<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: RADIUS management authentication on XMC / XIQ / Control 21.11.11.37 with ms-chap in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/radius-management-authentication-on-xmc-xiq-control-21-11-11-37/m-p/18794#M10</link>
    <description>Hi Ryan&lt;BR /&gt;&lt;BR /&gt;sorry for letting you wait on this topic, but for the moment: thanks a lot for your detailed help.&lt;BR /&gt;&lt;BR /&gt;I was not yet able to analyze / test it, but wanted to get sure you got the appreciation you deserve &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I will keep the post updated, as soon as I can find the time to test it.&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;BR /&gt;Dominic</description>
    <pubDate>Wed, 30 Mar 2022 11:25:00 GMT</pubDate>
    <dc:creator>DominicStalder</dc:creator>
    <dc:date>2022-03-30T11:25:00Z</dc:date>
    <item>
      <title>RADIUS management authentication on XMC / XIQ / Control 21.11.11.37 with ms-chap</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/radius-management-authentication-on-xmc-xiq-control-21-11-11-37/m-p/18792#M8</link>
      <description>&lt;DIV class="uconBody"&gt;&lt;DIV style="page: WordSection1"&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;Hi Ryan&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;Thanks a lot for your reply / this information.&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;&amp;gt; Which protocols have you tried at this point?&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;I tried CHAP and PEAP-msCHAPv2.&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;&amp;gt; If you have NTLM authentication set can you also confirm you have successfully joined the AD and that winbindd is running with correct trust secret?&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;I did check it now, and there is an error:&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:&amp;quot;Courier New&amp;quot;;color:windowtext"&gt;could not obtain winbind interface details: WBC_ERR_WINBIND_NOT_AVAILABLE&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:&amp;quot;Courier New&amp;quot;;color:windowtext"&gt;could not obtain winbind domain name!&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:&amp;quot;Courier New&amp;quot;;color:windowtext"&gt;checking the trust secret for domain (null) via RPC calls failed&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:&amp;quot;Courier New&amp;quot;;color:windowtext"&gt;failed to call wbcCheckTrustCredentials: WBC_ERR_WINBIND_NOT_AVAILABLE&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:&amp;quot;Courier New&amp;quot;;color:windowtext"&gt;Could not check secret&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:&amp;quot;Courier New&amp;quot;;color:windowtext"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;Will try to figure this out and fix it.&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;For the moment, thanks for this hint!&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;color:windowtext"&gt;Dominic&lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:&amp;quot;Courier New&amp;quot;;color:windowtext"&gt;&lt;/SPAN&gt;&lt;/P&gt; &lt;P style="margin: 0cm;font-size: 11.0pt;font-family: &amp;quot;Calibri&amp;quot;,sans-serif;color: #333333"&gt;&lt;SPAN lang="EN-US" style=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 10 Mar 2022 14:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/radius-management-authentication-on-xmc-xiq-control-21-11-11-37/m-p/18792#M8</guid>
      <dc:creator>DominicStalder</dc:creator>
      <dc:date>2022-03-10T14:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: RADIUS management authentication on XMC / XIQ / Control 21.11.11.37 with ms-chap</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/radius-management-authentication-on-xmc-xiq-control-21-11-11-37/m-p/18793#M9</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I set it up using XCC controller using MS-CHAPV2 authentication:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="31beee3fa08b48d8ad6414d976454b98.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2143i423657EA0F87871A/image-size/large?v=v2&amp;amp;px=999" role="button" title="31beee3fa08b48d8ad6414d976454b98.png" alt="31beee3fa08b48d8ad6414d976454b98.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Make sure your Control AAA configuration has a line to handle either "Management" auth type or "*":&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;
&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="422f51318ffe4f19af736bded03a183a.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2518i9A06E709D0C1220D/image-size/large?v=v2&amp;amp;px=999" role="button" title="422f51318ffe4f19af736bded03a183a.png" alt="422f51318ffe4f19af736bded03a183a.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Then make sure there is a rule that provides the correct authorization string for management access:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="b62a76f8847d44d69f85240d6e4d63ea.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6058i82A7615BCA57ACFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="b62a76f8847d44d69f85240d6e4d63ea.png" alt="b62a76f8847d44d69f85240d6e4d63ea.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="f9b1732153804b528862f482e2ac9a0c.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3203i97F2CB7947D744C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="f9b1732153804b528862f482e2ac9a0c.png" alt="f9b1732153804b528862f482e2ac9a0c.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;When you set the AAA line up for "LDAP Authentication" NAC should attempt to join the domain controller on enforce, it will also attempt to join on services restart:&lt;BR /&gt;&lt;BR /&gt;You can check the /var/log/tag.log to see if there was a domain join failure or success:&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="b8bd942cf4ea4a1a86b7e18a9616cad4.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1880iF27E4E2A82F8FBDF/image-size/large?v=v2&amp;amp;px=999" role="button" title="b8bd942cf4ea4a1a86b7e18a9616cad4.png" alt="b8bd942cf4ea4a1a86b7e18a9616cad4.png" /&gt;&lt;/span&gt;&lt;BR /&gt;If domain join fails, check permissions:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000090980&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;You can check the status of the management login if you go to Alarms/Events&amp;nbsp; --&amp;gt; Type Access Control/NAC&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="916e3c61a1974ec69ebc610ff1e5780c.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4585iC4841331159B8E1B/image-size/large?v=v2&amp;amp;px=999" role="button" title="916e3c61a1974ec69ebc610ff1e5780c.png" alt="916e3c61a1974ec69ebc610ff1e5780c.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Let me know if any of this helps.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2022 21:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/radius-management-authentication-on-xmc-xiq-control-21-11-11-37/m-p/18793#M9</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2022-03-12T21:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: RADIUS management authentication on XMC / XIQ / Control 21.11.11.37 with ms-chap</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/radius-management-authentication-on-xmc-xiq-control-21-11-11-37/m-p/18794#M10</link>
      <description>Hi Ryan&lt;BR /&gt;&lt;BR /&gt;sorry for letting you wait on this topic, but for the moment: thanks a lot for your detailed help.&lt;BR /&gt;&lt;BR /&gt;I was not yet able to analyze / test it, but wanted to get sure you got the appreciation you deserve &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I will keep the post updated, as soon as I can find the time to test it.&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;BR /&gt;Dominic</description>
      <pubDate>Wed, 30 Mar 2022 11:25:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/radius-management-authentication-on-xmc-xiq-control-21-11-11-37/m-p/18794#M10</guid>
      <dc:creator>DominicStalder</dc:creator>
      <dc:date>2022-03-30T11:25:00Z</dc:date>
    </item>
  </channel>
</rss>

