<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Locking a device to a specific port in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48368#M12636</link>
    <description>Olaf,&lt;BR /&gt;
&lt;BR /&gt;
This is the way I thought it worked.&lt;BR /&gt;
&lt;BR /&gt;
Our customer is not concerned about what is on that port, but rather where a certain MAC is located.&lt;BR /&gt;
&lt;BR /&gt;
They want 10:20:30:40:50:ab to &lt;B&gt;only&lt;/B&gt; be able to connect to ABC MDF port 1:1.&lt;BR /&gt;
Is there a way to accomplish this in XOS on X460s and X440s? &lt;BR /&gt;
&lt;BR /&gt;
I read your reply as saying "only 10:20:30:40:50:ab can connect on ABC MDF port 1:1, but it would still be able to connect on AAB IDF port 2:2 as well"&lt;BR /&gt;
I'm I reading your reply correctly?</description>
    <pubDate>Thu, 02 Aug 2018 23:31:00 GMT</pubDate>
    <dc:creator>davidj_cogliane</dc:creator>
    <dc:date>2018-08-02T23:31:00Z</dc:date>
    <item>
      <title>Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48366#M12634</link>
      <description>We have a customer who wants to lock specific MAC addresses to specific ports as a form of location tracking.&lt;BR /&gt;
They want 10:20:30:40:50:ab to only be able to connect to ABC MDF port 1:1.&lt;BR /&gt;
Is there a way to accomplish this in XOS on X460s and X440s? &lt;BR /&gt;
&lt;BR /&gt;
Does any vendor support something like this? Not looking to sell another product, but hoping I can say the desired behavior is not an option on any vendors equipment.&lt;BR /&gt;
&lt;BR /&gt;
As I currently understand it MAC locking does not work that way. I believe it works more like the example provided below.&lt;BR /&gt;
10:20:30:40:50:ab is the only  MAC allowed on ABC MDF port 1:1&lt;BR /&gt;
&lt;BR /&gt;
    10:20:30:40:50:ab is still able  to connect to ABC IDF-1 port 2:2&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Aug 2018 20:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48366#M12634</guid>
      <dc:creator>davidj_cogliane</dc:creator>
      <dc:date>2018-08-02T20:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48367#M12635</link>
      <description>You can either use static MAC entries or use MAC locking with a lern limit of 1. Then the first seen MAC will be converted into a static entry and all further MAC addresses will be discarded.&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Aug 2018 23:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48367#M12635</guid>
      <dc:creator>AnonymousM</dc:creator>
      <dc:date>2018-08-02T23:26:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48368#M12636</link>
      <description>Olaf,&lt;BR /&gt;
&lt;BR /&gt;
This is the way I thought it worked.&lt;BR /&gt;
&lt;BR /&gt;
Our customer is not concerned about what is on that port, but rather where a certain MAC is located.&lt;BR /&gt;
&lt;BR /&gt;
They want 10:20:30:40:50:ab to &lt;B&gt;only&lt;/B&gt; be able to connect to ABC MDF port 1:1.&lt;BR /&gt;
Is there a way to accomplish this in XOS on X460s and X440s? &lt;BR /&gt;
&lt;BR /&gt;
I read your reply as saying "only 10:20:30:40:50:ab can connect on ABC MDF port 1:1, but it would still be able to connect on AAB IDF port 2:2 as well"&lt;BR /&gt;
I'm I reading your reply correctly?</description>
      <pubDate>Thu, 02 Aug 2018 23:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48368#M12636</guid>
      <dc:creator>davidj_cogliane</dc:creator>
      <dc:date>2018-08-02T23:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48369#M12637</link>
      <description>You are correct - you'd need to lock all ports to avoid that but that is not what you are looking for = other MACs should be able to connect to every port available.&lt;BR /&gt;
&lt;BR /&gt;
For how many MACs does the customer like to do that.... are we talking 10/100/1k ?</description>
      <pubDate>Thu, 02 Aug 2018 23:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48369#M12637</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-08-02T23:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48370#M12638</link>
      <description>2,500 they are trying to prevent teachers from moving phones out of the room it belongs in.  In the US they are implamenting E-911. My understanding is that the police needs to know what room or area of a building a call is coming from. As a result phone extensions are mapped to certain rooms and if the phone is on the other side of the building the police would be working with bad information.  Apparently teachers don't understand the importance of safety and can not be trusted to not move phones around. So the tech department is trying to make the phones only work on a particular port.</description>
      <pubDate>Thu, 02 Aug 2018 23:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48370#M12638</guid>
      <dc:creator>davidj_cogliane</dc:creator>
      <dc:date>2018-08-02T23:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48371#M12639</link>
      <description>So MAC-auth with NAC isn't a great idea as that would mean 2.500 rules...&lt;BR /&gt;
&lt;BR /&gt;
I don't have any experience with such service but could LLDP with ELIN work !?&lt;BR /&gt;
Not in regards to locking the port but as a E911 solution.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://documentation.extremenetworks.com/exos_commands_22.4/exos_21_1/exos_commands_all/r_configure-lldp-ports-vendorspecific-med-locationidentification.shtml" target="_blank" rel="nofollow noreferrer noopener"&gt;https://documentation.extremenetworks.com/exos_commands_22.4/exos_21_1/exos_commands_all/r_configure...&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Aug 2018 23:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48371#M12639</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-08-02T23:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48372#M12640</link>
      <description>Ronald,&lt;BR /&gt;
&lt;BR /&gt;
Thanks for the suggestion.&lt;BR /&gt;
&lt;BR /&gt;
This has led me to an interesting rabbit hole though this will not help the customer in question because they have G1 switches, it could be useful in the future.&lt;BR /&gt;
&lt;BR /&gt;
I am still trying to figure out how or even what the location gets configured on...</description>
      <pubDate>Thu, 02 Aug 2018 23:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48372#M12640</guid>
      <dc:creator>davidj_cogliane</dc:creator>
      <dc:date>2018-08-02T23:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48373#M12641</link>
      <description>My colleague pointed me to this product as it's certified with our PBX solution.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://www.redskye911.com/e911-manager" target="_blank" rel="nofollow noreferrer noopener"&gt;http://www.redskye911.com/e911-manager&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://www.redskye911.com/sites/default/files/E911ManagerDatasheet.pdf" target="_blank" rel="nofollow noreferrer noopener"&gt;http://www.redskye911.com/sites/default/files/E911ManagerDatasheet.pdf&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
As far as I unterstand you configure the ELIN on the switch port, the 911 manager has then a table e.g. ELIN#123 = 3rd floor, room#301 and then this info is tx to the 911 call center.&lt;BR /&gt;
So must of the work is done by the PBX and 911manager.</description>
      <pubDate>Thu, 02 Aug 2018 23:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48373#M12641</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-08-02T23:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48374#M12642</link>
      <description>David, the documentation is a little misleading. That command has been around since EXOS 11.5 and works on the G1 models too. The newer guides list the new G2 platforms since G1s aren't supported there.&lt;BR /&gt;
&lt;A href="https://documentation.extremenetworks.com/exos_commands_16/EXOS_16_2/exos_commands_all/r_configure-lldp-ports-vendorspecific-med-locationidentification.shtml" target="_blank" rel="nofollow noreferrer noopener"&gt;https://documentation.extremenetworks.com/exos_commands_16/EXOS_16_2/exos_commands_all/r_configure-l...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Aug 2018 23:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48374#M12642</guid>
      <dc:creator>Drew_C</dc:creator>
      <dc:date>2018-08-02T23:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48375#M12643</link>
      <description>Thanks Drew, that makes sense. &lt;BR /&gt;
&lt;BR /&gt;
I think they would still need something like Redsky to tie all the information together.</description>
      <pubDate>Thu, 02 Aug 2018 23:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48375#M12643</guid>
      <dc:creator>davidj_cogliane</dc:creator>
      <dc:date>2018-08-02T23:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48376#M12644</link>
      <description>This looks like the write answer when combined with the LLDP location advertisement.</description>
      <pubDate>Thu, 02 Aug 2018 23:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48376#M12644</guid>
      <dc:creator>davidj_cogliane</dc:creator>
      <dc:date>2018-08-02T23:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48377#M12645</link>
      <description>Hi David,&lt;BR /&gt;
&lt;BR /&gt;
This may suit the requirement but needs a lot of manual configuration, please test and see if this helps. &lt;BR /&gt;
&lt;BR /&gt;
create fdb 10:20:30:40:50:ab vlan "phone" ports 1&lt;BR /&gt;
disable learning ports 1&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://documentation.extremenetworks.com/exos_commands_22.1/exos_21_1/exos_commands_all/r_disable-learning-port.shtml" target="_blank" rel="nofollow noreferrer noopener"&gt;https://documentation.extremenetworks.com/exos_commands_22.1/exos_21_1/exos_commands_all/r_disable-l...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Aug 2018 16:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48377#M12645</guid>
      <dc:creator>Karthik_Mohando</dc:creator>
      <dc:date>2018-08-03T16:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48378#M12646</link>
      <description>That doens't prevent the user to plug the device to port#2 which is what the customer requires - right ?!&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Aug 2018 16:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48378#M12646</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-08-03T16:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48379#M12647</link>
      <description>I've tried it and that looks like it could work on the same switch = static &amp;gt; dynamic learning but what about in a network with more then 1 switch.&lt;BR /&gt;
&lt;BR /&gt;
e.g. create the static entry on switch#1 but connect the device to switch#3.&lt;BR /&gt;
In that case switch#3 uses the dynamic learned local MAC and not what was learned via the trunk to switch #1.</description>
      <pubDate>Fri, 03 Aug 2018 16:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48379#M12647</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-08-03T16:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Locking a device to a specific port</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48380#M12648</link>
      <description>In addition the below can also be very suitable for dropping all the other packets except the static fdb. &lt;BR /&gt;
disable learning drop-packets ports 1&lt;BR /&gt;
drop-packets     Drop packets with unknown source MAC addresses&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Aug 2018 16:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/locking-a-device-to-a-specific-port/m-p/48380#M12648</guid>
      <dc:creator>Karthik_Mohando</dc:creator>
      <dc:date>2018-08-03T16:55:00Z</dc:date>
    </item>
  </channel>
</rss>

