<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ExtremeControl - MAC to IP resolution question in ExtremeControl</title>
    <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113730#M893</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for your feedback, Stefan &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Why shouldn't authentication be possible? Authentication shouldn't be based on the IP-Address. 802.1x is recommended, MAC-based is possible... After authentication DHCP is happening and the IP-Addressfield on NAC will be populated.&lt;BR /&gt;&lt;/EM&gt;&lt;STRONG&gt;Yes, I totally agree !&amp;nbsp;Authentication process is completly agnostic of DHCP process. That's why I'm kind of lost...&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is, I observed that I must plug the PC in a non-NACed port before the NACed port.&lt;BR /&gt;This observation has lead me to a possible "MAC-to-IP resolution" issue but, as you said, I understand that should not be the problem.&lt;/P&gt;&lt;P&gt;Does anyone has already encountered this problem and the root cause ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2024 16:30:28 GMT</pubDate>
    <dc:creator>Guilhem_Lejeune</dc:creator>
    <dc:date>2024-09-30T16:30:28Z</dc:date>
    <item>
      <title>ExtremeControl - MAC to IP resolution question</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113726#M889</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a pure theory question here.&lt;/P&gt;&lt;P&gt;It seems that MAC to IP resolution is mandatory to make ExtremeControl work properly.&lt;BR /&gt;The most popular technic is to relay DHCP messages toward ExtremeControl and that is what I use in production.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;What about a new client ?&lt;/STRONG&gt; It has never been seen on the network so its hypothetical IP address is not known. Or, the lease is expired.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;MAC to IP resolution cannot be done and... neither does the authentication, right ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have this exact use case in production. We have to plug the PC in non-NACed port in order to get through the whole DHCP process. Then, the PC is plugged in the NAC port and it works.&lt;/P&gt;&lt;P&gt;If we plugged the PC in the NACed port first, it does not work.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 12:45:26 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113726#M889</guid>
      <dc:creator>Guilhem_Lejeune</dc:creator>
      <dc:date>2024-09-30T12:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - MAC to IP resolution question</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113728#M891</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/26151"&gt;@Guilhem_Lejeune&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a pure theory question here.&lt;/P&gt;&lt;P&gt;It seems that MAC to IP resolution is mandatory to make ExtremeControl work properly.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Not really, it's more like a nice-to-have feature, to see the IP of the End-Systems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;What about a new client ? It has never been seen on the network so its hypothetical IP address is not known. Or, the lease is expired.&lt;P&gt;MAC to IP resolution cannot be done and... neither does the authentication, right ?&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Why shouldn't authentication be possible? Authentication shouldn't be based on the IP-Address. 802.1x is recommended, MAC-based is possible... After authentication DHCP is happening and the IP-Addressfield on NAC will be populated.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 14:18:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113728#M891</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2024-09-30T14:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - MAC to IP resolution question</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113730#M893</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for your feedback, Stefan &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Why shouldn't authentication be possible? Authentication shouldn't be based on the IP-Address. 802.1x is recommended, MAC-based is possible... After authentication DHCP is happening and the IP-Addressfield on NAC will be populated.&lt;BR /&gt;&lt;/EM&gt;&lt;STRONG&gt;Yes, I totally agree !&amp;nbsp;Authentication process is completly agnostic of DHCP process. That's why I'm kind of lost...&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is, I observed that I must plug the PC in a non-NACed port before the NACed port.&lt;BR /&gt;This observation has lead me to a possible "MAC-to-IP resolution" issue but, as you said, I understand that should not be the problem.&lt;/P&gt;&lt;P&gt;Does anyone has already encountered this problem and the root cause ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 16:30:28 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113730#M893</guid>
      <dc:creator>Guilhem_Lejeune</dc:creator>
      <dc:date>2024-09-30T16:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - MAC to IP resolution question</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113731#M894</link>
      <description>&lt;P&gt;First you have to find more information before trying to find a root cause. "If we plugged the PC in the NACed port first, it does not work."&lt;BR /&gt;"it does not work" is not a description of problems.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What switch do you use? Is it EXOS? What does "show log" and "show netlogin session port x" give you?&lt;BR /&gt;What is seen in the NAC End-System table?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 19:35:21 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113731#M894</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2024-09-30T19:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - MAC to IP resolution question</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113740#M895</link>
      <description>&lt;P&gt;The IP address resolution is needed in the following scenarios:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Captive portal based authentication/registration/remediation&lt;/LI&gt;&lt;LI&gt;Integration with 3rd party systems require that (e.g. Firewall integration)&lt;/LI&gt;&lt;LI&gt;Posture Assessment is needed (licensed feature)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I agree the IP address resolution is not required for MAC or 802.1X authentications.&lt;/P&gt;&lt;P&gt;good luck&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 20:00:04 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113740#M895</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2024-10-01T20:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - MAC to IP resolution question</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113748#M896</link>
      <description>&lt;P&gt;It sounds like your rules are based on profiling information of the end point which does not exist until DHCP profiling is complete. &amp;nbsp;Can you post a screenshot of the rules your endpoint is hitting ?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 11:07:07 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/113748#M896</guid>
      <dc:creator>Configterminal</dc:creator>
      <dc:date>2024-10-02T11:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - MAC to IP resolution question</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/116194#M1791</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The first rule I must match is down below. It's for host authentication (username field is used).&lt;BR /&gt;Here some anonymized screenshots :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Guilhem_Lejeune_0-1729231263292.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8518i9F55F8C0397896B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Guilhem_Lejeune_0-1729231263292.png" alt="Guilhem_Lejeune_0-1729231263292.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Guilhem_Lejeune_1-1729231387250.png" style="width: 999px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8519iA5E9DBDB19B1AE3B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Guilhem_Lejeune_1-1729231387250.png" alt="Guilhem_Lejeune_1-1729231387250.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also noticed that reverse DNS lookup doesn't work well so we are working on it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For information, I'm trying to reproduce this configuration :&amp;nbsp;&lt;A href="https://community.extremenetworks.com/t5/extremecontrol/eac-domain-user-over-domain-computer/m-p/116080#M1706" target="_blank"&gt;Solved: Re: EAC - domain user over domain computer - Extreme Networks - 93807&lt;/A&gt;&amp;nbsp;because I'm exactly in the same case (PEAP with host and user authentication).&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 06:11:15 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/116194#M1791</guid>
      <dc:creator>Guilhem_Lejeune</dc:creator>
      <dc:date>2024-10-18T06:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - MAC to IP resolution question</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/116253#M1829</link>
      <description>&lt;P&gt;If the PEAP or EAP-TLS is used then you should have name of the computer in USERname. That means you should use USERgroup test. Hostname-based&amp;nbsp;end-system group requires the hostname resolution to be working.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zdenk_Pala_0-1729321786317.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8521iDEC186375878B809/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Zdenk_Pala_0-1729321786317.png" alt="Zdenk_Pala_0-1729321786317.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;if you want to check LDAP for the computer membership then you can:&lt;BR /&gt;1. define LDAP for computers:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zdenk_Pala_1-1729322016934.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8522iEE3F19B3E154FA54/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Zdenk_Pala_1-1729322016934.png" alt="Zdenk_Pala_1-1729322016934.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2. define AAA rule for computers:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zdenk_Pala_2-1729322112762.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/8523iE8946B8659F9DE37/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Zdenk_Pala_2-1729322112762.png" alt="Zdenk_Pala_2-1729322112762.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. user the user rule with memberof&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 07:15:20 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/116253#M1829</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2024-10-19T07:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - MAC to IP resolution question</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/116261#M1835</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for your reply !&lt;/P&gt;&lt;P&gt;We use &lt;STRONG&gt;802.1x PEAP MsCHAPv2&lt;/STRONG&gt; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;We have a similar configuration except for the usergroup.&lt;/P&gt;&lt;P&gt;You use an attribute value "&lt;STRONG&gt;host/*&lt;/STRONG&gt;" where we use "&lt;STRONG&gt;objectCategory&lt;/STRONG&gt;" as attribute name and "&lt;STRONG&gt;CN=[...],CN=[...],[...],DC=[...],DC=[...]&lt;/STRONG&gt;" as attribute value as shown on a previous screenshot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I made a test by clicking "&lt;STRONG&gt;Attribute Lookup...&lt;/STRONG&gt;" and by filling a existing host with the format "host/[...]".&lt;BR /&gt;I do have a positive result.&lt;/P&gt;&lt;P&gt;So I think the configuration is alright.&lt;/P&gt;&lt;P&gt;What I did not understand very well is your last sentence : "&lt;SPAN&gt;&lt;STRONG&gt;user the user rule with memberof&lt;/STRONG&gt;".&lt;BR /&gt;Could you please tell me more ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In the mean time, we are still investigating the DNS reverse resolution possible issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kind regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 18:31:20 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/116261#M1835</guid>
      <dc:creator>Guilhem_Lejeune</dc:creator>
      <dc:date>2024-10-19T18:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: ExtremeControl - MAC to IP resolution question</title>
      <link>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/116267#M1841</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The autocorrect has changed "&lt;SPAN&gt;use the user rule with memberof&lt;/SPAN&gt;" to "user...". The most common criteria is "memberOf" but "objectCategory" should work also.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the common error is that people are using end-system group instead of user group.&lt;/LI&gt;&lt;LI&gt;another common error is using the same AAA rule and the same LDAP config for user authentication and computer authentication&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I recommend checking the format of the username with the LDAP search. Also Configuration Evaluation tool can help a lot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2024 07:21:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecontrol/extremecontrol-mac-to-ip-resolution-question/m-p/116267#M1841</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2024-10-20T07:21:46Z</dc:date>
    </item>
  </channel>
</rss>

