<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MHSA/MHMA automation in ExtremeSwitching (ERS)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91734#M275</link>
    <description>Fijs,&lt;BR /&gt;On ERS 4900 as from 7.9.1:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="317a318d949e4da48719d96453fbb4e1.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/954i8BA45733EF33882E/image-size/large?v=v2&amp;amp;px=999" role="button" title="317a318d949e4da48719d96453fbb4e1.png" alt="317a318d949e4da48719d96453fbb4e1.png" /&gt;&lt;/span&gt;Here for the ZTC for ERS:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="5a8eab328e4547a88eabc2e6aae0aecc.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2194i3E1ABED0ED3EFA50/image-size/large?v=v2&amp;amp;px=999" role="button" title="5a8eab328e4547a88eabc2e6aae0aecc.png" alt="5a8eab328e4547a88eabc2e6aae0aecc.png" /&gt;&lt;/span&gt;I suggest you to read the doc ConfigFabConERS49005900_7.8.1_CG.pdf&lt;BR /&gt;Mig</description>
    <pubDate>Tue, 05 Apr 2022 11:46:13 GMT</pubDate>
    <dc:creator>Miguel-Angel_RO</dc:creator>
    <dc:date>2022-04-05T11:46:13Z</dc:date>
    <item>
      <title>MHSA/MHMA automation</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91733#M274</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;We're deploying NAC in an existing network of mainly ERS49XX and ERS48XX switches.&lt;BR /&gt;&lt;BR /&gt;On these ERS switches, one needs to specify if a port needs to be in MHSA or MHMA mode.&lt;BR /&gt;&lt;BR /&gt;For example: &lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;our access points need MHSA (AP authenticates, connected clients do not since they're authenticated elsewhere)&lt;/LI&gt;
&lt;LI&gt;IP phones need MHMA: both the phone and the connected PC need to authenticate&lt;/LI&gt;
&lt;/UL&gt;
Is there a way to configure MHSA/MHMA dynamically, so can configure all access ports exactly the same, and we don't have to care where to connect AP's or phones?&lt;BR /&gt;&lt;BR /&gt;Thanks!</description>
      <pubDate>Mon, 04 Apr 2022 13:07:08 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91733#M274</guid>
      <dc:creator>Fijs</dc:creator>
      <dc:date>2022-04-04T13:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: MHSA/MHMA automation</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91734#M275</link>
      <description>Fijs,&lt;BR /&gt;On ERS 4900 as from 7.9.1:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="317a318d949e4da48719d96453fbb4e1.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/954i8BA45733EF33882E/image-size/large?v=v2&amp;amp;px=999" role="button" title="317a318d949e4da48719d96453fbb4e1.png" alt="317a318d949e4da48719d96453fbb4e1.png" /&gt;&lt;/span&gt;Here for the ZTC for ERS:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="5a8eab328e4547a88eabc2e6aae0aecc.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2194i3E1ABED0ED3EFA50/image-size/large?v=v2&amp;amp;px=999" role="button" title="5a8eab328e4547a88eabc2e6aae0aecc.png" alt="5a8eab328e4547a88eabc2e6aae0aecc.png" /&gt;&lt;/span&gt;I suggest you to read the doc ConfigFabConERS49005900_7.8.1_CG.pdf&lt;BR /&gt;Mig</description>
      <pubDate>Tue, 05 Apr 2022 11:46:13 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91734#M275</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2022-04-05T11:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: MHSA/MHMA automation</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91735#M276</link>
      <description>Thanks Mig! I'll give it a try.</description>
      <pubDate>Tue, 05 Apr 2022 15:39:27 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91735#M276</guid>
      <dc:creator>Fijs</dc:creator>
      <dc:date>2022-04-05T15:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: MHSA/MHMA automation</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91736#M277</link>
      <description>So the answer above from Miguel is correct; as of 7.9.1 release you can now enable MHSA on the port via a RADIUS attribute (the same that VOSS uses).&lt;BR /&gt;However, for completeness, there is also the "old" ERS approach which is still possible, which is based around FA zero-touch-options.&lt;BR /&gt;If you enable this command for FA Client type 6 = (WAP-type1):&lt;BR /&gt;&lt;STRONG&gt;fa zero-touch-option auto-port-mode-fa-client client-type 6&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;B&gt;auto-port-mode-fa-client&lt;/B&gt;: When this option is activated for certain FA Client types, whenever an FA client of that type is discovered on an access port, the access port is automatically pre-configured for EAP/NEAP in mode Multiple-Hosts-Single-Authentication (MHSA). The FA Client will thus need to authenticate against a RADIUS server using either EAPoL or RADIUS MAC-based authentication (NEAP).&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 06 Apr 2022 16:28:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91736#M277</guid>
      <dc:creator>Ludovico_Steven</dc:creator>
      <dc:date>2022-04-06T16:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: MHSA/MHMA automation</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91737#M278</link>
      <description>Got this unicast question:&lt;EM&gt; is this implemented also on the latest firmware for the ERS48xx series?&lt;/EM&gt;&lt;BR /&gt;Replying on thread for everyone's benefit.&lt;BR /&gt;So the &lt;STRONG&gt;fa zero-touch-option auto-port-mode-fa-client client-type 6 &lt;/STRONG&gt;is also available on ERS4800.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Whereas the new MHSA RADIUS attribute support is only on ERS5900/4900 &amp;amp; 3600:&lt;BR /&gt;&lt;BR /&gt;
&lt;DIV id="ers5900" class="list" style="display: block;"&gt;&lt;B class="product"&gt;ERS5900&lt;/B&gt;
&lt;PRE&gt;7.9.1	SW	Extreme Dynamic MHSA RADIUS vendor specific attribute (VSA) Extreme-Dynamic-MHSA (vendor ID 1916 value 250)&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;DIV id="ers4900" class="list" style="display: block;"&gt;&lt;B class="product"&gt;ERS4900&lt;/B&gt;
&lt;PRE&gt;7.9.1	SW	Extreme Dynamic MHSA RADIUS vendor specific attribute (VSA) Extreme-Dynamic-MHSA (vendor ID 1916 value 250)&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;DIV id="ers3600" class="list" style="display: block;"&gt;&lt;B class="product"&gt;ERS3600&lt;/B&gt;
&lt;PRE&gt;6.5.3	SW	Extreme Dynamic MHSA RADIUS vendor specific attribute (VSA) Extreme-Dynamic-MHSA (vendor ID 1916 value 250)&lt;/PRE&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Apr 2022 13:43:32 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91737#M278</guid>
      <dc:creator>Ludovico_Steven</dc:creator>
      <dc:date>2022-04-11T13:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: MHSA/MHMA automation</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91738#M279</link>
      <description>Unfortunately the AP's in this case are not Extreme AP's.&lt;BR /&gt;So for the 49XX, an upgrade will do the trick.&lt;BR /&gt;For the 48XX, we'll have to manually change to MHSA for AP ports.</description>
      <pubDate>Mon, 11 Apr 2022 17:42:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91738#M279</guid>
      <dc:creator>Fijs</dc:creator>
      <dc:date>2022-04-11T17:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: MHSA/MHMA automation</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91739#M280</link>
      <description>Ah, yes, good point. Both approaches work with Extreme APs (Fabric Attach enabled) but if you have non-Extreme WLAN APs then you need the RADIUS MHSA attribute... or you do manual config...or even better you use Extreme WLAN !</description>
      <pubDate>Mon, 11 Apr 2022 19:26:34 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/mhsa-mhma-automation/m-p/91739#M280</guid>
      <dc:creator>Ludovico_Steven</dc:creator>
      <dc:date>2022-04-11T19:26:34Z</dc:date>
    </item>
  </channel>
</rss>

