<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Extreme using radius JUST to authenticate, not for all command verification. in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51859#M14237</link>
    <description>I have a ExtremeXOS version 16.2.1.6 configured. My intention ware just authenticate my users, but I realized when a user pass any command the Extreme checks the permition. Is this normal? It is possible change this behavior? If yes how?&lt;BR /&gt;
Best regards</description>
    <pubDate>Tue, 01 Aug 2017 02:23:00 GMT</pubDate>
    <dc:creator>Kalil_De_A__Car</dc:creator>
    <dc:date>2017-08-01T02:23:00Z</dc:date>
    <item>
      <title>Extreme using radius JUST to authenticate, not for all command verification.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51859#M14237</link>
      <description>I have a ExtremeXOS version 16.2.1.6 configured. My intention ware just authenticate my users, but I realized when a user pass any command the Extreme checks the permition. Is this normal? It is possible change this behavior? If yes how?&lt;BR /&gt;
Best regards</description>
      <pubDate>Tue, 01 Aug 2017 02:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51859#M14237</guid>
      <dc:creator>Kalil_De_A__Car</dc:creator>
      <dc:date>2017-08-01T02:23:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme using radius JUST to authenticate, not for all command verification.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51860#M14238</link>
      <description>Please check the below Knowledge base article for your reference:&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/Q_A/Can-you-have-per-user-allowed-command-permissions-when-using-a-radius-server-for-authentication" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/Q_A/Can-you-have-per-user-allowed-command-permissions-when-using-a-radius-server-for-authentication&lt;/A&gt; &lt;BR /&gt;</description>
      <pubDate>Tue, 01 Aug 2017 05:38:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51860#M14238</guid>
      <dc:creator>Ram3</dc:creator>
      <dc:date>2017-08-01T05:38:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme using radius JUST to authenticate, not for all command verification.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51861#M14239</link>
      <description>Hello Ram, thanks for hoje replay.  I think that is my problem. I want just authoreze the login. After I dont want that switch check the RADIUS server all the time, when a user pass any command. If has any ccomunication problem between switch and RADIUS I loose my privilege. Is It that? Fan I chance It for not do the authenticat command alô the times?  Best regards</description>
      <pubDate>Tue, 01 Aug 2017 08:37:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51861#M14239</guid>
      <dc:creator>Kalil_De_A__Car</dc:creator>
      <dc:date>2017-08-01T08:37:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme using radius JUST to authenticate, not for all command verification.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51862#M14240</link>
      <description>Could you please explain us in detail how you are checking in RADIUS and switch that authorization is happening for any command executed? Also, please share the configuration "show configuration aaa".&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Aug 2017 09:29:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51862#M14240</guid>
      <dc:creator>Ram3</dc:creator>
      <dc:date>2017-08-01T09:29:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme using radius JUST to authenticate, not for all command verification.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51863#M14241</link>
      <description>Please take a look into this post which incl a link to screenshots of a working setup...&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://community.extremenetworks.com/extreme/topics/microsoft-nps-server-vsa-configuration-for-extreme-cliauthorization?topic-reply-list" target="_blank" rel="nofollow noreferrer noopener"&gt;https://community.extremenetworks.com/extreme/topics/microsoft-nps-server-vsa-configuration-for-extr...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Aug 2017 12:59:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51863#M14241</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2017-08-01T12:59:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme using radius JUST to authenticate, not for all command verification.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51864#M14242</link>
      <description>Hell all.&lt;BR /&gt;
&lt;BR /&gt;
Good morning Ram, here my configuration:&lt;BR /&gt;
&lt;BR /&gt;
configure radius mgmt-access primary shared-secret PASSWORD&lt;BR /&gt;
configure radius mgmt-access primary server IP_SERVER 1812 client-ip IP_CLIENT vr VR-Mgmt&lt;BR /&gt;
configure radius mgmt-access secondary shared-secret PASSWORD&lt;BR /&gt;
configure radius mgmt-access secondary server IP_SERVER 1812 client-ip IP_CLIENT vr VR-Mgmt&lt;BR /&gt;
enable radius mgmt-access&lt;BR /&gt;
&lt;BR /&gt;
We noticed that all command which user pass ware by the switchs. Like, if a user passed "show configuration" the switch send a new check for this command. The problem is if we have any problem between switch and RADIUS server the user will do nothing any more. &lt;BR /&gt;
&lt;BR /&gt;
We realized that beravior running tcpdum commands on RADIUS server. So, with that we could see this.&lt;BR /&gt;
&lt;BR /&gt;
It is possible torn off this, just let the switch check login and nothing more?&lt;BR /&gt;
&lt;BR /&gt;
Best regards.</description>
      <pubDate>Tue, 01 Aug 2017 17:59:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51864#M14242</guid>
      <dc:creator>Kalil_De_A__Car</dc:creator>
      <dc:date>2017-08-01T17:59:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme using radius JUST to authenticate, not for all command verification.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51865#M14243</link>
      <description>Could you please provide me the entire configuration of "show configuration aaa", "show switch" and "show version"? If it is an issue we need to test this in local lab. Hence, you could also open a GTAC case with "show tech" output with detailed explanation about your issue.&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Aug 2017 10:29:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51865#M14243</guid>
      <dc:creator>Ram3</dc:creator>
      <dc:date>2017-08-02T10:29:00Z</dc:date>
    </item>
    <item>
      <title>RE: Extreme using radius JUST to authenticate, not for all command verification.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51866#M14244</link>
      <description>Hello Ram.&lt;BR /&gt;
&lt;BR /&gt;
Sorry for my late. Here the information that you asked:&lt;BR /&gt;
&lt;BR /&gt;
show configuration aaa:&lt;BR /&gt;
configure radius mgmt-access primary server RADIUS_IP 1812 client-ip CLIENT_IP vr VR-Mgmt&lt;BR /&gt;
configure radius mgmt-access primary shared-secret encrypted PASSWORD&lt;BR /&gt;
configure radius mgmt-access secondary server RADIUS_IP 1812 client-ip CLIENT_IP vr VR-Mgmt&lt;BR /&gt;
configure radius mgmt-access secondary shared-secret encrypted PASSWORD&lt;BR /&gt;
enable radius mgmt-access&lt;BR /&gt;
&lt;BR /&gt;
show switch:&lt;BR /&gt;
&lt;BR /&gt;
SysName:          ampere&lt;BR /&gt;
SysLocation:      &lt;BR /&gt;
SysContact:       &lt;BR /&gt;
System MAC:       &lt;BR /&gt;
System Type:      X670-48x&lt;BR /&gt;
&lt;BR /&gt;
SysHealth check:  Enabled (Normal)&lt;BR /&gt;
Recovery Mode:    All&lt;BR /&gt;
System Watchdog:  Enabled&lt;BR /&gt;
&lt;BR /&gt;
Current Time:     Thu Aug  3 10:55:20 2017&lt;BR /&gt;
Timezone:         [Auto DST Disabled] GMT Offset: -180 minutes, name is BRT.&lt;BR /&gt;
Boot Time:        Sat Jul 22 01:21:01 2017&lt;BR /&gt;
Boot Count:       23&lt;BR /&gt;
Next Reboot:      None scheduled&lt;BR /&gt;
System UpTime:    12 days 9 hours 34 minutes 18 seconds &lt;BR /&gt;
&lt;BR /&gt;
Image Selected:   secondary               &lt;BR /&gt;
Image Booted:     secondary               &lt;BR /&gt;
Primary ver:      16.1.2.14               &lt;BR /&gt;
Secondary ver:    16.2.1.6    &lt;BR /&gt;
&lt;BR /&gt;
Config Selected:  primary.cfg                                          &lt;BR /&gt;
Config Booted:    primary.cfg                                          &lt;BR /&gt;
&lt;BR /&gt;
primary.cfg       Created by ExtremeXOS version 16.2.1.6&lt;BR /&gt;
                  1083719 bytes saved on Mon Jul 31 20:11:38 2017&lt;BR /&gt;
&lt;BR /&gt;
show version:&lt;BR /&gt;
Switch      : 800400-00-04 1151G-00686 Rev 4.0 BootROM: 2.0.1.5    IMG: 16.2.1.6  &lt;BR /&gt;
PSU-1       : Internal PSU-1 800282-00-04 1201K-82195&lt;BR /&gt;
PSU-2       : Internal PSU-2 800282-00-04 1201K-82194&lt;BR /&gt;
&lt;BR /&gt;
Image   : ExtremeXOS version 16.2.1.6 by release-manager&lt;BR /&gt;
          on Sat Aug 6 19:06:56 EDT 2016&lt;BR /&gt;
BootROM : 2.0.1.5&lt;BR /&gt;
Diagnostics : 6.4&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 03 Aug 2017 18:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/extreme-using-radius-just-to-authenticate-not-for-all-command/m-p/51866#M14244</guid>
      <dc:creator>Kalil_De_A__Car</dc:creator>
      <dc:date>2017-08-03T18:57:00Z</dc:date>
    </item>
  </channel>
</rss>

