<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: checking ldap user and radius attribute on NAC Authentication in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70742#M124</link>
    <description>&lt;P&gt;Hi Tomasz,&lt;/P&gt;&lt;P&gt;thanks for that idea.&lt;/P&gt;&lt;P&gt;That would be a very dirty workaround, but it should work.&lt;/P&gt;&lt;P&gt;I will test this. I’m excited how that will look in End-System View.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jan 2021 03:56:24 GMT</pubDate>
    <dc:creator>PeterK</dc:creator>
    <dc:date>2021-01-13T03:56:24Z</dc:date>
    <item>
      <title>checking ldap user and radius attribute on NAC Authentication</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70735#M117</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I’m currently on a migration process from Microsoft NPS to Extreme Control.&lt;/P&gt;&lt;P&gt;We have a Cisco ASA as VPN-Gateway.&lt;/P&gt;&lt;P&gt;I will authenticate VPN-Users and Mgmt-Logins.&lt;/P&gt;&lt;P&gt;In the past we separate this with different “called-station-id” values.&lt;/P&gt;&lt;P&gt;Can I realize this with NAC? AFAIK I can’t check/match LDAP-Criteria (LDAP-User-Group) and Radius-Attribute (Radius-User-Group) at the same time.&lt;/P&gt;&lt;P&gt;Or Is there a way to realize this?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 22:34:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70735#M117</guid>
      <dc:creator>PeterK</dc:creator>
      <dc:date>2021-01-11T22:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: checking ldap user and radius attribute on NAC Authentication</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70736#M118</link>
      <description>&lt;P&gt;PeterK,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here a screenshot on how I manage Mgmt logins on Control for ERS/VSP switches.&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="0b05845a96304f819caf6a9411ed7988_3fe7e89f-466a-4a4d-a7c8-ce8d1e2d512d.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/946i221567F8E2E6F496/image-size/large?v=v2&amp;amp;px=999" role="button" title="0b05845a96304f819caf6a9411ed7988_3fe7e89f-466a-4a4d-a7c8-ce8d1e2d512d.png" alt="0b05845a96304f819caf6a9411ed7988_3fe7e89f-466a-4a4d-a7c8-ce8d1e2d512d.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;For the VPN users, you can validate them on the location (originated on the VPN concentrator and User-Groups).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 22:40:09 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70736#M118</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-01-11T22:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: checking ldap user and radius attribute on NAC Authentication</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70737#M119</link>
      <description>&lt;P&gt;Hi Mig,&lt;/P&gt;&lt;P&gt;thanks for your answer, but this does not really helps.&lt;/P&gt;&lt;P&gt;Mgmt-Login for XOS Switches is no problem.&lt;/P&gt;&lt;P&gt;I will authenticate users for vpn-login und mgmt-login from Cisco ASA.&lt;/P&gt;&lt;P&gt;So, the source-IP is the same. So I need something to select. In the ASA we have different values which are send in Radius Request as called-station-id to the NAC.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 23:12:43 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70737#M119</guid>
      <dc:creator>PeterK</dc:creator>
      <dc:date>2021-01-11T23:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: checking ldap user and radius attribute on NAC Authentication</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70738#M120</link>
      <description>&lt;P&gt;Hi Peter,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something is still unclear.&lt;/P&gt;&lt;P&gt;You want to&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Authenticate VPN users with authentication requests coming from the ASA&lt;/LI&gt;	&lt;LI&gt;Authenticate admin users loging into ASA?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;If 2 is correct, the authentication request will be different in terms of inbound radius attributes and should be treated as such by Control.&lt;/P&gt;&lt;P&gt;Here an abstract of the event log of Control for a login on the switches:&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;This is an administrative request because Calling-Station-Id is not present&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;What attributes and values are you checking on your existing system?&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 23:22:15 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70738#M120</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-01-11T23:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: checking ldap user and radius attribute on NAC Authentication</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70739#M121</link>
      <description>&lt;P&gt;Hi Mig,&lt;/P&gt;&lt;P&gt;thanks for your answer.&lt;/P&gt;&lt;P&gt;I will have both 1 and 2 (not at the same time).&lt;/P&gt;&lt;P&gt;On the current NPS I check:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;NAS-IP (in both cases the same)&lt;/LI&gt;	&lt;LI&gt;the ldap-user-group (different groups, but a user can be member of both groups&lt;/LI&gt;	&lt;LI&gt;called-station-id (in case of VPN - value is WAN-IP; in case of mgmt its LAN-IP)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in general, can I check/match/validate LDAP and Radius Information from Radius-Request at the same time?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 23:28:54 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70739#M121</guid>
      <dc:creator>PeterK</dc:creator>
      <dc:date>2021-01-11T23:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: checking ldap user and radius attribute on NAC Authentication</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70740#M122</link>
      <description>&lt;P&gt;Hi Peter,&lt;/P&gt;&lt;P&gt;I don’t think you can match both at the same time because they are both “User-Group” type.&lt;/P&gt;&lt;P&gt;Can you set an empty called-station-id instead of LAN-IP?&lt;/P&gt;&lt;P&gt;If so, Control will treat this as management access&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 23:35:39 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70740#M122</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2021-01-11T23:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: checking ldap user and radius attribute on NAC Authentication</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70741#M123</link>
      <description>&lt;P&gt;Hi Mig, Peter,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just thinking loud, I suspect it would be possible to use User Group with LDAP/RADIUS lookups and End-System Group with LDAP lookups configured in a way that still a user is looked up…?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 22:47:37 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70741#M123</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2021-01-12T22:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: checking ldap user and radius attribute on NAC Authentication</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70742#M124</link>
      <description>&lt;P&gt;Hi Tomasz,&lt;/P&gt;&lt;P&gt;thanks for that idea.&lt;/P&gt;&lt;P&gt;That would be a very dirty workaround, but it should work.&lt;/P&gt;&lt;P&gt;I will test this. I’m excited how that will look in End-System View.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 03:56:24 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70742#M124</guid>
      <dc:creator>PeterK</dc:creator>
      <dc:date>2021-01-13T03:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: checking ldap user and radius attribute on NAC Authentication</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70743#M125</link>
      <description>&lt;P&gt;Hi Peter,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This idea came to my mind as in the past there were some issues with LDAP Configuration having both user and computer lookup settings and for computer authentication a separate LDAP Configuration had to be made, with computer-specific attributes and object type in user lookup fields. I don’t remember why it was so, but if it worked, the opposite should also work. Labels are just labels. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 04:58:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/checking-ldap-user-and-radius-attribute-on-nac-authentication/m-p/70743#M125</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2021-01-13T04:58:19Z</dc:date>
    </item>
  </channel>
</rss>

