<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Multisession on single port problem in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57993#M17189</link>
    <description>Hello Marek,&lt;BR /&gt;
&lt;BR /&gt;
now your problem. It seems you used commands from both concepts. But your configuration&lt;BR /&gt;
works. You see the session.&lt;BR /&gt;
&lt;BR /&gt;
The missing ip in EAC is something totally different. After a successfull authentication&lt;BR /&gt;
the EAC waits 10 second to start the resolving process. If it fails it waits 60 seconds, tries&lt;BR /&gt;
again, waits 60 seconds and tries again. So after 2:10 it stopps the process and you&lt;BR /&gt;
get 'ip resulution failed'.&lt;BR /&gt;
&lt;BR /&gt;
There are about 5 ways to fix this:&lt;BR /&gt;
&lt;OL&gt; 
&lt;LI&gt;update to EXOS 22.2 and EMC/EAC 7.1 and enable nodealias 
&lt;/LI&gt;&lt;LI&gt;forward dhcp packet from every router in every vlan to one or two EACE 
&lt;/LI&gt;&lt;LI&gt;configure an ip address in every vlan in the switch 
&lt;/LI&gt;&lt;LI&gt;tell EAC the default gateway for the vlan/switch combination 
&lt;/LI&gt;&lt;LI&gt;...&lt;/LI&gt;&lt;/OL&gt;1 works always, 2 only with dhcp clients, 3 should work, 4 works only with one vlan&lt;BR /&gt;
per switch, ....&lt;BR /&gt;
&lt;BR /&gt;
In your case turn off the printer, plug it into the mini switch, and turn it on again. It&lt;BR /&gt;
should work. If not enable endsystem diagnostics in the EACE.&lt;BR /&gt;
&lt;BR /&gt;
See Extreme Access Control course for more information...&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Sat, 18 Mar 2017 04:36:00 GMT</pubDate>
    <dc:creator>Patrick_Koppen</dc:creator>
    <dc:date>2017-03-18T04:36:00Z</dc:date>
    <item>
      <title>Multisession on single port problem</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57986#M17182</link>
      <description>Hi &lt;BR /&gt;
&lt;BR /&gt;
i have problem to assing IP to MAC based authentication (printer) on a x440 single port.&lt;BR /&gt;
situation looks like below:&lt;BR /&gt;
&lt;BR /&gt;
computer---&lt;BR /&gt;
computer--- desktop switch ----- x440 switch single port&lt;BR /&gt;
printer-------&lt;BR /&gt;
&lt;BR /&gt;
all dot1x sesions (users) are accepted and works fine but MAC session is not.&lt;BR /&gt;
&lt;BR /&gt;
Port                          : 43&lt;BR /&gt;
Authentication                : 802.1x, mac-based&lt;BR /&gt;
Port State                    : Enabled&lt;BR /&gt;
Authentication Mode           : Required (Policy Enabled only)&lt;BR /&gt;
Max Supported Users           : 256 (Policy Enabled only)&lt;BR /&gt;
Allowed Users                 : 128 (Policy Enabled only)&lt;BR /&gt;
Current Users                 : 3 (Policy Enabled only)&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
        802.1x Port Configuration&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
Quiet Period                  : 300&lt;BR /&gt;
Supplicant Response Timeout   : 120&lt;BR /&gt;
Re-authentication             : On&lt;BR /&gt;
Re-authentication period      : 0&lt;BR /&gt;
Max Re-authentications        : 3&lt;BR /&gt;
RADIUS server timeout         : 120&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
        MAC Mode Port Configuration&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
Re-authentication period      : 7200&lt;BR /&gt;
Re-authentication             : On&lt;BR /&gt;
Authentication Delay          : 120 seconds&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
        Netlogin Clients&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
&lt;BR /&gt;
MAC                IP address       Authenticated     Type    ReAuth-Timer   User&lt;BR /&gt;
00:0f:fe:xx:xx:xx  0.0.0.0          Yes, Radius       802.1x  0              user &lt;BR /&gt;
00:23:7d:xx:xx:xx  0.0.0.0          Yes, Radius       MAC     4385           00-23-7D-XX-XX-XX&lt;BR /&gt;
94??80:xx:xx:xx  0.0.0.0          Yes, Radius       802.1x  0              user&lt;BR /&gt;
-----------------------------------------------&lt;BR /&gt;
(B) - Client entry Blackholed in FDB&lt;BR /&gt;
&lt;BR /&gt;
On NAC manager i see that user (dot1x) sesions are resolving ip addresses using radius server which is visible in request (in table), but mac sessions are not.&lt;BR /&gt;
&lt;BR /&gt;
when i switch printer direct to x440 port, all works fine.&lt;BR /&gt;
&lt;BR /&gt;
Please help &lt;BR /&gt;
&lt;BR /&gt;
Regards Mark &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 15 Mar 2017 18:38:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57986#M17182</guid>
      <dc:creator>MarekorMark</dc:creator>
      <dc:date>2017-03-15T18:38:00Z</dc:date>
    </item>
    <item>
      <title>RE: Multisession on single port problem</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57987#M17183</link>
      <description>anybody ?&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Mar 2017 00:56:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57987#M17183</guid>
      <dc:creator>MarekorMark</dc:creator>
      <dc:date>2017-03-16T00:56:00Z</dc:date>
    </item>
    <item>
      <title>RE: Multisession on single port problem</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57988#M17184</link>
      <description>Maybe you could post some more information... &lt;BR /&gt;
 Software version, show config netlogin, show config policy and show config aaa &lt;BR /&gt;
&lt;BR /&gt;
 Does it work if you only attach the printer behind the switch?&lt;BR /&gt;
It could be a maximum user limit on the port? &lt;BR /&gt;
 Does the mac shows up in the fdb?&lt;BR /&gt;
Did you enable logging?&lt;BR /&gt;
What happend if you connect the printer (with logging enabled)?</description>
      <pubDate>Thu, 16 Mar 2017 03:24:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57988#M17184</guid>
      <dc:creator>Patrick_Koppen</dc:creator>
      <dc:date>2017-03-16T03:24:00Z</dc:date>
    </item>
    <item>
      <title>RE: Multisession on single port problem</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57989#M17185</link>
      <description>so  this is what i've got:&lt;BR /&gt;
&lt;BR /&gt;
show switch&lt;BR /&gt;
SysName:          LOL&lt;BR /&gt;
SysLocation:      LOL&lt;BR /&gt;
SysContact:       Marek Konopinski&lt;BR /&gt;
System MAC:       00:04:96:XX:XX:XX&lt;BR /&gt;
System Type:      X440G2-48t-10G4&lt;BR /&gt;
&lt;BR /&gt;
Current State:    OPERATIONAL&lt;BR /&gt;
Image Selected:   primary&lt;BR /&gt;
Image Booted:     primary&lt;BR /&gt;
Primary ver:      21.1.1.4&lt;BR /&gt;
                  patch1-3&lt;BR /&gt;
Secondary ver:    21.1.1.4&lt;BR /&gt;
&lt;BR /&gt;
Config Selected:  primary.cfg&lt;BR /&gt;
Config Booted:    Factory Default&lt;BR /&gt;
&lt;BR /&gt;
primary.cfg       Created by ExtremeXOS version 21.1.1.4&lt;BR /&gt;
                  1225234 bytes saved on Thu Mar 16 09:39:51 2017&lt;BR /&gt;
&lt;BR /&gt;
show version&lt;BR /&gt;
Switch      : 800617-00-09 1634N-40777 Rev 9.0 BootROM: 1.0.1.8    IMG: 21.1.1.4&lt;BR /&gt;
PSU-1       : Internal Power Supply&lt;BR /&gt;
PSU-2       :&lt;BR /&gt;
&lt;BR /&gt;
Image   : ExtremeXOS version 21.1.1.4 21.1.1.4-patch1-3 by release-manager&lt;BR /&gt;
          on Wed May 4 16:47:32 EDT 2016&lt;BR /&gt;
BootROM : 1.0.1.8&lt;BR /&gt;
Diagnostics : 5.4&lt;BR /&gt;
&lt;BR /&gt;
NETLOGIN conf&lt;BR /&gt;
&lt;BR /&gt;
enable netlogin dot1x mac&lt;BR /&gt;
configure netlogin mac authentication database-order radius&lt;BR /&gt;
configure netlogin authentication protocol-order dot1x mac web-based&lt;BR /&gt;
configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48&lt;BR /&gt;
enable netlogin ports 1-46 dot1x&lt;BR /&gt;
enable netlogin ports 1-46 mac&lt;BR /&gt;
configure netlogin dot1x ports 1-46 timers quiet-period 5&lt;BR /&gt;
&lt;BR /&gt;
configure netlogin dot1x ports 47 timers reauth-period 30 reauth-max 4 - uplink (interswitch)&lt;BR /&gt;
configure netlogin dot1x ports 48 timers reauth-period 30 reauth-max 4 - uplink (interswitch)&lt;BR /&gt;
enable netlogin reauthenticate-on-refresh&lt;BR /&gt;
configure netlogin session-refresh 30&lt;BR /&gt;
configure netlogin allowed-refresh-failures 5&lt;BR /&gt;
configure netlogin mac ports 1 timers reauthentication on&lt;BR /&gt;
&lt;BR /&gt;
configure netlogin idle-timeout dot1x 0&lt;BR /&gt;
configure netlogin idle-timeout web-based 0&lt;BR /&gt;
configure netlogin idle-timeout mac 0&lt;BR /&gt;
configure netlogin port 47 authentication mode optional&lt;BR /&gt;
configure netlogin port 48 authentication mode optional&lt;BR /&gt;
&lt;BR /&gt;
OTHER conf&lt;BR /&gt;
&lt;BR /&gt;
enable radius&lt;BR /&gt;
enable radius mgmt-access&lt;BR /&gt;
enable radius netlogin&lt;BR /&gt;
enable radius-accounting&lt;BR /&gt;
enable radius-accounting mgmt-access&lt;BR /&gt;
enable radius-accounting netlogin&lt;BR /&gt;
enable log target syslog "IP":514 vr VR-Mgmt local4&lt;BR /&gt;
enable log target syslog "IP":514 vr VR-Default local4&lt;BR /&gt;
enable ssh2&lt;BR /&gt;
enable netlogin dot1x mac&lt;BR /&gt;
enable netlogin ports 1-46 dot1x&lt;BR /&gt;
enable netlogin ports 1-46 mac&lt;BR /&gt;
enable netlogin reauthenticate-on-refresh&lt;BR /&gt;
enable stpd s0&lt;BR /&gt;
&lt;BR /&gt;
Also i &lt;B&gt;&lt;U&gt;can not&lt;/U&gt;&lt;/B&gt; enable one option:&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;configure netlogin port (port number/range) mode mac-based-vlans&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
becouse after &lt;B&gt;﻿port (port number/range) &lt;/B&gt;﻿there is no "&lt;B&gt;﻿mode&lt;/B&gt;﻿" option&lt;BR /&gt;
&lt;BR /&gt;
regards&lt;BR /&gt;
Marek</description>
      <pubDate>Fri, 17 Mar 2017 12:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57989#M17185</guid>
      <dc:creator>MarekorMark</dc:creator>
      <dc:date>2017-03-17T12:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Multisession on single port problem</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57990#M17186</link>
      <description>Please check this article for your reference:&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-Mac-based-Netlogin-with-Radius" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-Mac-based-Netlogin-with-R...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Mar 2017 12:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57990#M17186</guid>
      <dc:creator>Ram3</dc:creator>
      <dc:date>2017-03-17T12:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Multisession on single port problem</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57991#M17187</link>
      <description>it aint that... i read it already but  my problem is different&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Mar 2017 12:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57991#M17187</guid>
      <dc:creator>MarekorMark</dc:creator>
      <dc:date>2017-03-17T12:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: Multisession on single port problem</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57992#M17188</link>
      <description>Hello Marek,&lt;BR /&gt;
&lt;BR /&gt;
you have a G2 with software &amp;gt;=21 so you can choose between to different&lt;BR /&gt;
versions of netlogin. The old one from EXOS or the even older one from EOS&lt;BR /&gt;
which is implemented in version 16 and 21 on G2 hardware.&lt;BR /&gt;
&lt;BR /&gt;
The EXOS can do dot1x and mac auth with multiple host one the same port.&lt;BR /&gt;
There's single vlan and a multi vlan model. It's configured like this:&lt;BR /&gt;
&lt;BR /&gt;
!aaa&lt;BR /&gt;
configure radius primary server 10.0.0.1 client-ip 10.1.1.2 vr "VR-Default" shared-secret geheim&lt;BR /&gt;
enable radius netlogin&lt;BR /&gt;
&lt;BR /&gt;
!create a dummy vlan and attach it do the netlogin process&lt;BR /&gt;
create vlan ZNETLOGIN_DUMMY&lt;BR /&gt;
configure netlogin vlan "ZNETLOGIN_DUMMY"&lt;BR /&gt;
&lt;BR /&gt;
!enable netlogin globally&lt;BR /&gt;
enable netlogin mac dot1x&lt;BR /&gt;
&lt;BR /&gt;
!enable netlogin per port&lt;BR /&gt;
enable netlogin port 5 mac dot1x&lt;BR /&gt;
&lt;BR /&gt;
!do mac-auth for all mac-addresses&lt;BR /&gt;
configure netlogin add mac-list default&lt;BR /&gt;
&lt;BR /&gt;
!test it and look for sessions:&lt;BR /&gt;
show netlogin [port 5]And the new (EOS) way....&lt;BR /&gt;
&lt;BR /&gt;
!switch to policy mode (this make the world great again!)&lt;BR /&gt;
enable policy&lt;BR /&gt;
&lt;BR /&gt;
!mode optional on all ports&lt;BR /&gt;
configure netlogin ports all authentication mode optional&lt;BR /&gt;
&lt;BR /&gt;
!enable netlogin globally and per port&lt;BR /&gt;
enable netlogin mac dot1x&lt;BR /&gt;
enable netlogin por 5 mac dot1x&lt;BR /&gt;
&lt;BR /&gt;
!do mac-auth for all mac-addresses&lt;BR /&gt;
configure netlogin add mac-list default&lt;BR /&gt;
&lt;BR /&gt;
!test it and look for sessions:&lt;BR /&gt;
show netlogin sessionsclassic netlogin vs. policy mode:&lt;BR /&gt;
&lt;BR /&gt;
In policy mode you can authenticate and authorize each mac on a port&lt;BR /&gt;
individually. Mac-authentication and dot1x run simultaneously and&lt;BR /&gt;
the better method wins:&lt;BR /&gt;
&lt;BR /&gt;
 Authentication Protocol Order: 802.1x, web-based, mac-based (default)&lt;BR /&gt;
&lt;BR /&gt;
So one protocol is sufficient to get an valid netlogin session.&lt;BR /&gt;
&lt;BR /&gt;
For each port EOS has four different configuration how packets are&lt;BR /&gt;
handled:&lt;BR /&gt;
&lt;BR /&gt;
 - Forced Authorized: netlogin disabled, packets always forwarded&lt;BR /&gt;
 - Forced UnAuthorized: netlogin disabled, packets always dropped&lt;BR /&gt;
 - Authentication Required: netlogin enable, unauthenticated packets&lt;BR /&gt;
   dropped&lt;BR /&gt;
 - Authentication Optional (with optional Policy/Filterlist):&lt;BR /&gt;
   netlogin enabled, unauthenticated packets forwarded&lt;BR /&gt;
&lt;BR /&gt;
EXOS implements only Required and Optional. You can disable netlogin&lt;BR /&gt;
per port to get the 'forced' modes. See the policy course for&lt;BR /&gt;
more detailed information...&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 04:15:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57992#M17188</guid>
      <dc:creator>Patrick_Koppen</dc:creator>
      <dc:date>2017-03-18T04:15:00Z</dc:date>
    </item>
    <item>
      <title>RE: Multisession on single port problem</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57993#M17189</link>
      <description>Hello Marek,&lt;BR /&gt;
&lt;BR /&gt;
now your problem. It seems you used commands from both concepts. But your configuration&lt;BR /&gt;
works. You see the session.&lt;BR /&gt;
&lt;BR /&gt;
The missing ip in EAC is something totally different. After a successfull authentication&lt;BR /&gt;
the EAC waits 10 second to start the resolving process. If it fails it waits 60 seconds, tries&lt;BR /&gt;
again, waits 60 seconds and tries again. So after 2:10 it stopps the process and you&lt;BR /&gt;
get 'ip resulution failed'.&lt;BR /&gt;
&lt;BR /&gt;
There are about 5 ways to fix this:&lt;BR /&gt;
&lt;OL&gt; 
&lt;LI&gt;update to EXOS 22.2 and EMC/EAC 7.1 and enable nodealias 
&lt;/LI&gt;&lt;LI&gt;forward dhcp packet from every router in every vlan to one or two EACE 
&lt;/LI&gt;&lt;LI&gt;configure an ip address in every vlan in the switch 
&lt;/LI&gt;&lt;LI&gt;tell EAC the default gateway for the vlan/switch combination 
&lt;/LI&gt;&lt;LI&gt;...&lt;/LI&gt;&lt;/OL&gt;1 works always, 2 only with dhcp clients, 3 should work, 4 works only with one vlan&lt;BR /&gt;
per switch, ....&lt;BR /&gt;
&lt;BR /&gt;
In your case turn off the printer, plug it into the mini switch, and turn it on again. It&lt;BR /&gt;
should work. If not enable endsystem diagnostics in the EACE.&lt;BR /&gt;
&lt;BR /&gt;
See Extreme Access Control course for more information...&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sat, 18 Mar 2017 04:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/multisession-on-single-port-problem/m-p/57993#M17189</guid>
      <dc:creator>Patrick_Koppen</dc:creator>
      <dc:date>2017-03-18T04:36:00Z</dc:date>
    </item>
  </channel>
</rss>

