<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extreme Control Machine + User authentication fails in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70170#M105</link>
    <description>&lt;P&gt;Hello SDR,&lt;/P&gt;&lt;P&gt;your maschine is matching &lt;STRONG&gt;IS NOT&lt;/STRONG&gt; in &lt;EM&gt;End-System Groups AD machine&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;and is not matching &lt;STRONG&gt;IS &lt;/STRONG&gt;in &lt;EM&gt;End-System Groups AD machine&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;=&amp;gt; Are you 100% sure that the maschine is in the expacted AD group?&lt;/P&gt;&lt;P&gt;That’s why I ask if you can see if the client is in the group (with the LDAP test tool)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 06 Feb 2021 01:47:35 GMT</pubDate>
    <dc:creator>StephanH</dc:creator>
    <dc:date>2021-02-06T01:47:35Z</dc:date>
    <item>
      <title>Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70165#M100</link>
      <description>&lt;P&gt;​&lt;BR /&gt;Hi,&lt;/P&gt;&lt;P&gt;This Topic is a a follow up to&lt;/P&gt;&lt;OEMBED url="https://community.extremenetworks.com/extreme-management-center-233228/extreme-control-rule-and-ad-7829202/index2.html#post19907557"&gt;&lt;/OEMBED&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although, I hopefully configured everything as advised and discussed in above thread,&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Machine + User authentication fails. (Machine auth ONLY works fine, now!)&lt;/P&gt;&lt;P&gt;Below is a screenshot of&amp;nbsp;&amp;nbsp;the EvaluationTool result:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="9b635a8e5ebc40f6a8c66126253d4e30_70302b0d-5609-4778-b310-606ec3098b0f.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2104i5D4374722C630E95/image-size/large?v=v2&amp;amp;px=999" role="button" title="9b635a8e5ebc40f6a8c66126253d4e30_70302b0d-5609-4778-b310-606ec3098b0f.jpg" alt="9b635a8e5ebc40f6a8c66126253d4e30_70302b0d-5609-4778-b310-606ec3098b0f.jpg" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don´t see the mistake….&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 21:21:09 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70165#M100</guid>
      <dc:creator>SDR</dc:creator>
      <dc:date>2021-02-05T21:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70166#M101</link>
      <description>&lt;P&gt;Hello SDR,&lt;/P&gt;&lt;P&gt;take the user data you see in Eval Tool. Got to the corresponding LDAP Rule and select test.&lt;/P&gt;&lt;P&gt;Fill in the user data and check if you receive the result&amp;nbsp;that you expect.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 21:27:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70166#M101</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-02-05T21:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70167#M102</link>
      <description>&lt;P&gt;SDR,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your rules seems to be wrong.&lt;/P&gt;&lt;P&gt;The non domain machine rule is matching an AD user on a AD computer.&lt;/P&gt;&lt;P&gt;Could you share a screen of the rules?&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 21:31:10 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70167#M102</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-02-05T21:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70168#M103</link>
      <description>&lt;P&gt;We already did and to my understanding, the tests were sucessfull.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 21:36:55 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70168#M103</guid>
      <dc:creator>SDR</dc:creator>
      <dc:date>2021-02-05T21:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70169#M104</link>
      <description>&lt;P&gt;See below - as we are still testing, we did not focus on the “actions” (profiles)&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="d3f2935d00954a8c976cccd2558c297d_77005e7a-6928-4d60-970f-7b384744220f.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4124iF60A66E554CEBDC6/image-size/large?v=v2&amp;amp;px=999" role="button" title="d3f2935d00954a8c976cccd2558c297d_77005e7a-6928-4d60-970f-7b384744220f.jpg" alt="d3f2935d00954a8c976cccd2558c297d_77005e7a-6928-4d60-970f-7b384744220f.jpg" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 21:40:20 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70169#M104</guid>
      <dc:creator>SDR</dc:creator>
      <dc:date>2021-02-05T21:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70170#M105</link>
      <description>&lt;P&gt;Hello SDR,&lt;/P&gt;&lt;P&gt;your maschine is matching &lt;STRONG&gt;IS NOT&lt;/STRONG&gt; in &lt;EM&gt;End-System Groups AD machine&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;and is not matching &lt;STRONG&gt;IS &lt;/STRONG&gt;in &lt;EM&gt;End-System Groups AD machine&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;=&amp;gt; Are you 100% sure that the maschine is in the expacted AD group?&lt;/P&gt;&lt;P&gt;That’s why I ask if you can see if the client is in the group (with the LDAP test tool)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 01:47:35 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70170#M105</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-02-06T01:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70171#M106</link>
      <description>&lt;P&gt;Hi SDR,&lt;/P&gt;&lt;P&gt;Looking at those screens I see:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;From the rules: “Machine and User Auth” is expecting “End-Systems Groups AD machines”&lt;/LI&gt;	&lt;LI&gt;From the evaluation tool: “Th Host ...doesn’t have LDAP attributes..in this inclusive LDAP Host Group End-Systems Groups AD machines”&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Looking at the the description of the workflows and scripts from Zdenek we see:&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;"Add MAC to Domain Computers" is executed when the computer authenticates. The MAC address is added to End-System and the timestamp is created (updated). Consequent User authentication can be combined with the condition of the End-System group. "Clear old End-Systems in the group" checks if the timestamp is older than X hours and old End-Systems are deleted from the group.&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;From the script description, it means that the HOST (read “End-System”) is to be looked into a group of MAC adresses while you defined and LDAP group in the rule for the statement “&lt;STRONG&gt;End-System is in&lt;/STRONG&gt;”.&lt;/P&gt;&lt;P&gt;To make it shorter, you’ll store (for a defined period of time) all the MAC addresses from the AD computers (having been authenticated) in a group and check if the authenticating user is with a computer having his MAC in this group.&lt;/P&gt;&lt;P&gt;I know that the way this script works is not very intuitive (looking for a MAC to see if a computer belongs to an AD domain) but there are some technical constrains on the authentication steps that implies this solution.&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 02:36:32 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70171#M106</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-02-06T02:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70172#M107</link>
      <description>&lt;P&gt;Hello SDR, hello Mig,&lt;/P&gt;&lt;P&gt;I'm a little confused. What are you trying to implement SDR? Based on your ruleset, I assumed you were using the procedure described here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000080814&amp;amp;q=nuc%20802.1x%20ldap%20user%20&amp;amp;_ga=2.117373440.783434873.1612345045-1757759156.1597658815" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000080814&amp;amp;q=nuc%20802.1x%20ldap%20user%20&amp;amp;_ga=2.117373440.783434873.1612345045-1757759156.15976588&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 02:58:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70172#M107</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-02-06T02:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70173#M108</link>
      <description>&lt;P&gt;That wasn’t my understanding…&lt;/P&gt;&lt;P&gt;SDR, It would be nice to clarify the exact use case and method you are trying to achieve.&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 03:06:36 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70173#M108</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-02-06T03:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70174#M109</link>
      <description>&lt;P&gt;Hello Stephan, Mig,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry for delay due to private reasons.&lt;/P&gt;&lt;P&gt;&lt;USER-MENTION data-id="9728928"&gt;@Miguel-Angel RODRIGUEZ-GARCIA&lt;/USER-MENTION&gt;&amp;nbsp;: I thought, you understood my use case, as you gave me several hints, how to get mor close to the solution. Sorry for not beeing detailed enough.&lt;/P&gt;&lt;P&gt;&lt;USER-MENTION data-id="8733471"&gt;@StephanH&lt;/USER-MENTION&gt;&amp;nbsp;: You are right. I followed the linked procedure to realize customers wish:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;Authenticate Windows CLIENT based on machine being in the AD.&lt;/LI&gt;	&lt;LI&gt;Authenticate Windows USER&amp;nbsp;on Windows CLIENT based on machine AND User being in the AD.&amp;nbsp;&lt;/LI&gt;	&lt;LI&gt;Reject Non-domain machine.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;According to the documents and you assistance here we managed, that&lt;/P&gt;&lt;P&gt;TOP 1)&amp;nbsp;“Authenticate Windows CLIENT based on machine being in the AD.” works.&lt;/P&gt;&lt;P&gt;TOP 2) does not yet work - as documented by my screenshots.&lt;/P&gt;&lt;P&gt;With regards to&amp;nbsp; &amp;nbsp;&lt;USER-MENTION data-id="8733471"&gt;@StephanH&lt;/USER-MENTION&gt;&amp;nbsp; “Are you 100% sure that the maschine is in the expacted AD group?”my anwer is: “I am nearly 100% sure”,….&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we have no remote access to the environment at the moment, I cannot test/verify again.&lt;/P&gt;&lt;P&gt;However, pls clearify what/how to test.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to verify once again&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;if the Host (written exactly like thrown out in the EVAL tool) is found in LDAP-Test (which section? User search? Host search?&lt;/LI&gt;	&lt;LI&gt;if the User (written exactly like thrown out in the EVAL tool) is found in LDAP-Test (which section? User search? Host search?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;As soon as I have the result, i´ll post a screenshot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks + sorry for confusion, again&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 22:05:58 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70174#M109</guid>
      <dc:creator>SDR</dc:creator>
      <dc:date>2021-02-09T22:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70175#M110</link>
      <description>&lt;P&gt;Hello Stefan,&lt;/P&gt;&lt;P&gt;as I wrote above. If you have two rules with two different checks (is not and is), this is the point you have to investigate first.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the LDAP test tool use the user search for rules matching an user and the host search for rules matching the host.&lt;/P&gt;&lt;P&gt;You can check which LDAP rule is used via the Eval tool (second tab = 2. Authentication evaluation).&lt;/P&gt;&lt;P&gt;As result you will receive the groups you user/device is in.&lt;/P&gt;&lt;P&gt;If you play arround with these settings you will have a good understanding what happen during the ldap checks in NAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 23:49:06 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70175#M110</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-02-09T23:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70176#M111</link>
      <description>&lt;P&gt;Stefan,&lt;/P&gt;&lt;P&gt;Are you meeting all the requirements for the LDAP groups?&lt;/P&gt;&lt;P&gt;See documentation:&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="85f082ce93bb4b37b3fb3fb04d7bdd23_06557724-caf9-4538-8e10-48ef023cad1c.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1758iA1CB77B70D4C0AEB/image-size/large?v=v2&amp;amp;px=999" role="button" title="85f082ce93bb4b37b3fb3fb04d7bdd23_06557724-caf9-4538-8e10-48ef023cad1c.png" alt="85f082ce93bb4b37b3fb3fb04d7bdd23_06557724-caf9-4538-8e10-48ef023cad1c.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 00:00:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70176#M111</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-02-10T00:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70177#M112</link>
      <description>&lt;P&gt;Good morning all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I´m quite desperate. I now have remote access and verified everything + also checked with the Eval-Tool + LDAP-Test-Feature.&lt;/P&gt;&lt;P&gt;Without success.&lt;/P&gt;&lt;P&gt;As shown in an earlier Screenshot, the Eval tool claims, that the Host “MV-xxx.de” does not have LDAP-attributes defined in the LDAP Host Group “End System Groups AD machines”.&lt;/P&gt;&lt;P&gt;Verifying this with LDAP-Test : see below:&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="d29a9d0681c940f98c639011845c2cc1_a8479f22-f8d3-4316-a2c5-07f271ff3550.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6083iA5A220EA37FC211D/image-size/large?v=v2&amp;amp;px=999" role="button" title="d29a9d0681c940f98c639011845c2cc1_a8479f22-f8d3-4316-a2c5-07f271ff3550.png" alt="d29a9d0681c940f98c639011845c2cc1_a8479f22-f8d3-4316-a2c5-07f271ff3550.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;So, there IS such an entry.&lt;/P&gt;&lt;P&gt;What I am confused about: This entry is found as “dNSHostName”.&lt;/P&gt;&lt;P&gt;According to ealier mentioned guide, “objectcategory” is defined as attribute for the group.&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="d29a9d0681c940f98c639011845c2cc1_f0c3a4c1-a8db-493f-b26f-4d074420a960.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3189iE1098C6076C1CB77/image-size/large?v=v2&amp;amp;px=999" role="button" title="d29a9d0681c940f98c639011845c2cc1_f0c3a4c1-a8db-493f-b26f-4d074420a960.png" alt="d29a9d0681c940f98c639011845c2cc1_f0c3a4c1-a8db-493f-b26f-4d074420a960.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;However, changing this to dnsNostName does not work either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checke configuration vs. guide several times…..don´t find the mistake.&lt;/P&gt;&lt;P&gt;Hope you can point out the issue….&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 15:44:40 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70177#M112</guid>
      <dc:creator>SDR</dc:creator>
      <dc:date>2021-02-12T15:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70178#M113</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a quick question, sorry if I misunderstood anything above. Your End-System Group checks if the device’s objectCategory is cn=computer(...). Is that what you need to check? What is the MV-NB-IT-13 objectCategory?&lt;/P&gt;&lt;P&gt;Quite often group membership in LDAP is checked with attribute like memberOf. dNSHostName is something you define in LDAP configurations for host lookup so when NAC receives auth request with a unique hostname, it can search in LDAP for a relevant device’s details (to match authenticating hostname and its LDAP reference).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 00:40:01 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70178#M113</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2021-02-13T00:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70179#M114</link>
      <description>&lt;P&gt;SDR,&lt;/P&gt;&lt;P&gt;As far as I remeber there were some issue for this config on double authentication (user+computer) using an LDAP validation for the computer. A specific agent could be necessary (Cisco does that) with windows.&lt;/P&gt;&lt;P&gt;This is the reason why an alternative with the workflow and script mentioned in my previous posts was done.&lt;/P&gt;&lt;P&gt;As a reminder this way of working is using MAC check instead of LDAP check to validate the computer during a user auth:&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;"Add MAC to Domain Computers" is executed when the computer authenticates. The MAC address is added to End-System and the timestamp is created (updated). Consequent User authentication can be combined with the condition of the End-System group. "Clear old End-Systems in the group" checks if the timestamp is older than X hours and old End-Systems are deleted from the group.&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe &lt;USER-MENTION data-id="6370292"&gt;@Zdenek Pala&lt;/USER-MENTION&gt; could briefly comment this use case.&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 18:46:13 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70179#M114</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-02-13T18:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70180#M115</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;I don´t know why, however I missed the last updates from Tomasz + Miguel.&lt;/P&gt;&lt;P&gt;Sorry, that was not intended.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luckily it seems, that I could solve the issue by myself in the meantime.&lt;/P&gt;&lt;P&gt;At least, the Eval-Tool now shows a match to the according rule.&lt;/P&gt;&lt;P&gt;As i´m pretty unsure in this topic, I would like to wait for customer to test and confirm the solution.&lt;/P&gt;&lt;P&gt;Afterwards, I´ll update this topic.&lt;/P&gt;&lt;P&gt;Thanks @ALL for your help so far.&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 20:11:10 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70180#M115</guid>
      <dc:creator>SDR</dc:creator>
      <dc:date>2021-02-18T20:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Extreme Control Machine + User authentication fails</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70181#M116</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;today customer tested the solution/correction and it worked.&lt;/P&gt;&lt;P&gt;Below my solution/explanation:&lt;/P&gt;&lt;P&gt;In an earlier mentioned documentation (&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000080814" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000080814&lt;/A&gt;)&amp;nbsp; I primarily followed it was advised to use “cn” as &lt;STRONG&gt;Host Search Attibute&amp;nbsp;&lt;/STRONG&gt;(within the LDAP-configuration of “Domain users”&lt;/P&gt;&lt;P&gt;At least in my environment, this did not work (as shown in above screenshots). The solution was to use “dNSHostName” as&amp;nbsp;&lt;STRONG&gt;Host Search Attibute&amp;nbsp;&lt;/STRONG&gt;(which is the default).&lt;/P&gt;&lt;P&gt;Changing this, the configuration worked. Machine AND User-Authentication are passed successfull.&lt;/P&gt;&lt;P&gt;Unfortunately, this solution is already described in&amp;nbsp;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000082479" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000082479&lt;/A&gt;&amp;nbsp;which I found during my troubleshooting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition to this modification of the solution, I changed the advised order of&amp;nbsp;the Rules.&lt;/P&gt;&lt;P&gt;Instead of&amp;nbsp;&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;Authenticate and authorise a machine&lt;/LI&gt;	&lt;LI&gt;Authenticate and authorise a machine as a valid domain computer with a valid domain user logged in&lt;/LI&gt;	&lt;LI&gt;Deny a valid user who is on a non-domain (BYOD) computer&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;In my environment, Rule “2” never will be verified, after a Machine was successfully authenticated.&lt;/P&gt;&lt;P&gt;So, no user-authentication will ever happen.&lt;/P&gt;&lt;P&gt;For that reason, I switched the order of rule&amp;nbsp;1 and 2 and afterwards, all&amp;nbsp;variations could be verified and authenticated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all for your assistance.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 18:35:11 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-machine-user-authentication-fails/m-p/70181#M116</guid>
      <dc:creator>SDR</dc:creator>
      <dc:date>2021-02-26T18:35:11Z</dc:date>
    </item>
  </channel>
</rss>

