<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 802.1x Clients No Waking After Going To Sleep in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/802-1x-clients-no-waking-after-going-to-sleep/m-p/73298#M19079</link>
    <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
Currently have an issue where 802.1x clients using machine certs (8021.x) keep dropping off the network?&lt;BR /&gt;
&lt;BR /&gt;
The port is configured for 802.1x, MAC and CEP authentication. &lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;802.1x or PC's 
&lt;/LI&gt;&lt;LI&gt;MAC for phones and other devices 
&lt;/LI&gt;&lt;LI&gt;CEP for phones to assign voice VLAN should NAC's go offline 
&lt;/LI&gt;&lt;/UL&gt;
Firmware&lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;EXOS = 22.6.1.4 
&lt;/LI&gt;&lt;LI&gt;XMC = 8.2.4.42 
&lt;/LI&gt;&lt;/UL&gt;
On further investigation it seems clients can re-join by bouncing the network interface. It also seems that the issue is possibly related to the end-system going to sleep, maybe for around an hour or more.&lt;BR /&gt;
&lt;BR /&gt;
Considered using the command:&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;configure netlogin ports 1:7 allow egress-traffic all_cast&lt;BR /&gt;configure netlogin ports 1:7 restart&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
But this no longer seems available:&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Slot-1 Far-B20_23-GND.2 # configure netlogin ports 1:7 allow egress-traffic all_cast&lt;BR /&gt;                               ^&lt;BR /&gt;%% Invalid number detected at '^' marker.&lt;BR /&gt;Slot-1 Far-B20_23-GND.3 # configure netlogin ports 1:7 ?&lt;BR /&gt; allowed-users  Number of users allowed per port&lt;BR /&gt; authentication Configure port authentication settings&lt;BR /&gt; trap      Enable/Disable/Prohibit trap on first rule use&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
When looking at the netlogin parameters there is a timer for 'Quiet Period', that could be related to the issue.&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Slot-1 Far-B20_23-GND.1 # show netlogin port 1:7&lt;BR /&gt;Port             : 1:7&lt;BR /&gt;Authentication        : 802.1x, mac-based&lt;BR /&gt;Port State          : Enabled&lt;BR /&gt;Authentication Mode      : Optional (Policy Enabled only)&lt;BR /&gt;Max Supported Users      : 6144 (Policy Enabled only)&lt;BR /&gt;Allowed Users         : 128 (Policy Enabled only)&lt;BR /&gt;Current Users         : 1 (Policy Enabled only)&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    802.1x Port Configuration&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;Quiet Period         : 60&lt;BR /&gt;Supplicant Response Timeout  : 30&lt;BR /&gt;Re-authentication       : On&lt;BR /&gt;Re-authentication period   : 3600&lt;BR /&gt;Max Re-authentications    : 3&lt;BR /&gt;RADIUS server timeout     : 30&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    MAC Mode Port Configuration&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;Re-authentication period   : 3600&lt;BR /&gt;Re-authentication       : On&lt;BR /&gt;Authentication Delay     : 0 seconds (Default)&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    Netlogin Clients&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;MAC        IP address    Authenticated   Type  ReAuth-Timer  User      &lt;BR /&gt;a0:d3:c1:15:29:8e 0.0.0.0     Yes, Radius    802.1x 2276      host/companny-1853.compannyr.co.uk&lt;BR /&gt;-----------------------------------------------&lt;BR /&gt;(B) - Client entry Blackholed in FDB&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
I could adjust the timer, but that doesn't really fix the issue as the problem is the wake-up doesn't seem be enough to re-initiate the connection.&lt;BR /&gt;
&lt;BR /&gt;
So at this point I'm not sure if there is an Extreme or Windows configuration I can implement to cure the issue.&lt;BR /&gt;
&lt;BR /&gt;
Not sure (need to check) if the 'Quick Period' 60 is seconds or minutes. I know the Re-authentication period is in seconds. Maybe the answer is to perhaps, say, adjust the re-auth time to  be within the quiet period if both are seconds?&lt;BR /&gt;
&lt;BR /&gt;
Not sure if anyone else has experienced the same issue?&lt;BR /&gt;
&lt;BR /&gt;
Many thanks in advance.</description>
    <pubDate>Mon, 08 Jul 2019 23:07:11 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2019-07-08T23:07:11Z</dc:date>
    <item>
      <title>802.1x Clients No Waking After Going To Sleep</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/802-1x-clients-no-waking-after-going-to-sleep/m-p/73298#M19079</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
Currently have an issue where 802.1x clients using machine certs (8021.x) keep dropping off the network?&lt;BR /&gt;
&lt;BR /&gt;
The port is configured for 802.1x, MAC and CEP authentication. &lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;802.1x or PC's 
&lt;/LI&gt;&lt;LI&gt;MAC for phones and other devices 
&lt;/LI&gt;&lt;LI&gt;CEP for phones to assign voice VLAN should NAC's go offline 
&lt;/LI&gt;&lt;/UL&gt;
Firmware&lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;EXOS = 22.6.1.4 
&lt;/LI&gt;&lt;LI&gt;XMC = 8.2.4.42 
&lt;/LI&gt;&lt;/UL&gt;
On further investigation it seems clients can re-join by bouncing the network interface. It also seems that the issue is possibly related to the end-system going to sleep, maybe for around an hour or more.&lt;BR /&gt;
&lt;BR /&gt;
Considered using the command:&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;configure netlogin ports 1:7 allow egress-traffic all_cast&lt;BR /&gt;configure netlogin ports 1:7 restart&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
But this no longer seems available:&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Slot-1 Far-B20_23-GND.2 # configure netlogin ports 1:7 allow egress-traffic all_cast&lt;BR /&gt;                               ^&lt;BR /&gt;%% Invalid number detected at '^' marker.&lt;BR /&gt;Slot-1 Far-B20_23-GND.3 # configure netlogin ports 1:7 ?&lt;BR /&gt; allowed-users  Number of users allowed per port&lt;BR /&gt; authentication Configure port authentication settings&lt;BR /&gt; trap      Enable/Disable/Prohibit trap on first rule use&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
When looking at the netlogin parameters there is a timer for 'Quiet Period', that could be related to the issue.&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Slot-1 Far-B20_23-GND.1 # show netlogin port 1:7&lt;BR /&gt;Port             : 1:7&lt;BR /&gt;Authentication        : 802.1x, mac-based&lt;BR /&gt;Port State          : Enabled&lt;BR /&gt;Authentication Mode      : Optional (Policy Enabled only)&lt;BR /&gt;Max Supported Users      : 6144 (Policy Enabled only)&lt;BR /&gt;Allowed Users         : 128 (Policy Enabled only)&lt;BR /&gt;Current Users         : 1 (Policy Enabled only)&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    802.1x Port Configuration&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;Quiet Period         : 60&lt;BR /&gt;Supplicant Response Timeout  : 30&lt;BR /&gt;Re-authentication       : On&lt;BR /&gt;Re-authentication period   : 3600&lt;BR /&gt;Max Re-authentications    : 3&lt;BR /&gt;RADIUS server timeout     : 30&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    MAC Mode Port Configuration&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;Re-authentication period   : 3600&lt;BR /&gt;Re-authentication       : On&lt;BR /&gt;Authentication Delay     : 0 seconds (Default)&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    Netlogin Clients&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;MAC        IP address    Authenticated   Type  ReAuth-Timer  User      &lt;BR /&gt;a0:d3:c1:15:29:8e 0.0.0.0     Yes, Radius    802.1x 2276      host/companny-1853.compannyr.co.uk&lt;BR /&gt;-----------------------------------------------&lt;BR /&gt;(B) - Client entry Blackholed in FDB&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
I could adjust the timer, but that doesn't really fix the issue as the problem is the wake-up doesn't seem be enough to re-initiate the connection.&lt;BR /&gt;
&lt;BR /&gt;
So at this point I'm not sure if there is an Extreme or Windows configuration I can implement to cure the issue.&lt;BR /&gt;
&lt;BR /&gt;
Not sure (need to check) if the 'Quick Period' 60 is seconds or minutes. I know the Re-authentication period is in seconds. Maybe the answer is to perhaps, say, adjust the re-auth time to  be within the quiet period if both are seconds?&lt;BR /&gt;
&lt;BR /&gt;
Not sure if anyone else has experienced the same issue?&lt;BR /&gt;
&lt;BR /&gt;
Many thanks in advance.</description>
      <pubDate>Mon, 08 Jul 2019 23:07:11 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/802-1x-clients-no-waking-after-going-to-sleep/m-p/73298#M19079</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-07-08T23:07:11Z</dc:date>
    </item>
  </channel>
</rss>

