<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: question on MAC auth using windows NPS in ExtremeSwitching (ERS)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118762#M606</link>
    <description>&lt;P&gt;here is the config, not sure why it's seperated into multiple lines, it should apply to all ports from 2-48 since port1 is the trunk.&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;! *** EAP ***&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost allow-non-eap-enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost radius-non-eap-enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost use-radius-assigned-vlan&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost non-eap-use-radius-assigned-vlan&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;interface Ethernet ALL&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 2-14 enable eap-mac-max 2 allow-non-eap-enable non-eap-mac&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;-max 2 radius-non-eap-enable use-radius-assigned-vlan non-eap-use-radius-assign&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ed-vlan mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 15 enable eap-mac-max 2 allow-non-eap-enable non-eap-mac-m&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ax 2 radius-non-eap-enable non-eap-phone-enable use-radius-assigned-vlan non-ea&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;p-use-radius-assigned-vlan mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 16-34 enable eap-mac-max 2 allow-non-eap-enable non-eap-ma&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;c-max 2 radius-non-eap-enable use-radius-assigned-vlan non-eap-use-radius-assig&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ned-vlan mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 35 enable eap-mac-max 2 allow-non-eap-enable non-eap-mac-m&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ax 2 radius-non-eap-enable non-eap-phone-enable use-radius-assigned-vlan non-ea&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;p-use-radius-assigned-vlan mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 36-48 enable eap-mac-max 2 allow-non-eap-enable non-eap-ma&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;c-max 2 radius-non-eap-enable use-radius-assigned-vlan non-eap-use-radius-assig&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ned-vlan mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 49-50 mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;no eapol multihost port 1&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;eap-protocol-enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;exit&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;interface Ethernet ALL&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol port 2-48 status auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;exit&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;! *** EAP Guest VLAN ***&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol guest-vlan enable vid 2204&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;! *** EAP Fail Open VLAN ***&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;! *** EAP Voip VLAN ***&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 May 2025 19:16:24 GMT</pubDate>
    <dc:creator>kitkat0981</dc:creator>
    <dc:date>2025-05-21T19:16:24Z</dc:date>
    <item>
      <title>question on MAC auth using windows NPS</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118708#M597</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;new when it comes to Avaya/Extreme. I have a ERS 4850GTS in my lab and trying to see how MAC auth using Windows NPS works in order to assign the port a specific vlan based on MAC manufacture OUI and Windows user laptops enables with 802.1x authentication. Is this even possible on theses switches? (running base software 5.8.0.3).&lt;/P&gt;&lt;P&gt;The purpose is to assign vlan 10 to non wuthenticated windows PC, vlan 15 to authenticated windows and vlan 20 to IOT's like printers and possibly other vlans for other purposes with the default vlan 2 as a quarantined initial vlan.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 17:53:26 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118708#M597</guid>
      <dc:creator>kitkat0981</dc:creator>
      <dc:date>2025-05-13T17:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: question on MAC auth using windows NPS</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118724#M598</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It is possible using MultiHost MultiVlan, after&amp;nbsp;configure RADIUS server:&lt;/P&gt;&lt;P&gt;eapol enable&lt;BR /&gt;eapol multihost allow-non-eap-enable&lt;BR /&gt;eapol multihost use-radius-assigned-vlan&lt;BR /&gt;eapol multihost non-eap-use-radius-assigned-vlan&lt;BR /&gt;eapol multihost multivlan enable&lt;BR /&gt;eapol multihost non-eap-pwd-fmt show&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;interface Ethernet ALL&lt;BR /&gt;eapol multihost port 1/ALL enable eap-mac-max 2 allow-non-eap-enable non-eap-mac-max 2 radius-non-eap-enable use-radius-assigned-vlan non-eap-use-radius-assigned-vlan mac-max 2&lt;BR /&gt;eapol status auto&lt;/P&gt;&lt;P&gt;If you got EAP and NON-EAP clients maybe and it's useful delay MAC auth to avoid unnessesary MAC auth from EAP clients:&lt;/P&gt;&lt;P&gt;eapol multihost radius-non-eap-delay &amp;lt;0-20&amp;gt;&lt;/P&gt;&lt;P&gt;About "to assign vlan 10 to non wuthenticated windows PC" maybe you can use "guest vlan" feature but I dont like much, cable for enterprise devices and wifi guest for...guests.&lt;/P&gt;&lt;P&gt;Cheers!!&lt;/P&gt;&lt;P&gt;EF&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 10:41:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118724#M598</guid>
      <dc:creator>EF</dc:creator>
      <dc:date>2025-05-15T10:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: question on MAC auth using windows NPS</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118731#M599</link>
      <description>&lt;P&gt;thanks for the reponse, i will try that.&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 12:25:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118731#M599</guid>
      <dc:creator>kitkat0981</dc:creator>
      <dc:date>2025-05-15T12:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: question on MAC auth using windows NPS</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118732#M600</link>
      <description>&lt;P&gt;Sorry "&lt;SPAN&gt;eapol multihost non-eap-pwd-fmt show&lt;/SPAN&gt;" is "&lt;SPAN&gt;eapol multihost non-eap-pwd-fmt mac-addr&lt;/SPAN&gt;"&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 12:31:21 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118732#M600</guid>
      <dc:creator>EF</dc:creator>
      <dc:date>2025-05-15T12:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: question on MAC auth using windows NPS</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118753#M602</link>
      <description>&lt;P&gt;so how would this differ if what I need is when a user logs into the device (windows PC) he gets put on a specific VLAN?&amp;nbsp; The VLAN comes from the Radius correct?&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 14:43:41 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118753#M602</guid>
      <dc:creator>kitkat0981</dc:creator>
      <dc:date>2025-05-20T14:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: question on MAC auth using windows NPS</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118756#M603</link>
      <description>&lt;P&gt;Hi, this is the config in the SW to enable EAPOL with multiple host multiple VLANs for EAPOL and NONEAPOL clients, then you must configure the RADIUS with the policies and returned atributes, for example VLANs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 11:48:41 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118756#M603</guid>
      <dc:creator>EF</dc:creator>
      <dc:date>2025-05-21T11:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: question on MAC auth using windows NPS</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118757#M604</link>
      <description>&lt;P&gt;so I received more info; there is Avaya IP Phones and some users connect behind the phone and some users connect directly to a switchport.&lt;/P&gt;&lt;P&gt;How would this work in order to differentiate a phone to any other device on a port? as well as detecting the device that is connected behind the phone?&lt;/P&gt;&lt;P&gt;EAP would be configured for devices that support EAP like Windows Laptops and Chromebooks correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 14:32:05 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118757#M604</guid>
      <dc:creator>kitkat0981</dc:creator>
      <dc:date>2025-05-21T14:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: question on MAC auth using windows NPS</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118761#M605</link>
      <description>&lt;P&gt;so I added this configuration and it locked me out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;i guess it's because my port #1 is the trunk, so eap should not be setup on that port, but I don't know how to NOT include it.&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 18:50:13 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118761#M605</guid>
      <dc:creator>kitkat0981</dc:creator>
      <dc:date>2025-05-21T18:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: question on MAC auth using windows NPS</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118762#M606</link>
      <description>&lt;P&gt;here is the config, not sure why it's seperated into multiple lines, it should apply to all ports from 2-48 since port1 is the trunk.&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;! *** EAP ***&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost allow-non-eap-enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost radius-non-eap-enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost use-radius-assigned-vlan&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost non-eap-use-radius-assigned-vlan&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;interface Ethernet ALL&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 2-14 enable eap-mac-max 2 allow-non-eap-enable non-eap-mac&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;-max 2 radius-non-eap-enable use-radius-assigned-vlan non-eap-use-radius-assign&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ed-vlan mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 15 enable eap-mac-max 2 allow-non-eap-enable non-eap-mac-m&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ax 2 radius-non-eap-enable non-eap-phone-enable use-radius-assigned-vlan non-ea&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;p-use-radius-assigned-vlan mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 16-34 enable eap-mac-max 2 allow-non-eap-enable non-eap-ma&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;c-max 2 radius-non-eap-enable use-radius-assigned-vlan non-eap-use-radius-assig&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ned-vlan mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 35 enable eap-mac-max 2 allow-non-eap-enable non-eap-mac-m&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ax 2 radius-non-eap-enable non-eap-phone-enable use-radius-assigned-vlan non-ea&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;p-use-radius-assigned-vlan mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 36-48 enable eap-mac-max 2 allow-non-eap-enable non-eap-ma&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;c-max 2 radius-non-eap-enable use-radius-assigned-vlan non-eap-use-radius-assig&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ned-vlan mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol multihost port 49-50 mac-max 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;no eapol multihost port 1&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;eap-protocol-enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;exit&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;interface Ethernet ALL&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol port 2-48 status auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;exit&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;! *** EAP Guest VLAN ***&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol guest-vlan enable vid 2204&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;! *** EAP Fail Open VLAN ***&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;! *** EAP Voip VLAN ***&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;eapol enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 19:16:24 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-ers/question-on-mac-auth-using-windows-nps/m-p/118762#M606</guid>
      <dc:creator>kitkat0981</dc:creator>
      <dc:date>2025-05-21T19:16:24Z</dc:date>
    </item>
  </channel>
</rss>

