<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using NAC to Fabric attach an ERS 4900 to an ERS 5900 in ExtremeSwitching (ERS)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71459#M125</link>
    <description>&lt;P&gt;Hello Ludovico, I hope you are well!&lt;BR /&gt;&lt;BR /&gt; Can you clarify - does&amp;nbsp; this mean that this can be used to attach any vendor’s downstream switch with multiple vlans for various services (printer, phone, pc, etc) ?&amp;nbsp; My thought is to act on the mac address of the switch to send the vlans:ISID to the ERS, which I have working, but am not understanding how to tag the ERS port.&amp;nbsp; Reading your response says to me that a printer mac in the printer vlan on the downstream switch will be put into the printer vlan on the ERS even in absence of the ERS port being tagged.&lt;/P&gt;  &lt;P&gt;Topology&lt;BR /&gt;&lt;BR /&gt; VSP --- ERS --- generic switch -- end point devices&lt;BR /&gt;&lt;BR /&gt; “ In this mode you don't care how the packet arrives on the port (tagged/untagged) (and the PVID config of the ERS port is completely irrelevant) since the authenticated source MAC automatically determines the VLAN (which was assigned to that MAC); under the bonnet it is MAC-based-VLANs. “&lt;BR /&gt;&lt;BR /&gt; PS120-4950-WC1-Stk3(config)#show vlan interface verbose 1/47&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Filter Filter&lt;BR /&gt; Unit/ Untag. Unreg.&lt;BR /&gt; Port&amp;nbsp; Frames Frames PVID VLAN VLAN Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PRI Tagging&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port Name&lt;BR /&gt; ----- ------ ------ ---- ---- ---------------- --- ------------- --------------&lt;BR /&gt; 1/47&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Yes&amp;nbsp;&amp;nbsp;&amp;nbsp; 92&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp; WiredUsers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; UntagAll&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unit 1,Port 47&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 92&amp;nbsp;&amp;nbsp; SwitchMgmt&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 96&amp;nbsp;&amp;nbsp; NewVoIP&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 112&amp;nbsp; Printers&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001 OldVoIP&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt; Thanks!&lt;BR /&gt; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jun 2020 02:00:12 GMT</pubDate>
    <dc:creator>trobinson</dc:creator>
    <dc:date>2020-06-11T02:00:12Z</dc:date>
    <item>
      <title>Using NAC to Fabric attach an ERS 4900 to an ERS 5900</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71452#M118</link>
      <description>I have ERS5900's running full fabric connect (NNI Ports) back to VSP8400''s, and I would like to use FA to connect another ERS4900 switch to an EAP enabled port.  All ports on the 5900 are EAP enabled and controlled with Extreme NAC to auto provision the VLAN:I-SID for phones (port set as untagPvidOnly with ADAC/LLDP) and clients. (port is default untagAll)&lt;BR /&gt;
&lt;BR /&gt;
When I connect the 4900 switch to a port I can use MAC auth to set the VLAN, but I cannot set the port for tagAll (or untagPvidOnly) so that VLAN's are passed through.  In XMC the policy mapping has an option for VLAN Egress: (Tagged/Untagged/Same as Ingress/User Defined) but it does not seem to change the port tagging behavior.&lt;BR /&gt;
&lt;BR /&gt;
I realize I can just change the port to be authorized and manually enable to port for tagging, but I would like to leave all ports as generic ports so we can attach the switch anywhere on the network.&lt;BR /&gt;
&lt;BR /&gt;
Thanks in advance.&lt;BR /&gt;
&lt;BR /&gt;
Terrel Hobbs&lt;BR /&gt;
Yellowknife, NT</description>
      <pubDate>Wed, 10 Apr 2019 06:22:50 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71452#M118</guid>
      <dc:creator>ExtremeNorth</dc:creator>
      <dc:date>2019-04-10T06:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Using NAC to Fabric attach an ERS 4900 to an ERS 5900</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71453#M119</link>
      <description>Hi&lt;BR /&gt;
Some of what you are trying to do is possible. But not everything..&lt;BR /&gt;
For a start the XMC Policy Egress VLAN tab will have no effect on ERS.&lt;BR /&gt;
You can however achieve the  desired ERS port config by returning these RADIUS attributes to the switch when opening the port:&lt;BR /&gt;
&lt;BR /&gt;
FA-VLAN-Create=1&lt;BR /&gt;
FA-VLAN-PVID=10&lt;BR /&gt;
FA-VLAN-ISID=10:20010&lt;BR /&gt;
FA-VLAN-ISID=20:20020&lt;BR /&gt;
FA-VLAN-ISID=30:20030&lt;BR /&gt;
&lt;BR /&gt;
This would allow NAC to create and assign all of VLANs 10,20,30 on the authorized port, where VLAN 10 is the Untagged VLAN on that port.&lt;BR /&gt;
&lt;BR /&gt;
However, the above attributes, with multiple VLANs, will only be processed if the port being authorized is in MHSA mode (Multi-Host-Single-Authentication), which requires this config on the ERS, globally:&lt;BR /&gt;
&lt;BR /&gt;
	eapol multihost auto-non-eap-mhsa-enable&lt;BR /&gt;
&lt;BR /&gt;
And at port level:&lt;BR /&gt;
&lt;BR /&gt;
	eapol multihost auto-non-eap-mhsa-enable mhsa-no-limit&lt;BR /&gt;
&lt;BR /&gt;
Which is what you need anyway, as you will be getting traffic from lots of other MACs once you've opened the port to the ERS4900 behind.&lt;BR /&gt;
The trouble is that now you have a different config for that port, which is not what you intended.&lt;BR /&gt;
There is an FA zero-touch-option which is designed to automatically set the port to MHSA based on detection of an FA client on the port:&lt;BR /&gt;
&lt;BR /&gt;
	fa zero-touch-options auto-port-mode-fa-client client-type &lt;BR /&gt;
&lt;BR /&gt;
But unfortunately it cannot be set to FA-type = FA-Proxy, which is what the ERS4900 will FA announce itself as. Might be worth an enhancement...</description>
      <pubDate>Wed, 10 Apr 2019 14:23:02 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71453#M119</guid>
      <dc:creator>Ludovico_Steven</dc:creator>
      <dc:date>2019-04-10T14:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Using NAC to Fabric attach an ERS 4900 to an ERS 5900</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71454#M120</link>
      <description>Thanks for the response Ludico.&lt;BR /&gt;
&lt;BR /&gt;
Good to know that the XMC Policy Egress has no effect; I think this would be a nice enhancement...&lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;I am sending the radius attributes, but the switch says "EAP: Pvid attribute from RADIUS ignored" when I added the FA-VLAN-PVID. 
&lt;/LI&gt;&lt;LI&gt;globally I have "eapol multihost auto-non-eap-mhsa-enable" 
&lt;/LI&gt;&lt;LI&gt;on every port I had "eapol multihost eap-mac-max 32 non-eap-mac-max 32 radius-non-eap-enable mac-max 32", and I added auto-non-eap-mhsa-enable mhsa-no-limit which does not affect it. 
&lt;/LI&gt;&lt;LI&gt;I do have "fa zero-touch-option auto-port-mode-fa-client client-type 6,8" enabled 
&lt;/LI&gt;&lt;LI&gt;I also have "fa zero-touch-client standard switch vlan xxx i-sid xxxxxx" set so it adds the WAP vlan to the port. 
&lt;/LI&gt;&lt;/UL&gt;
When I "show fa elements" the 5900 shows 4900 as Proxy, and the 4900 shows the 5900 as a Server. (since it is setup as a FC switch)   I will try sending multiple vlans when the switch authenticates, and will update my findings.&lt;BR /&gt;
&lt;BR /&gt;
Terrel.</description>
      <pubDate>Fri, 12 Apr 2019 07:01:09 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71454#M120</guid>
      <dc:creator>ExtremeNorth</dc:creator>
      <dc:date>2019-04-12T07:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Using NAC to Fabric attach an ERS 4900 to an ERS 5900</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71455#M121</link>
      <description>&lt;P&gt;As Ludo stated, both EAP command (global/port-level) solves the issue you pointed out in this thread.&lt;/P&gt;&lt;P&gt;I had the same experiences and I was looking here for a solution - and again Ludo helped again&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here are all related information as summary.&lt;/P&gt;&lt;P&gt;Port 1-12 are EAP enabled and want to assign a Vlan:I-SID (10:10012) dynamically once the device is authenticated.&lt;/P&gt;&lt;P&gt;The Radius-Return attribute is based as Ludo mentioned above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;+-------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Global:&lt;/P&gt;&lt;P&gt;eapol multihost auto-non-eap-mhsa-enable&lt;/P&gt;&lt;P&gt;Port level:&lt;/P&gt;&lt;P&gt;eapol multihost auto-non-eap-mhsa-enable mhsa-no-limit&lt;/P&gt;&lt;P&gt;+-------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;! Embedded ASCII Configuration Generator Script&lt;BR /&gt;! Model = Ethernet Routing Switch 4926GTS-PWR+&lt;BR /&gt;! Software version = v7.7.0.003&lt;BR /&gt;!&lt;BR /&gt;! Displaying only parameters different to default&lt;BR /&gt;!================================================&lt;BR /&gt;enable&lt;BR /&gt;configure terminal&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;! *** Fabric Attach ***&lt;BR /&gt;!&lt;BR /&gt;fa uplink trunk 1&lt;BR /&gt;fa timeout 45&lt;BR /&gt;fa extended-logging&lt;BR /&gt;fa zero-touch-option auto-trusted-mode-fa-client client-type 6-17&lt;BR /&gt;fa zero-touch-option auto-pvid-mode-fa-client client-type 6-17&lt;BR /&gt;fa zero-touch-option auto-mgmt-vlan-fa-client&lt;BR /&gt;fa zero-touch-option auto-client-attach&lt;BR /&gt;no fa message-authentication 1-24&lt;BR /&gt;! i-sid 10012 vlan 12 ==&amp;gt; created by FA Client&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;!&lt;BR /&gt;! *** EAP ***&lt;BR /&gt;!&lt;BR /&gt;eapol multihost radius-non-eap-enable&lt;BR /&gt;eapol multihost auto-non-eap-mhsa-enable&lt;BR /&gt;interface Ethernet ALL&lt;BR /&gt;eapol multihost port 1-12 eap-mac-max 4 allow-non-eap-enable non-eap-mac-max 4 radius-non-eap-enable auto-non-eap-mhsa-enable non-eap-phone-enable mac-max 64 mhsa-no-limit&lt;BR /&gt;exit&lt;BR /&gt;interface Ethernet ALL&lt;BR /&gt;eapol port 1-12 status auto re-authentication enable&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;FAP-2#sho vlan interface vids 3,7&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;******************************************************************************&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Command Execution Time: 2019-10-21 09:31:32 GMT+02:00&amp;nbsp;&amp;nbsp;&amp;nbsp; UTC time: 2019-10-21 07:31:32&lt;BR /&gt;&lt;BR /&gt;******************************************************************************&lt;BR /&gt;&lt;BR /&gt;Port VLAN VLAN Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN VLAN Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN VLAN Name&lt;BR /&gt;&lt;BR /&gt;---- ---- ----------------&amp;nbsp; ---- ----------------&amp;nbsp; ---- ----------------&lt;BR /&gt;&lt;BR /&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp; VLAN #12&lt;BR /&gt;&lt;BR /&gt;---- ---- ----------------&amp;nbsp; ---- ----------------&amp;nbsp; ---- ----------------&lt;BR /&gt;&lt;BR /&gt;7&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp; VLAN #12&lt;BR /&gt;&lt;BR /&gt;---- ---- ----------------&amp;nbsp; ---- ----------------&amp;nbsp; ---- ----------------&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;CODE&gt;FAP-2#sho vlan interface info&amp;nbsp; 3,7&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;******************************************************************************&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Command Execution Time: 2019-10-21 09:31:37 GMT+02:00&amp;nbsp;&amp;nbsp;&amp;nbsp; UTC time: 2019-10-21 07:31:37&lt;BR /&gt;&lt;BR /&gt;******************************************************************************&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Filter&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Filter&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Untagged Unregistered&lt;BR /&gt;&lt;BR /&gt;Port&amp;nbsp; Frames&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Frames&amp;nbsp;&amp;nbsp;&amp;nbsp; PVID PRI&amp;nbsp;&amp;nbsp;&amp;nbsp; Tagging&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&lt;BR /&gt;&lt;BR /&gt;---- -------- ------------ ---- --- ------------- ----------------&lt;BR /&gt;&lt;BR /&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; UntagPvidOnly Port 3&lt;BR /&gt;&lt;BR /&gt;7&amp;nbsp;&amp;nbsp;&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; UntagPvidOnly Port 7&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;# sho log&lt;BR /&gt;&lt;BR /&gt;I&amp;nbsp;&amp;nbsp;&amp;nbsp; 2019-10-21T09:25:43+02:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 23&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fabric Attach: binding activation success (port 7 10012/12)&lt;BR /&gt;&lt;BR /&gt;I&amp;nbsp;&amp;nbsp;&amp;nbsp; 2019-10-21T09:25:43+02:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fabric Attach: binding activation success (port 3 10012/12)&lt;BR /&gt;&lt;BR /&gt;I&amp;nbsp;&amp;nbsp;&amp;nbsp; 2019-10-21T09:25:43+02:00&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fabric Attach: binding activation success (trunk 1 10012/12)&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanx again and good luck for all the others who will run in the same “finding”&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cheers - Matthias&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2019 14:42:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71455#M121</guid>
      <dc:creator>mneumann</dc:creator>
      <dc:date>2019-10-21T14:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Using NAC to Fabric attach an ERS 4900 to an ERS 5900</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71456#M122</link>
      <description>&lt;P&gt;Me again,&lt;/P&gt;&lt;P&gt;In the meantime, I figured out that passing the value [FA-Client-Trust=1] unfortunately doesn't get any attention on the switch.&lt;/P&gt;&lt;P&gt;Now the question is, is this not supported or is the attribute wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers - Matthias&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2019 15:18:52 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71456#M122</guid>
      <dc:creator>mneumann</dc:creator>
      <dc:date>2019-10-21T15:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Using NAC to Fabric attach an ERS 4900 to an ERS 5900</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71457#M123</link>
      <description>&lt;P&gt;Coming back to Ludo’s statement:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For ERS enable globally:&lt;BR /&gt;&lt;BR /&gt;eapol multihost auto-non-eap-mhsa-enable&lt;BR /&gt;&lt;BR /&gt;And at port level:&lt;BR /&gt;&lt;BR /&gt;eapol multihost auto-non-eap-mhsa-enable mhsa-no-limit&lt;BR /&gt;&lt;BR /&gt;These commands will open the port to the ERS4900 behind, that means also unwanted devices will get access to the network, once one authenticated client on that port is authenticated successfully.&lt;/P&gt;&lt;P&gt;I guess that is not what a network administrator want and that cannot be the solution to get this automatic VLAN:I-SID assignment running?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any other way to get this running?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks - Matthias&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 13:20:32 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71457#M123</guid>
      <dc:creator>mneumann</dc:creator>
      <dc:date>2019-10-22T13:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Using NAC to Fabric attach an ERS 4900 to an ERS 5900</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71458#M124</link>
      <description>&lt;P&gt;The MHSA mode is only intended for opening ports where a wireless AP is connected, and hence, yes, it is required to open the port for all MACs associated to the AP thereafter (or as in this thread it was desired to open an ERS NAC port behind which a 2nd ERS switch is connected).&lt;/P&gt;&lt;P&gt;But MHSA is not the mode to use on ports where you have end-stations, or else it defeats the purpose of NAC.&lt;/P&gt;&lt;P&gt;For end-stations directly connected to ERS ports (PCs, phones, etc..) you don't enable MHSA on the port, and so the ERS port will work in MHMA Multi-VLAN mode.&lt;/P&gt;&lt;P&gt;In this mode you don't care how the packet arrives on the port (tagged/untagged) (and the PVID config of the ERS port is completely irrelevant) since the authenticated source MAC automatically determines the VLAN (which was assigned to that MAC); under the bonnet it is MAC-based-VLANs.&lt;/P&gt;&lt;P&gt;You might still care about untagging frames for a certain VLAN when sending packets out of the ERS port, in this case you need to also send the RFC4675 attribute in addition to the FA-VLAN-ISID (the FA-VLAN-PVID attribute will be ignored in this mode)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the&amp;nbsp; FA-Client-Trust RADIUS attribute, this is again mostly intended for ERS ports where we connect an FA Client device which has a need to do FA signalling to request additional VLAN:ISID bindings beyond the initial VLAN it got put on by NAC/RADIUS. These devices are Extreme Wireless APs or the Defender for IOT (which get their final config from a controller), or possibly some other device running Open vSwitch (OVS). All of these devices would require the MHSA mode (not MHMA!) as they will bridge additional MACs into the same ERS port.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 15:54:34 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71458#M124</guid>
      <dc:creator>Ludovico_Steven</dc:creator>
      <dc:date>2019-10-23T15:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Using NAC to Fabric attach an ERS 4900 to an ERS 5900</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71459#M125</link>
      <description>&lt;P&gt;Hello Ludovico, I hope you are well!&lt;BR /&gt;&lt;BR /&gt; Can you clarify - does&amp;nbsp; this mean that this can be used to attach any vendor’s downstream switch with multiple vlans for various services (printer, phone, pc, etc) ?&amp;nbsp; My thought is to act on the mac address of the switch to send the vlans:ISID to the ERS, which I have working, but am not understanding how to tag the ERS port.&amp;nbsp; Reading your response says to me that a printer mac in the printer vlan on the downstream switch will be put into the printer vlan on the ERS even in absence of the ERS port being tagged.&lt;/P&gt;  &lt;P&gt;Topology&lt;BR /&gt;&lt;BR /&gt; VSP --- ERS --- generic switch -- end point devices&lt;BR /&gt;&lt;BR /&gt; “ In this mode you don't care how the packet arrives on the port (tagged/untagged) (and the PVID config of the ERS port is completely irrelevant) since the authenticated source MAC automatically determines the VLAN (which was assigned to that MAC); under the bonnet it is MAC-based-VLANs. “&lt;BR /&gt;&lt;BR /&gt; PS120-4950-WC1-Stk3(config)#show vlan interface verbose 1/47&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Filter Filter&lt;BR /&gt; Unit/ Untag. Unreg.&lt;BR /&gt; Port&amp;nbsp; Frames Frames PVID VLAN VLAN Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PRI Tagging&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port Name&lt;BR /&gt; ----- ------ ------ ---- ---- ---------------- --- ------------- --------------&lt;BR /&gt; 1/47&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Yes&amp;nbsp;&amp;nbsp;&amp;nbsp; 92&amp;nbsp;&amp;nbsp; 32&amp;nbsp;&amp;nbsp; WiredUsers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; UntagAll&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unit 1,Port 47&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 92&amp;nbsp;&amp;nbsp; SwitchMgmt&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 96&amp;nbsp;&amp;nbsp; NewVoIP&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 112&amp;nbsp; Printers&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1001 OldVoIP&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt; Thanks!&lt;BR /&gt; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 02:00:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71459#M125</guid>
      <dc:creator>trobinson</dc:creator>
      <dc:date>2020-06-11T02:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Using NAC to Fabric attach an ERS 4900 to an ERS 5900</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71460#M126</link>
      <description>&lt;P&gt;Lets say your ERS receives MAC X on the port to your generic switch, and you need that MAC to be scooped into VLAN 10.&lt;/P&gt;  &lt;P&gt;When you authorize the MAC via RADIUS, you return these RADIUS attributes:&lt;/P&gt;  &lt;P&gt;&lt;CODE&gt;FA-VLAN-Create=1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # If the VLAN needs creating on the ERS&lt;/CODE&gt;&lt;/P&gt;  &lt;P&gt;&lt;CODE&gt;FA-VLAN-ISID=10:&amp;lt;I-SID&amp;gt;&lt;/CODE&gt;&lt;/P&gt;  &lt;P&gt;The above is sufficient to place ingress traffic from that MAC into VLAN 10 (I-SID whatever)&lt;/P&gt;  &lt;P&gt;The question now is how do you want to send egress traffic to that same MAC on the same port ? Tagged or Untagged ?&lt;/P&gt;  &lt;P&gt;If you want it to go out untagged, you will include this RADIUS attribute as well:&lt;/P&gt;  &lt;P&gt;&lt;CODE&gt;Egress-VLANID=0x3200000a&lt;/CODE&gt;&lt;/P&gt;  &lt;P&gt;Whereas if you want it to go out tagged:&lt;/P&gt;  &lt;P&gt;&lt;CODE&gt;Egress-VLANID=0x3100000a&lt;/CODE&gt;&lt;/P&gt;  &lt;P&gt;But in this case the egress VLAN id better match the VLAN id you authorized the same MAC into; I don’t think it will work if you try and do VLAN translation..&lt;/P&gt;  &lt;P&gt;The above attribute is defined in RFC4675; the vlan-id is the last 12 bits (hex A = 10 decimal).&lt;/P&gt;  &lt;P&gt;Again, the above attribute is only applicable to MHMA mode (not MHSA).&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2020 02:32:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/using-nac-to-fabric-attach-an-ers-4900-to-an-ers-5900/m-p/71460#M126</guid>
      <dc:creator>Ludovico_Steven</dc:creator>
      <dc:date>2020-06-27T02:32:12Z</dc:date>
    </item>
  </channel>
</rss>

