<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ExtremeControl - Issue - Unexpected NEAP ReAuth in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113459#M880</link>
    <description>&lt;P&gt;Check the time (NTP) on switch and Access Control Engine.&lt;BR /&gt;Check the shared secret for your CoA.&lt;BR /&gt;&lt;BR /&gt;Or use default SNMP instead of RFC3576&lt;BR /&gt;I know switch supports both, but SNMP works better in some scenarios.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Sep 2024 12:12:27 GMT</pubDate>
    <dc:creator>Zdeněk_Pala</dc:creator>
    <dc:date>2024-09-26T12:12:27Z</dc:date>
    <item>
      <title>ExtremeControl - Issue - Unexpected NEAP ReAuth</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113433#M879</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Devices involved :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ExtremeCloud IQ Site Engine version 24.2.15.5&lt;/LI&gt;&lt;LI&gt;ExtremeControl version 24.2.15.5&lt;/LI&gt;&lt;LI&gt;Fabric-Engine&amp;nbsp;5420F-48P-4XE version 8.10.5&lt;/LI&gt;&lt;LI&gt;Windows PC&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Windows PC first authentication is OK (we use 802.1x PEAP MSCHAPv2).&lt;/P&gt;&lt;P&gt;After 10 minutes, ExtremeControl sends RADIUS CoA Disconnect message to reauthenticate the PC.&lt;BR /&gt;The problem is, ExtremeControl receive NEAP Access-Request and the PC is placed in quarantine.&lt;/P&gt;&lt;P&gt;Of course, I expect EAP Reauth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Troubleshoot actions done :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Deactivate NEAP auth on acces port (on the switch) : OK but we want to keep the port configuration as generic as possible.&lt;/LI&gt;&lt;LI&gt;Force Windows supplicant to do 802.1x EAP only : OK but there are some side effects when the PC is back on a non-NACed network.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe CoA message sent from the NAC is malformed ?&lt;/P&gt;&lt;P&gt;Here the reauth parameters for the switch :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Guilhem_Lejeune_1-1727293608632.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8259i9A975841A85D903C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Guilhem_Lejeune_1-1727293608632.png" alt="Guilhem_Lejeune_1-1727293608632.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I have to fix something ?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 19:47:14 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113433#M879</guid>
      <dc:creator>Guilhem_Lejeune</dc:creator>
      <dc:date>2024-09-25T19:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - Issue - Unexpected NEAP ReAuth</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113459#M880</link>
      <description>&lt;P&gt;Check the time (NTP) on switch and Access Control Engine.&lt;BR /&gt;Check the shared secret for your CoA.&lt;BR /&gt;&lt;BR /&gt;Or use default SNMP instead of RFC3576&lt;BR /&gt;I know switch supports both, but SNMP works better in some scenarios.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 12:12:27 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113459#M880</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2024-09-26T12:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - Issue - Unexpected NEAP ReAuth</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113464#M881</link>
      <description>&lt;P&gt;Unclear why CoA is triggered after 10m from initial 802.1x authentication; however yes confirm that Control and switch time are synchronized.&lt;/P&gt;&lt;P&gt;The default for the model you reported is RFC 3576 - Generic CoA Colon Delimited so unclear why it is manually set in override.&lt;/P&gt;&lt;P&gt;This said if the authenticator supports CoA and triggers a re-authentication of the session it should result in a EAPOL Start or ResponseIdentity upstream to the supplicant to trigger 802.1x. Is this happening? Is the client responding to that request? If the client is not then the traffic from the client will be enough to trigger NEAP. Do not know if there is some holddown timer or priority on VOSS to wait for dot1x before moving forward with NEAP.&lt;/P&gt;&lt;P&gt;I always recommend tracing these type of issues if they are reproducible. Client (supplicant) &amp;lt;-&amp;gt; authenticator trace and authenticator &amp;lt;-&amp;gt; Control trace to see the interactions afoot.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 13:29:31 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113464#M881</guid>
      <dc:creator>Robert_Haynes</dc:creator>
      <dc:date>2024-09-26T13:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - Issue - Unexpected NEAP ReAuth</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113691#M888</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;By default there is a 10 minute session timeout for quarantined devices.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Right click the NAC --&amp;gt; Engine Settings --&amp;gt; Reauthentication&lt;BR /&gt;&lt;BR /&gt;There is also an "Accept Session Timeout" that can be enabled, has this been enabled?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I agree with Robert here, it would be a good idea to get a tcpdump of the reauthentication as well as enabling debug for "Reauthentication" and we can take a look at why the initial reauth was issued.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;-Ryan&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 16:40:47 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113691#M888</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2024-09-29T16:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - Issue - Unexpected NEAP ReAuth</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113729#M892</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you gentlemen for all your comments.&lt;BR /&gt;For now, I can tell that both NTP and Shared Secret are all right.&lt;/P&gt;&lt;P&gt;A troubleshoot session is scheduled next Friday. I will share with you what we will find.&lt;/P&gt;&lt;P&gt;See you soon !&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 16:19:13 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113729#M892</guid>
      <dc:creator>Guilhem_Lejeune</dc:creator>
      <dc:date>2024-09-30T16:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - Issue - Unexpected NEAP ReAuth</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113749#M897</link>
      <description>&lt;P&gt;I’m curious as to why Control is issuing a CoA after 10 min? &amp;nbsp;Are you sure there isn’t a reauthentication timer configured directly on the switch?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 11:11:55 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/113749#M897</guid>
      <dc:creator>Configterminal</dc:creator>
      <dc:date>2024-10-02T11:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - Issue - Unexpected NEAP ReAuth</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/115287#M1461</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Support highlighted this point too. We have reconfigured ExtremeControl to disable it and we are now using timer from the switch &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 13:53:59 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/115287#M1461</guid>
      <dc:creator>Guilhem_Lejeune</dc:creator>
      <dc:date>2024-10-10T13:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - Issue - Unexpected NEAP ReAuth</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/115291#M1464</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I've some news... The problem was the RADIUS attributes configured on XIQ SE / ExtremeControl.&lt;BR /&gt;A custom preset was configued, based on "Extreme VOSS". A particular attribute which was added is %PER_USER_ACL%.&lt;/P&gt;&lt;P&gt;It caused the issue because at the moment of reauth, EAP trafic was simply blocked. So no reauth...&lt;/P&gt;&lt;P&gt;Support has seen that by using "show filter acl" command and the "deny all" counter was keeping incrementing !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The attribute has been deleted from the configuration and everyting seems OK now &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 13:57:41 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-issue-unexpected-neap-reauth/m-p/115291#M1464</guid>
      <dc:creator>Guilhem_Lejeune</dc:creator>
      <dc:date>2024-10-10T13:57:41Z</dc:date>
    </item>
  </channel>
</rss>

