<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC - 802.1x End-Systems IP missing, forward AAA in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65290#M55</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two Cisco WLCs 5500 using our Extreme NACs as Radius Authentication and Accounting servers.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;While Authentication works nicely, I am missing some IP addresses from End-Systems while others are there.	&lt;UL&gt;&lt;LI&gt;Any idea why?&lt;/LI&gt;	&lt;/UL&gt;&lt;/LI&gt;	&lt;LI&gt;We would also like to forward the username / identity to a FortiGate firewall.	&lt;UL&gt;&lt;LI&gt;How would I do that?&lt;/LI&gt;	&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Klaus&lt;/P&gt;</description>
    <pubDate>Fri, 28 May 2021 07:58:37 GMT</pubDate>
    <dc:creator>tfsnetman</dc:creator>
    <dc:date>2021-05-28T07:58:37Z</dc:date>
    <item>
      <title>NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65290#M55</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two Cisco WLCs 5500 using our Extreme NACs as Radius Authentication and Accounting servers.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;While Authentication works nicely, I am missing some IP addresses from End-Systems while others are there.	&lt;UL&gt;&lt;LI&gt;Any idea why?&lt;/LI&gt;	&lt;/UL&gt;&lt;/LI&gt;	&lt;LI&gt;We would also like to forward the username / identity to a FortiGate firewall.	&lt;UL&gt;&lt;LI&gt;How would I do that?&lt;/LI&gt;	&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Klaus&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 07:58:37 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65290#M55</guid>
      <dc:creator>tfsnetman</dc:creator>
      <dc:date>2021-05-28T07:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65291#M56</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;typically the NAC gets the MAC IP mapping information by reading DHCP requests and responses.&lt;BR /&gt;For this purpose, NAC is registered as a DHCP server on the routers that forward DHCP requests (=DHCP relays).&lt;BR /&gt;This does not work with static IP addresses on the end devices.&lt;/P&gt;&lt;P&gt;So my question:&amp;nbsp;Is the difference between the devices for which the ip addresses are displayed and for the devices for which they are not displayed&amp;nbsp;that one uses DHCP and the other not?&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 22:13:59 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65291#M56</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-05-28T22:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65292#M57</link>
      <description>&lt;P&gt;This is one of several possibilites. Other options are for example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;radius accounting (as tfsnetman stated)&lt;/LI&gt;	&lt;LI&gt;nodealias (not possible here)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I had the problem once that NAC couldn’t display end-system IP-addresses. DHCP was configured correctly and Radius accounting was also enabled. Maybe tfsnetman has the same problem. Only solution was nodealias.&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 03:13:26 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65292#M57</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2021-05-30T03:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65293#M58</link>
      <description>&lt;P&gt;Switching on WLC accounting is not always sufficient depending on the sw version. To be sure&amp;nbsp;you have to check if the transmission of MAC and IP under&lt;/P&gt;&lt;P&gt;Acct&amp;nbsp;Called Station ID Type&lt;/P&gt;&lt;P&gt;is switched on. But guessing helps little here, it would be good to know how the address resolution runs in the installation Klaus mentioned.&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 03:58:08 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65293#M58</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-05-30T03:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65294#M59</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Accounting Called Station ID type is set o IP and there is no option for both MAC and IP - see attachment.&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="0b22bee4426944ada3b8f39bfdb8fc07_71b48a88-52d8-44c5-bd41-ffe869fddf89.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2866i87F3DEFF836ADD68/image-size/large?v=v2&amp;amp;px=999" role="button" title="0b22bee4426944ada3b8f39bfdb8fc07_71b48a88-52d8-44c5-bd41-ffe869fddf89.png" alt="0b22bee4426944ada3b8f39bfdb8fc07_71b48a88-52d8-44c5-bd41-ffe869fddf89.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;We are talking about Wi-Fi and 802.1x authentication only where IP addresses are always assigned via DHCP.&lt;/P&gt;&lt;P&gt;@Stephan: not sure whether what you mean by registering NACs as a DHCP server and how those DHCP requests would flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Klaus&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 11:58:39 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65294#M59</guid>
      <dc:creator>tfsnetman</dc:creator>
      <dc:date>2021-05-30T11:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65295#M60</link>
      <description>&lt;P&gt;Hello Klaus,&lt;/P&gt;&lt;P&gt;the accounting settings should fit&lt;/P&gt;&lt;P&gt;&amp;nbsp;Regarding DHCP, I assume the DHCP server has no IP in the same network as your clients. Then there must be a router in your network that has a DHCP helper entry that contains the IP address of the DHCP server. Enter there also the NAC IP (additional), as if the NAC was a DHCP server.&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 12:07:34 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65295#M60</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-05-30T12:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65296#M61</link>
      <description>&lt;P&gt;If the WLC care about the DHCP forwarding add the NAC ip as DHCP server on the WLC.&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 12:08:47 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65296#M61</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-05-30T12:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65297#M62</link>
      <description>&lt;P&gt;Hi Stephan,&lt;/P&gt;&lt;P&gt;I guess, I will find out how well it works and let you know.&lt;/P&gt;&lt;P&gt;Any thoughts about how to forward user identity from the Extreme NACs to a FortiGate firewall?&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Klaus&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 13:12:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65297#M62</guid>
      <dc:creator>tfsnetman</dc:creator>
      <dc:date>2021-05-30T13:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65298#M63</link>
      <description>&lt;P&gt;Hello Klaus,&lt;/P&gt;&lt;P&gt;maybe the ExtremeConnect integration for FortiGate is what you need. Check the manual here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.extremenetworks.com/netsight/8.5/XMC_8.5_ExtremeConnect_User_Guide.pdf?_ga=2.251304518.1913999325.1622458672-913789110.1618568265" target="_blank" rel="nofollow noreferrer noopener"&gt;https://documentation.extremenetworks.com/netsight/8.5/XMC_8.5_ExtremeConnect_User_Guide.pdf?_ga=2.251304518.1913999325.1622458672-913789110.1618568265&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you need other information in you Fortigate. Maybe the XMC NBI-API can help you.&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 18:16:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65298#M63</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-05-31T18:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65299#M64</link>
      <description>&lt;P&gt;Hi Stephan,&lt;/P&gt;&lt;P&gt;Adding the Extreme NACs as a secondary DHCP on the Cisco WLCs is providing additional information such as Device Type and hostname but doesn’t help with further IP addresses.&lt;/P&gt;&lt;P&gt;Thank you for pointing me to the manual. I will have my black belt / PhD in XMC, Control after applying that knowledge.&lt;/P&gt;&lt;P&gt;Cheers, Klaus&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 07:16:43 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65299#M64</guid>
      <dc:creator>tfsnetman</dc:creator>
      <dc:date>2021-06-01T07:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65300#M65</link>
      <description>&lt;P&gt;Hello Klaus,&lt;/P&gt;&lt;P&gt;because of the additional information&amp;nbsp;you metioned, you know your helper setting is correct.&lt;/P&gt;&lt;P&gt;To see what's goung wrong with your ip resolution, follow that guide for debugging and check the output in the log file:&lt;/P&gt;&lt;P&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000082183&amp;amp;q=mac%20to%20ip%20resolution%20failed" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000082183&amp;amp;q=mac%20to%20ip%20resolution%20failed&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 13:31:55 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65300#M65</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2021-06-01T13:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAC - 802.1x End-Systems IP missing, forward AAA</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65301#M66</link>
      <description>&lt;P&gt;Thank you Stephan,&lt;/P&gt;&lt;P&gt;Added the NACs as a secondary DHCP server on all WLC interfaces which increased the accuracy for MAC IP address resolution.&lt;/P&gt;&lt;P&gt;Since both the NACs and the DHCP server are in the same subnet I would have expected this to work based on DHCP multicast messages alone.&lt;/P&gt;&lt;P&gt;I was also able to use the FortiGate SSO module in the XMC Connect which is now forwarding Radius accounting information. The sender IP of the Radius data is the XMC and not the NAC.&lt;/P&gt;&lt;P&gt;All the best,&lt;/P&gt;&lt;P&gt;Klaus&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 09:15:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/nac-802-1x-end-systems-ip-missing-forward-aaa/m-p/65301#M66</guid>
      <dc:creator>tfsnetman</dc:creator>
      <dc:date>2021-06-02T09:15:17Z</dc:date>
    </item>
  </channel>
</rss>

