<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re:  Extreme Control as External RADIUS in Cloud IQ in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87510#M241</link>
    <description>I have got this to work! After solving the first problem with the developer profile (redirect URI was missing) then the first task passed and data was collected. I then realized the subsequent tasks also had scripts which when reviewed revealed what I needed to do in addition. I had to create a profile for the new device to use (or alter the script) and I added another IF statement for the model of AP I was using (AP305C) and in the last script alter the primary RADIUS server IP. That's it! I've learnt a lot from this and will be very useful for bulk importing and integrating XIQ WAPs with XIQ-SE with Extreme Control.</description>
    <pubDate>Wed, 02 Mar 2022 08:57:48 GMT</pubDate>
    <dc:creator>AdminS</dc:creator>
    <dc:date>2022-03-02T08:57:48Z</dc:date>
    <item>
      <title>Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87500#M231</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;I understand that it is possible to create a network policy in Cloud IQ for Wireless which can use External RADIUS server for authentication (Extreme A3, NPS, Extreme Control). Do the APs (AP3705C) which are onboarded in the cloud also need to be added under Access-Control&amp;gt;Switches? If so what RADIUS Attributes should they use?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Rob</description>
      <pubDate>Tue, 22 Feb 2022 12:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87500#M231</guid>
      <dc:creator>RobertD1</dc:creator>
      <dc:date>2022-02-22T12:21:00Z</dc:date>
    </item>
    <item>
      <title>Re:  Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87501#M232</link>
      <description>Hi Rob, thanks for reaching out. I just wanted to clarify something really quick so I know what team to reach out to for help with this question- are you building the Radius policy out in ExtremCloud IQ or Extreme A3? We'll be able to help you either way, I just want to make sure I take this to the right team to avoid delays here.</description>
      <pubDate>Wed, 02 Mar 2022 08:56:02 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87501#M232</guid>
      <dc:creator>AdminS</dc:creator>
      <dc:date>2022-03-02T08:56:02Z</dc:date>
    </item>
    <item>
      <title>Re:  Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87502#M233</link>
      <description>Hi Sam,&lt;BR /&gt;&lt;BR /&gt;I have a customer that already has Cloud IQ APs and they are using PSK which has been compromised. They would like a more secure solution where they can assign VLANs for different user types. So, yes I want to use a network policy which uses the Extreme Access Control virtual appliance which is in a secure location at the customer's HQ. EAC and XIQ-SE are able to onboard to Cloud IQ as well as the APs. &lt;BR /&gt;&lt;BR /&gt;Am I right that the APs need to be imported from XIQ into XIQ-SE so that they can be added to Access-Control&amp;gt;Switches? The APs that onboard to the cloud could be in any global location, so missing some facts about how Cloud based APs can use on premise Extreme NAC (not A3) as RADIUS Server using network policy in XIQ. &lt;BR /&gt;&lt;BR /&gt;How is the AP configured under Access-Control&amp;gt;Switches? There is a list of different choices of RADIUS Attributes to Send in the device configuration, what should it be?&lt;BR /&gt;&lt;BR /&gt;Not using Extreme A3.&lt;BR /&gt;&lt;BR /&gt;Extreme Access Control could have local users or integrate with AD database. &lt;BR /&gt;&lt;BR /&gt;Requirement is for 802.1X. &lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Rob</description>
      <pubDate>Wed, 02 Mar 2022 08:56:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87502#M233</guid>
      <dc:creator>AdminS</dc:creator>
      <dc:date>2022-03-02T08:56:16Z</dc:date>
    </item>
    <item>
      <title>Re:  Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87503#M234</link>
      <description>Update... I have found this document to answer quite a few of the questions I had so I will try this out.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://documentation.extremenetworks.com/ExtremeCloudIQ/HowTo/ExtremeControl_for_XIQ-SE_and_XIQ_APs_How-to_Guide.pdf" target="_blank" rel="noopener"&gt;https://documentation.extremenetworks.com/ExtremeCloudIQ/HowTo/ExtremeControl_for_XIQ-SE_and_XIQ_APs_How-to_Guide.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;These are the sort of guides we all find useful and give great guidance with examples which are easy to follow and apply. It would be difficult to know what to do otherwise.</description>
      <pubDate>Wed, 02 Mar 2022 08:56:29 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87503#M234</guid>
      <dc:creator>AdminS</dc:creator>
      <dc:date>2022-03-02T08:56:29Z</dc:date>
    </item>
    <item>
      <title>Re:  Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87504#M235</link>
      <description>I have used the document and managed to get an XIQ WAP to interact with the Access-Control engine. I created three SSIDs and all three worked (for PPSK, Open and Secure).&lt;BR /&gt;&lt;BR /&gt;One thing that failed in my setup was the Workflow to Import the XIQ APs. When I ran it it said it succeeded very quickly as if it did not run through all of the tasks. No APs were added to XIQ-SE and no APs were added to Access-Control.&lt;BR /&gt;&lt;BR /&gt;The output for the workflow showed an error:&lt;BR /&gt;&lt;BR /&gt;Script Name: Process New XIQ Devices_Extract_All_Devices_from_XIQ&lt;BR /&gt;Date and Time: 2022-02-24T16:19:51.443&lt;BR /&gt;XIQ-SE User: netsight&lt;BR /&gt;XIQ-SE User Domain:&lt;BR /&gt;IP:&lt;BR /&gt;code: GatewayErrorCode.CLIENT_VERIFICATION_FAILED&lt;BR /&gt;message: Client Credential verification failed.&lt;BR /&gt;rawMessage: XCKCKzThhF&lt;BR /&gt;status: 401&lt;BR /&gt;&lt;BR /&gt;I imported the workflow and appeared to succeed but nothing happened. Any ideas?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Rob</description>
      <pubDate>Wed, 02 Mar 2022 08:56:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87504#M235</guid>
      <dc:creator>AdminS</dc:creator>
      <dc:date>2022-03-02T08:56:42Z</dc:date>
    </item>
    <item>
      <title>Re:  Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87505#M236</link>
      <description>I think I need to update the script first...&lt;BR /&gt;&lt;BR /&gt;###################################################################&lt;BR /&gt;# Update the Bearer Token, client secret, client-id,&lt;BR /&gt;# redirect-uri, and ownerid in the curl_cmd variable to&lt;BR /&gt;# match your developer credentials, bearer token from&lt;BR /&gt;# XIQ, and VIQ ID.&lt;BR /&gt;# Developer credentials: &lt;A href="https://developer.aerohive.com/" target="_blank" rel="noopener"&gt;https://developer.aerohive.com/&lt;/A&gt;&lt;BR /&gt;# Bearer Token: XIQ Interface/Global Settings/ API Token Management&lt;BR /&gt;# VIQ ID: From the XIQ interface "About" menu option&lt;BR /&gt;###################################################################&lt;BR /&gt;&lt;BR /&gt;curl_cmd = 'curl -s -k --header "Authorization: Bearer xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"'&lt;BR /&gt;curl_cmd = curl_cmd + ' --header "X-AH-API-CLIENT-SECRET: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"'&lt;BR /&gt;curl_cmd = curl_cmd + ' --header "X-AH-API-CLIENT-ID: xxxxxxxx"'&lt;BR /&gt;curl_cmd = curl_cmd + ' --header "X-AH-API-CLIENT-REDIRECT-URI: &lt;A href="https://x.x.x.x" target="_blank" rel="noopener"&gt;https://x.x.x.x"'&lt;/A&gt;&lt;BR /&gt;curl_cmd = curl_cmd + ' &lt;A href="https://va2.extremecloudiq.com/xapi/v1/monitor/devices{?ownerId=xxxxxx}'" target="_blank" rel="noopener"&gt;https://va2.extremecloudiq.com/xapi/v1/monitor/devices{?ownerId=xxxxxx}'&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I've found the ownerId and REDIRECT-URI address (my XIQ-SE) but struggling to find the CLIENT-ID and complete</description>
      <pubDate>Wed, 02 Mar 2022 08:56:56 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87505#M236</guid>
      <dc:creator>AdminS</dc:creator>
      <dc:date>2022-03-02T08:56:56Z</dc:date>
    </item>
    <item>
      <title>Re:  Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87506#M237</link>
      <description>I registered on the developer site and have been able to generate a token. I updated the script, saved it and re-ran the workflow but it fails.</description>
      <pubDate>Wed, 02 Mar 2022 08:57:05 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87506#M237</guid>
      <dc:creator>AdminS</dc:creator>
      <dc:date>2022-03-02T08:57:05Z</dc:date>
    </item>
    <item>
      <title>Re:  Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87507#M238</link>
      <description>&lt;P&gt;Hello Robert,&lt;BR /&gt;&lt;BR /&gt;That is a great document that was developed by our TME team. I use it myself all the time.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;
&lt;/P&gt;&lt;P&gt;To answer your questions for future use:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The AP's needed to be added into the Control --&amp;gt; Switches tab.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Extreme Control/A3 both can have local users or integration with AD.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="c34b3bc41b8040d7a848ffe2ab4fa3af.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1798i8FA02FBB6F58CA0E/image-size/large?v=v2&amp;amp;px=999" role="button" title="c34b3bc41b8040d7a848ffe2ab4fa3af.png" alt="c34b3bc41b8040d7a848ffe2ab4fa3af.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Adding APs into the Control switches tab will add them to a clients.conf file that will make them authorized for RADIUS communication. Without them in the clients.conf file NAC will not respond to RADIUS requests from their IP address.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We use filter-ID for role assignment with XIQ.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 08:57:15 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87507#M238</guid>
      <dc:creator>AdminS</dc:creator>
      <dc:date>2022-03-02T08:57:15Z</dc:date>
    </item>
    <item>
      <title>Re:  Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87508#M239</link>
      <description>Hi Ryan,&lt;BR /&gt;&lt;BR /&gt;I've used the document to get an AP305C to work with XIQ-SE and Extreme Control. I'm struggling to get the workflow mentioned in the document to work though. Some kind of client authorization issue. I've updated the script as instructed and even tried with root but same issue. I just opened a case to try to get help on it (hoping Gitbhub workflows are supported of course).</description>
      <pubDate>Wed, 02 Mar 2022 08:57:27 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87508#M239</guid>
      <dc:creator>AdminS</dc:creator>
      <dc:date>2022-03-02T08:57:27Z</dc:date>
    </item>
    <item>
      <title>Re:  Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87509#M240</link>
      <description>I made a little progress and can get an authorized response from the API with a list of devices but the WF does not add them to XIQ/Access-Control. Getting closer.</description>
      <pubDate>Wed, 02 Mar 2022 08:57:37 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87509#M240</guid>
      <dc:creator>AdminS</dc:creator>
      <dc:date>2022-03-02T08:57:37Z</dc:date>
    </item>
    <item>
      <title>Re:  Extreme Control as External RADIUS in Cloud IQ</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87510#M241</link>
      <description>I have got this to work! After solving the first problem with the developer profile (redirect URI was missing) then the first task passed and data was collected. I then realized the subsequent tasks also had scripts which when reviewed revealed what I needed to do in addition. I had to create a profile for the new device to use (or alter the script) and I added another IF statement for the model of AP I was using (AP305C) and in the last script alter the primary RADIUS server IP. That's it! I've learnt a lot from this and will be very useful for bulk importing and integrating XIQ WAPs with XIQ-SE with Extreme Control.</description>
      <pubDate>Wed, 02 Mar 2022 08:57:48 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extreme-control-as-external-radius-in-cloud-iq/m-p/87510#M241</guid>
      <dc:creator>AdminS</dc:creator>
      <dc:date>2022-03-02T08:57:48Z</dc:date>
    </item>
  </channel>
</rss>

