pubDate>Thu, 12 Sep 2019 17:16:13 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-monitoring-only/m-p/92202#M9636</guid>
      <dc:creator>m18grunling</dc:creator>
      <dc:date>2019-09-12T17:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Netsight - Monitoring only</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-monitoring-only/m-p/92203#M9637</link>
      <description>Hi Marcus,&lt;BR /&gt;
&lt;BR /&gt;
&lt;OL&gt; 
&lt;LI&gt;You can configure the switch ports to use "optional authentication." The switch ports allow devices onto the network irrespective of authentication success or failure, but NAC has all the end-system information it learns from authentication. 
&lt;/LI&gt;&lt;LI&gt;You have described the "silent device" problem, see &lt;A href="https://extreme.connectedcommunity.org/communities/community-home/digestviewer/viewthread?MessageKey=d43cbadb-dfb1-45ff-aa1e-57dfc9f5b631&amp;amp;CommunityKey=70134b43-8d05-4bf7-8d9e-979e14e85bb4&amp;amp;tab=digestviewer#bmd43cbadb-dfb1-45ff-aa1e-57dfc9f5b631" target="_blank" rel="nofollow noreferrer noopener"&gt;https://community.extremenetworks.com/aaa-radius-230508/mac-authentication-dynamic-vlans-and-silent-devices-7612836&lt;/A&gt; for a lot of info. I like the idea of monitoring the end-systems so that the MAC address is refreshed often enough. 
&lt;/LI&gt;&lt;/OL&gt;
Thanks,&lt;BR /&gt;
Erik</description>
      <pubDate>Thu, 12 Sep 2019 18:51:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-monitoring-only/m-p/92203#M9637</guid>
      <dc:creator>Erik_Auerswald</dc:creator>
      <dc:date>2019-09-12T18:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Netsight - Monitoring only</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-monitoring-only/m-p/92204#M9638</link>
      <description>Hi Erik,&lt;BR /&gt;
&lt;BR /&gt;
Thanks for your fast reply!!&lt;BR /&gt;
&lt;BR /&gt;
1.) Can you give me your recommended (netlogin) config without authentication to see the devices with all information in NAC, please?&lt;BR /&gt;
&lt;BR /&gt;
THANKS&lt;BR /&gt;
marcus</description>
      <pubDate>Thu, 12 Sep 2019 19:00:55 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-monitoring-only/m-p/92204#M9638</guid>
      <dc:creator>m18grunling</dc:creator>
      <dc:date>2019-09-12T19:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: Netsight - Monitoring only</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-monitoring-only/m-p/92205#M9639</link>
      <description>Hi Marcus,&lt;BR /&gt;
&lt;BR /&gt;
you configure authentication in NAC and the switch normally (without policy or VLAN assignment), but then you add the port configuration to not actually require authentication:&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;configure netlogin ports PORTS authentication mode optional&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
Note: &lt;U&gt;This is supported for OnePolicy only&lt;/U&gt; (i.e., with &lt;B&gt;enable policy&lt;/B&gt; as part of the configuration).&lt;BR /&gt;
&lt;BR /&gt;
I would expect that this can be achieved using the XMC ("NAC") web frontend as well.&lt;BR /&gt;
&lt;BR /&gt;
If authentication is successful and sends policy and / or VLAN information, those will be used. Thus you should configure NAC to &lt;I&gt;not send any policy or VLAN assignment&lt;/I&gt; to those switches where you only need the visibility features of NAC.&lt;BR /&gt;
&lt;BR /&gt;
Please test this before actually using it in production!&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Erik</description>
      <pubDate>Thu, 12 Sep 2019 19:23:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/netsight-monitoring-only/m-p/92205#M9639</guid>
      <dc:creator>Erik_Auerswald</dc:creator>
      <dc:date>2019-09-12T19:23:19Z</dc:date>
    </item>
  </channel>
</rss>

