<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure dot1x auth with NAC and AD in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75190#M19262</link>
    <description>do you got guide to do this?&lt;BR /&gt;
&lt;BR /&gt;
Questions:&lt;BR /&gt;
1 = do you see radius request coming from the switch to your Access Control Engine?&lt;BR /&gt;
2 = do you see dot1x in the radius request? or just MACauthentication?&lt;BR /&gt;
3 = do you see end-system in the end-system table? how it looks like "accept / error"&lt;BR /&gt;
4 = What is the supplicant (client) setting?&lt;BR /&gt;
5 = anything in the logs?&lt;BR /&gt;
&lt;BR /&gt;
1=yes&lt;BR /&gt;
2=both&lt;BR /&gt;
3=error&lt;BR /&gt;
4=enable dot1x login&lt;BR /&gt;
5=no</description>
    <pubDate>Fri, 08 Feb 2019 15:22:59 GMT</pubDate>
    <dc:creator>Ashraf</dc:creator>
    <dc:date>2019-02-08T15:22:59Z</dc:date>
    <item>
      <title>How to configure dot1x auth with NAC and AD</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75185#M19257</link>
      <description>exos switch ip:10.10.1.254&lt;BR /&gt;
nac ip:10.10.1.201&lt;BR /&gt;
ad ip:10.10.1.204&lt;BR /&gt;
&lt;BR /&gt;
exos config:&lt;BR /&gt;
Netlogin&lt;BR /&gt;
enable netlogin dot1x mac&lt;BR /&gt;
configure netlogin authentication protocol-order dot1x mac web-based&lt;BR /&gt;
enable netlogin ports 3-28 dot1x&lt;BR /&gt;
enable netlogin ports 3-28 mac&lt;BR /&gt;
configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48&lt;BR /&gt;
configure netlogin mac ports 3 timers reauthentication on&lt;BR /&gt;
aaa&lt;BR /&gt;
enable netlogin dot1x mac&lt;BR /&gt;
configure netlogin authentication protocol-order dot1x mac web-based&lt;BR /&gt;
enable netlogin ports 3-28 dot1x&lt;BR /&gt;
enable netlogin ports 3-28 mac&lt;BR /&gt;
configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48&lt;BR /&gt;
configure netlogin mac ports 3 timers reauthentication on&lt;BR /&gt;
VLAN config&lt;BR /&gt;
configure vlan Default add ports 1-28 untagged&lt;BR /&gt;
configure vlan Default ipaddress 10.10.1.254 255.255.255.0&lt;BR /&gt;
enable ipforwarding vlan Default&lt;BR /&gt;
NAC CONFIG:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2b59716147b448db8e9490cadb3566ab_71f1c0aa-2216-4c23-bf32-dcf069bac0ca.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4365i2D0399A4D76355F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="2b59716147b448db8e9490cadb3566ab_71f1c0aa-2216-4c23-bf32-dcf069bac0ca.png" alt="2b59716147b448db8e9490cadb3566ab_71f1c0aa-2216-4c23-bf32-dcf069bac0ca.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2b59716147b448db8e9490cadb3566ab_158170a1-23f9-42f7-9c04-3b8fd25231b1.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5914i2506864A39EB976A/image-size/large?v=v2&amp;amp;px=999" role="button" title="2b59716147b448db8e9490cadb3566ab_158170a1-23f9-42f7-9c04-3b8fd25231b1.png" alt="2b59716147b448db8e9490cadb3566ab_158170a1-23f9-42f7-9c04-3b8fd25231b1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2b59716147b448db8e9490cadb3566ab_2f069a67-68be-4c7b-a83a-0d26ca13b409.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/795iBA81A8ABD69D3E0A/image-size/large?v=v2&amp;amp;px=999" role="button" title="2b59716147b448db8e9490cadb3566ab_2f069a67-68be-4c7b-a83a-0d26ca13b409.png" alt="2b59716147b448db8e9490cadb3566ab_2f069a67-68be-4c7b-a83a-0d26ca13b409.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2b59716147b448db8e9490cadb3566ab_a42223d9-1ec6-4b0b-85a7-89a04b1aab93.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5245iB62D210D22374EDA/image-size/large?v=v2&amp;amp;px=999" role="button" title="2b59716147b448db8e9490cadb3566ab_a42223d9-1ec6-4b0b-85a7-89a04b1aab93.png" alt="2b59716147b448db8e9490cadb3566ab_a42223d9-1ec6-4b0b-85a7-89a04b1aab93.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2b59716147b448db8e9490cadb3566ab_e9cc2662-1dcb-45e1-a496-995a9f93982e.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2389i3E940184BB303BA6/image-size/large?v=v2&amp;amp;px=999" role="button" title="2b59716147b448db8e9490cadb3566ab_e9cc2662-1dcb-45e1-a496-995a9f93982e.png" alt="2b59716147b448db8e9490cadb3566ab_e9cc2662-1dcb-45e1-a496-995a9f93982e.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 12:47:39 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75185#M19257</guid>
      <dc:creator>Ashraf</dc:creator>
      <dc:date>2019-01-15T12:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure dot1x auth with NAC and AD</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75186#M19258</link>
      <description>Hi.&lt;BR /&gt;
&lt;BR /&gt;
it seems you have two AAA configurations in your NAC. One is “basic” one is “advanced”.&lt;BR /&gt;
i guess your NAC configurationnis using the basic one.&lt;BR /&gt;
&lt;BR /&gt;
option 1: change the nac configuration to use the aaa configuration “advanced” with two rules you have there.&lt;BR /&gt;
option 2: change the basic configuration to the “asvanced” (right click on the aaa configuration, make advanced).&lt;BR /&gt;
&lt;BR /&gt;
do not forget to enforce. In your switch config I do not see AAA configuration. If you have CLI credentials working in Extreme Management Center and if the switch is assigned to the Access Control Engine and you leave the default values when you add the switch to the acceas control engine then the AAA will be configured for you. Otherwise you need to setup radius on the switch.</description>
      <pubDate>Tue, 15 Jan 2019 14:49:03 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75186#M19258</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2019-01-15T14:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure dot1x auth with NAC and AD</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75187#M19259</link>
      <description>here aaa configuration&lt;BR /&gt;
&lt;BR /&gt;
configure radius netlogin 1 server 10.10.1.201 1812 client-ip 10.10.1.254 vr VR-Default&lt;BR /&gt;
configure radius 1 shared-secret encrypted "#$H6YKEMmpgZRQk4/3ZdZ92pVm5Hk/CXk/2HCOmoHAXF8aH95P9HI="&lt;BR /&gt;
configure radius-accounting netlogin 1 server 10.10.1.201 1813 client-ip 10.10.1.254 vr VR-Default&lt;BR /&gt;
configure radius-accounting 1 shared-secret encrypted "#$u/KlXkwtQYtxcaLzMBFRZNJ3P40ahHVoYZQKgn1moK1Q8R+3INg="&lt;BR /&gt;
configure radius-accounting 1 timeout 10&lt;BR /&gt;
enable radius&lt;BR /&gt;
disable radius mgmt-access&lt;BR /&gt;
enable radius netlogin&lt;BR /&gt;
configure radius timeout 15&lt;BR /&gt;
enable radius-accounting&lt;BR /&gt;
disable radius-accounting mgmt-access&lt;BR /&gt;
enable radius-accounting netlogin</description>
      <pubDate>Tue, 15 Jan 2019 17:54:33 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75187#M19259</guid>
      <dc:creator>Ashraf</dc:creator>
      <dc:date>2019-01-15T17:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure dot1x auth with NAC and AD</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75188#M19260</link>
      <description>i have deleted advance aaa on nac&lt;BR /&gt;
i have change basic to advance</description>
      <pubDate>Tue, 15 Jan 2019 17:55:55 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75188#M19260</guid>
      <dc:creator>Ashraf</dc:creator>
      <dc:date>2019-01-15T17:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure dot1x auth with NAC and AD</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75189#M19261</link>
      <description>Questions:&lt;BR /&gt;
1 = do you see radius request coming from the switch to your Access Control Engine?&lt;BR /&gt;
2 = do you see dot1x in the radius request? or just MACauthentication?&lt;BR /&gt;
3 = do you see end-system in the end-system table? how it looks like "accept / error"&lt;BR /&gt;
4 = What is the supplicant (client) setting?&lt;BR /&gt;
5 = anything in the logs?</description>
      <pubDate>Sat, 19 Jan 2019 21:36:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75189#M19261</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2019-01-19T21:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure dot1x auth with NAC and AD</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75190#M19262</link>
      <description>do you got guide to do this?&lt;BR /&gt;
&lt;BR /&gt;
Questions:&lt;BR /&gt;
1 = do you see radius request coming from the switch to your Access Control Engine?&lt;BR /&gt;
2 = do you see dot1x in the radius request? or just MACauthentication?&lt;BR /&gt;
3 = do you see end-system in the end-system table? how it looks like "accept / error"&lt;BR /&gt;
4 = What is the supplicant (client) setting?&lt;BR /&gt;
5 = anything in the logs?&lt;BR /&gt;
&lt;BR /&gt;
1=yes&lt;BR /&gt;
2=both&lt;BR /&gt;
3=error&lt;BR /&gt;
4=enable dot1x login&lt;BR /&gt;
5=no</description>
      <pubDate>Fri, 08 Feb 2019 15:22:59 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75190#M19262</guid>
      <dc:creator>Ashraf</dc:creator>
      <dc:date>2019-02-08T15:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure dot1x auth with NAC and AD</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75191#M19263</link>
      <description>Please share the error message you see in the end-system table.&lt;BR /&gt;
Please share the supplicant config on your end system.</description>
      <pubDate>Mon, 11 Feb 2019 15:59:05 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75191#M19263</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2019-02-11T15:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure dot1x auth with NAC and AD</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75192#M19264</link>
      <description>Hi &lt;BR /&gt;
&lt;BR /&gt;
Did you manage to do configure dot1x auth  with Nac and AD?  Is there any documentation available?&lt;BR /&gt;
&lt;BR /&gt;
I would appreciate your help &lt;BR /&gt;
&lt;BR /&gt;
Regard &lt;BR /&gt;
Justine</description>
      <pubDate>Wed, 19 Jun 2019 03:41:37 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-configure-dot1x-auth-with-nac-and-ad/m-p/75192#M19264</guid>
      <dc:creator>Justine_Silbery</dc:creator>
      <dc:date>2019-06-19T03:41:37Z</dc:date>
    </item>
  </channel>
</rss>

