<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EXOS | Extreme Control dynamic vlan assignment in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74289#M157</link>
    <description>&lt;P&gt;Miguel,&lt;/P&gt;&lt;P&gt;Yeah, I’ve tried to disable the 802.1X on the port, only having MAC auth. With that, the issue does not appear again. The problem is that is some kind of an exception on the switch config and we loose the flexibility to connect the Printers in any port without any concern regarding the configuration of the port.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the printer is the issue, I’ll have to talk to the customer about that. No magic here, I’m afraid.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Dec 2020 19:30:39 GMT</pubDate>
    <dc:creator>csantos</dc:creator>
    <dc:date>2020-12-30T19:30:39Z</dc:date>
    <item>
      <title>EXOS | Extreme Control dynamic vlan assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74287#M155</link>
      <description>&lt;P&gt;Hi Hub Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We’re using the Extreme Control Policy (NAC) in one of our customers in the health care system&amp;nbsp;to implement some security checks, regarding the devices that can connect to our network. In resume, in our EXOS stacks we have all the ports with the DATA vlan (untag) and VoIP vlan (tag) and we use 802.1X (dot1x - NAC and Microsoft AD) to authenticate our users. On the other hand, we have some&amp;nbsp;NAC policies for special cases, like the printers and the medical devices. When this kind of devices is connected to one of the EXOS stacks, the NAC Engine dynamically assigns the proper vlan (we have a vlan for printers and a vlan for medical devices) on the switch port, using MAC authentication, not 802.1X. In most cases, this is working just fine. However, for some printers we’re facing a stange issue. Basically, from time to time, a printer just stops to communicate. I’m sharing the logs of the port where a printer with this symptom is connected.&amp;nbsp;&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="37ea0ac272414c66ae365520812e081b_37d699b7-7216-474d-9f36-02b28f2a6a56.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/724i43089DD1004FF6A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="37ea0ac272414c66ae365520812e081b_37d699b7-7216-474d-9f36-02b28f2a6a56.png" alt="37ea0ac272414c66ae365520812e081b_37d699b7-7216-474d-9f36-02b28f2a6a56.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;As you can see, we can observe some 802.1X auth being rejected. The funny thing, is that the printer (Zebra G series)&amp;nbsp;does not support 802.1X. So, how can I see these kind of logs? To workaround the issue, we need to reboot the printer and delete the DHCP lease that the printer acquires during the process of authentication on the DATA static vlan. Eventually, after 2 or 3 retries, the printer starts working on the proper vlan for quite some time.&lt;/P&gt;&lt;P&gt;So anyone can help?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;César Santos&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 18:46:06 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74287#M155</guid>
      <dc:creator>csantos</dc:creator>
      <dc:date>2020-12-30T18:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS | Extreme Control dynamic vlan assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74288#M156</link>
      <description>&lt;P&gt;csantos,&lt;/P&gt;&lt;P&gt;I also have issues with Zebra printers on ERS switches when using 802.1X/MAC Auth on the ports.&lt;/P&gt;&lt;P&gt;We forced the MAC on the switch/port to limit the impact but sometimes we set the port without authentication.&lt;/P&gt;&lt;P&gt;I’m afraid those printers are the issue…&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 19:21:33 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74288#M156</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2020-12-30T19:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS | Extreme Control dynamic vlan assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74289#M157</link>
      <description>&lt;P&gt;Miguel,&lt;/P&gt;&lt;P&gt;Yeah, I’ve tried to disable the 802.1X on the port, only having MAC auth. With that, the issue does not appear again. The problem is that is some kind of an exception on the switch config and we loose the flexibility to connect the Printers in any port without any concern regarding the configuration of the port.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the printer is the issue, I’ll have to talk to the customer about that. No magic here, I’m afraid.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 19:30:39 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74289#M157</guid>
      <dc:creator>csantos</dc:creator>
      <dc:date>2020-12-30T19:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS | Extreme Control dynamic vlan assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74290#M158</link>
      <description>&lt;P&gt;I can confirm, that zebra printers are sometimes very special…&lt;/P&gt;&lt;P&gt;One of our customer hase sometimes very strange effects with these printers in a aruba wireless enviroment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case, maybe you could try to disable 802.1x with upm-profile via a special radius-attribute. This should work in exos.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 21:51:52 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74290#M158</guid>
      <dc:creator>PeterK</dc:creator>
      <dc:date>2020-12-30T21:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS | Extreme Control dynamic vlan assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74291#M159</link>
      <description>&lt;P&gt;Hi PeterK, Thanks for the tip.&lt;/P&gt;&lt;P&gt;&lt;USER-MENTION data-id="9898739"&gt;@csantos&lt;/USER-MENTION&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I’m thinking on adapting the timers of 802.1X/MAC Auth on the ports for the Zebra printers.&lt;/P&gt;&lt;P&gt;This could help on allowing the MAC Auth faster than today and still keeping the 802.1X operational.&lt;/P&gt;&lt;P&gt;I need this because some Zebra’s are behind an IP Phone doing 802.1X.&lt;/P&gt;&lt;P&gt;I’ll try after my holidays.&lt;/P&gt;&lt;P&gt;Miug&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2020 23:35:59 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74291#M159</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2020-12-31T23:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS | Extreme Control dynamic vlan assignment</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74292#M160</link>
      <description>&lt;P&gt;&lt;USER-MENTION data-id="6412741"&gt;@PeterK&lt;/USER-MENTION&gt;&amp;nbsp;thanks for your tip. I’ll try, just in case. But I would prefer do not have any kind of exception, between the ports of my stacks,&amp;nbsp;regarding the 802.1X auth process. I’ll let the end customer have the final decision about that, if my lab with upm-profile works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;USER-MENTION data-id="9728928"&gt;@Miguel-Angel RODRIGUEZ-GARCIA&lt;/USER-MENTION&gt;&amp;nbsp;that’s an interesting idea. After you try thak workaround, please let me know if the behaviour of these printers change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2021 01:21:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/exos-extreme-control-dynamic-vlan-assignment/m-p/74292#M160</guid>
      <dc:creator>csantos</dc:creator>
      <dc:date>2021-01-01T01:21:23Z</dc:date>
    </item>
  </channel>
</rss>

