<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: NAC: Avoid that end-systems aging out in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44247#M10807</link>
    <description>Hi Ronald,&lt;BR /&gt;
&lt;BR /&gt;
no, the rules aren't the problem.&lt;BR /&gt;
If a existing permitted device which netlogin passed access doesn't generate a event for more than 90 days, the end system is deleted from all connected end-system groups.&lt;BR /&gt;
In addition the port will be reauthenticated and so the access will be denied</description>
    <pubDate>Fri, 10 Feb 2017 21:58:00 GMT</pubDate>
    <dc:creator>Chacko</dc:creator>
    <dc:date>2017-02-10T21:58:00Z</dc:date>
    <item>
      <title>NAC: Avoid that end-systems aging out</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44245#M10805</link>
      <description>In NAC-Manager, there is a setting via "Options" -&amp;gt; "NAC Manager" -&amp;gt; "Data Persistence" -&amp;gt; "Age end-systems older than XX days" (our setting is at 90 Days per default).&lt;BR /&gt;
The problem is, that we have a few systems, running more than 90 days without any network-related events that are generated.&lt;BR /&gt;
&lt;BR /&gt;
So for example a time-registration terminal will be disconnected after three month and is rejected from the network until a new import of the MAC is being triggered.&lt;BR /&gt;
&lt;BR /&gt;
Is there a way to disable this setting or to exclùde specific end-system groups from it?</description>
      <pubDate>Fri, 10 Feb 2017 21:40:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44245#M10805</guid>
      <dc:creator>Chacko</dc:creator>
      <dc:date>2017-02-10T21:40:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC: Avoid that end-systems aging out</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44246#M10806</link>
      <description>How about a end-system group with the MACs that you'd like to allow.&lt;BR /&gt;
Then copy the rule that you've used before and link it to that group - move the new rule on top of the other.&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="13501fa9dbaa4c2083b7bc4600771c4d_RackMultipart20170210-53932-qf4dmz-NAC_endsys_group_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/49i9A94BCEEDA40F537/image-size/large?v=v2&amp;amp;px=999" role="button" title="13501fa9dbaa4c2083b7bc4600771c4d_RackMultipart20170210-53932-qf4dmz-NAC_endsys_group_inline.png" alt="13501fa9dbaa4c2083b7bc4600771c4d_RackMultipart20170210-53932-qf4dmz-NAC_endsys_group_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 10 Feb 2017 21:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44246#M10806</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2017-02-10T21:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC: Avoid that end-systems aging out</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44247#M10807</link>
      <description>Hi Ronald,&lt;BR /&gt;
&lt;BR /&gt;
no, the rules aren't the problem.&lt;BR /&gt;
If a existing permitted device which netlogin passed access doesn't generate a event for more than 90 days, the end system is deleted from all connected end-system groups.&lt;BR /&gt;
In addition the port will be reauthenticated and so the access will be denied</description>
      <pubDate>Fri, 10 Feb 2017 21:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44247#M10807</guid>
      <dc:creator>Chacko</dc:creator>
      <dc:date>2017-02-10T21:58:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC: Avoid that end-systems aging out</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44248#M10808</link>
      <description>In NAC Manager go tools --&amp;gt; Options --&amp;gt; Data Persistence. &lt;BR /&gt;
&lt;BR /&gt;
You can set the timer to 0, however this means that every end system that attaches to the system will never be purged, so eventually you'll end up with a large amount of old end systems. &lt;BR /&gt;
&lt;BR /&gt;
What you can do is as Roland has said put these special end system into a group and make sure the option to "Remove Associated MAC locks and Occurrences in Groups" is NOT checked. &lt;BR /&gt;
&lt;BR /&gt;
Once the end system ages out and re-authenticates it should authenticate back into it's end system group rule as the option to remove has been disabled. &lt;BR /&gt;
&lt;BR /&gt;
Also, if you can get RADIUS accounting, or a DHCP packet from these devices it'll reset the last seen time and they'll never age out.&lt;BR /&gt;
&lt;BR /&gt;
You can also set a session timeout or re-authentication timer on the port to have the device re-authenticate after a period of time, resetting the last seem timer so these devices don't age out either.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
-Ryan</description>
      <pubDate>Mon, 13 Feb 2017 03:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44248#M10808</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2017-02-13T03:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC: Avoid that end-systems aging out</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44249#M10809</link>
      <description>Dear Ryan,&lt;BR /&gt;
&lt;BR /&gt;
thanks for the feedback.&lt;BR /&gt;
I never thought about the reauthentication - but now that you mention it, it seems to be a good idea.&lt;BR /&gt;
I think we will set the reauth-timer to 1 month and give that a try.&lt;BR /&gt;
&lt;BR /&gt;
Many thanks </description>
      <pubDate>Mon, 13 Feb 2017 14:59:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/nac-avoid-that-end-systems-aging-out/m-p/44249#M10809</guid>
      <dc:creator>Chacko</dc:creator>
      <dc:date>2017-02-13T14:59:00Z</dc:date>
    </item>
  </channel>
</rss>

