<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5420F and macmon in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78918#M19800</link>
    <description>Hi and Thank you for the response,&lt;BR /&gt;&lt;BR /&gt;yes, we use macmon as radius server. I don't know how macmon determine the port status.&lt;BR /&gt;&lt;BR /&gt;MAC bypass, i mean that there are devices without username, password and / or certifikate. This devices will explicit released with them mac-address. This devices are for e.g. accesspoints or cams. We use macmon to monitor this devices and react before there are problems. A User call us because the client have no connection. A camera doesn't this.&amp;nbsp;&lt;BR /&gt;</description>
    <pubDate>Tue, 02 Aug 2022 14:42:25 GMT</pubDate>
    <dc:creator>FranzR</dc:creator>
    <dc:date>2022-08-02T14:42:25Z</dc:date>
    <item>
      <title>5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78915#M19797</link>
      <description>Dear community,&lt;BR /&gt;&lt;BR /&gt;we have one problem with our new Switches from Extreme an macmon nac. All of the new Switches doesn't show the correct 802.1X Status in macmon. They show "unauthorized" although they are authorized. It seems as if the 802.1X MAC Bypass isn't correct. The 802.1X radius looks good.&lt;BR /&gt;&lt;BR /&gt;Any idea? Any experiences with this topic?&lt;BR /&gt;&lt;BR /&gt;Thanks an kind regards&lt;BR /&gt;&lt;BR /&gt;Franz</description>
      <pubDate>Mon, 01 Aug 2022 11:51:04 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78915#M19797</guid>
      <dc:creator>FranzR</dc:creator>
      <dc:date>2022-08-01T11:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78916#M19798</link>
      <description>I dont know macmon but I assume you use macmon as radius server.&lt;BR /&gt;Weird if the switch shows authenticated but the radius server that did send the accept does not show that.&lt;BR /&gt;&lt;BR /&gt;How does macmon determine the port status, SNMP, radius accounting ?&lt;BR /&gt;Try to find out how it does that and troubleshoot. that part.&lt;BR /&gt;</description>
      <pubDate>Tue, 02 Aug 2022 10:08:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78916#M19798</guid>
      <dc:creator>OscarK</dc:creator>
      <dc:date>2022-08-02T10:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78917#M19799</link>
      <description>Hi,&lt;BR /&gt;what do you mean with "802.1x MAC bypass"?&lt;BR /&gt;&lt;BR /&gt;Just to make sure: Everything is working fine, clients are working and are authorized, but in Macmon you see that they are unauthorized?</description>
      <pubDate>Tue, 02 Aug 2022 14:22:07 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78917#M19799</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2022-08-02T14:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78918#M19800</link>
      <description>Hi and Thank you for the response,&lt;BR /&gt;&lt;BR /&gt;yes, we use macmon as radius server. I don't know how macmon determine the port status.&lt;BR /&gt;&lt;BR /&gt;MAC bypass, i mean that there are devices without username, password and / or certifikate. This devices will explicit released with them mac-address. This devices are for e.g. accesspoints or cams. We use macmon to monitor this devices and react before there are problems. A User call us because the client have no connection. A camera doesn't this.&amp;nbsp;&lt;BR /&gt;</description>
      <pubDate>Tue, 02 Aug 2022 14:42:25 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78918#M19800</guid>
      <dc:creator>FranzR</dc:creator>
      <dc:date>2022-08-02T14:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78919#M19801</link>
      <description>&lt;P&gt;Care to share your switch config (the relevant parts)? And also share a "show netlogin session port x", preferably of a port where a user is connect and of a port where a camera is connected.&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;/P&gt;
&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 14:56:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78919#M19801</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2022-08-02T14:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78920#M19802</link>
      <description>Which part of Switch configuration do you need and how can i share this?&lt;BR /&gt;&lt;BR /&gt;"&lt;SPAN&gt;show netlogin session port x" files are attached. The second one is from a printer, but the bahaviour is the same.&lt;/SPAN&gt;</description>
      <pubDate>Tue, 02 Aug 2022 15:26:09 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78920#M19802</guid>
      <dc:creator>FranzR</dc:creator>
      <dc:date>2022-08-02T15:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78921#M19803</link>
      <description>The second client shows "Auth status: failed" for 802.1x, so there is something wrong with the 802.1x config. It depends on the end-system what happens in such a case... Some end-systems will stop doing 802.1x Auth and fallback to mac-auth, but others won't function, depending on the configuration. (afaik)&lt;BR /&gt;On windows this is called "Fallback to unautorized network access" I believe.</description>
      <pubDate>Tue, 02 Aug 2022 15:48:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78921#M19803</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2022-08-02T15:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78922#M19804</link>
      <description>OK, i understand and it sounds logical.&lt;BR /&gt;&lt;BR /&gt;But we have exact the same end-systems on older extreme switches, eg. 4950GTS (i think this is EOS) and this works fine. macmon shows the correct status. So i think this is not a client problem.</description>
      <pubDate>Tue, 02 Aug 2022 15:59:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78922#M19804</guid>
      <dc:creator>FranzR</dc:creator>
      <dc:date>2022-08-02T15:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78923#M19805</link>
      <description>Okay, that's strange. Is 802.1x configured on those 4950GTS (they are Avaya btw)? Maybe the clients only do MAC-Auth there?&lt;BR /&gt;What does "show log" displays, when you connect the client on the 5420? &lt;BR /&gt;&lt;BR /&gt;Viele Grüße&lt;BR /&gt;Stefan</description>
      <pubDate>Tue, 02 Aug 2022 16:14:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78923#M19805</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2022-08-02T16:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78924#M19806</link>
      <description>This is a log from yesterday with a printer on the port:&lt;BR /&gt;&lt;BR /&gt;08/01/2022 12:08:14.14 &amp;lt;Noti:nl.ClientAuthFailure&amp;gt; Authentication failed for Network Login 802.1x user Mac 17:22:c7:12:ea:bd port 3&lt;BR /&gt;08/01/2022 12:08:14.14 &amp;lt;Noti:nl.Dot1xClientAuthFail&amp;gt; Authentication failed for Network Login 802.1x user Mac 17:22:c7:12:ea:bd port 3 because either the supplicant does not support dot1X or the supplicant has not responded to the EAPOL PDUs.</description>
      <pubDate>Tue, 02 Aug 2022 16:29:13 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78924#M19806</guid>
      <dc:creator>FranzR</dc:creator>
      <dc:date>2022-08-02T16:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78925#M19807</link>
      <description>So this is an EXOS switch, if a mac authentication happens it will try a dot1x authentication also. If there is a device behind that does not do dot1x it will show this log entry. And show netlogin session will show a success mac auth session and a failed dot1x session.&lt;BR /&gt;This is normal behavior for EXOS.</description>
      <pubDate>Tue, 02 Aug 2022 16:36:55 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78925#M19807</guid>
      <dc:creator>OscarK</dc:creator>
      <dc:date>2022-08-02T16:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78926#M19808</link>
      <description>OK, i asked the macmon support too. They answered:&lt;BR /&gt;&lt;BR /&gt;
&lt;PRE class="tw-data-text tw-text-large tw-ta" data-placeholder="Übersetzung" dir="ltr"&gt;&lt;SPAN class="Y2IQFc" lang="en"&gt;The manufacturer probably does not implement a MAC bypass authentication as a Radius status and only sets the status correctly for a pure Radius (certificate or user/host) authentication.
You should ask the manufacturer about this.&lt;/SPAN&gt;&lt;/PRE&gt;
Is there a mib table in exos which shows the status of the mac auth session? Possibly macmon can implement this mib table entry a additionally column.</description>
      <pubDate>Tue, 02 Aug 2022 17:10:41 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78926#M19808</guid>
      <dc:creator>FranzR</dc:creator>
      <dc:date>2022-08-02T17:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78927#M19809</link>
      <description>Sorry, I'm still wondering what exactly is the problem. Is it only about the Auth status in Macmon or is there anything else regarding the authentication that is not working?</description>
      <pubDate>Wed, 03 Aug 2022 12:31:56 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78927#M19809</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2022-08-03T12:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78928#M19810</link>
      <description>&lt;SPAN style="vertical-align: inherit"&gt;&lt;SPAN style="vertical-align: inherit"&gt;Danke für die Antwort. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="vertical-align: inherit"&gt;&lt;SPAN style="vertical-align: inherit"&gt;Maybe its just a Problem with our way of working &lt;/SPAN&gt;&lt;SPAN style="vertical-align: inherit"&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;There are two problems with this.&lt;BR /&gt;First, every morning I scan our devices to see if there are any devices like cameras, access control, etc. that aren't online.&lt;BR /&gt;&lt;BR /&gt;The second issue is that sometimes when a device like this isn't online, the problem is authentication. Then it works if I toggle authentication off and on.&lt;/SPAN&gt;</description>
      <pubDate>Wed, 03 Aug 2022 12:39:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78928#M19810</guid>
      <dc:creator>FranzR</dc:creator>
      <dc:date>2022-08-03T12:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78929#M19811</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;we have downloaded the mib file for our exos version. I can't find the right OID to readout if a device on a port is authenticated by dot1x or mac.&lt;BR /&gt;On the Switch i can see those information with this command. Does anyone know if there is an OID which readout that information?&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="29eb17579a844b1c834cf2d1f2cce98c.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2604i548381D06DFF6CB3/image-size/large?v=v2&amp;amp;px=999" role="button" title="29eb17579a844b1c834cf2d1f2cce98c.png" alt="29eb17579a844b1c834cf2d1f2cce98c.png" /&gt;&lt;/span&gt;&lt;BR /&gt;We also need an OID to toggle mac based authentication. On the exos switch the commands would be:&lt;BR /&gt;&lt;SPAN&gt;disable netlogin port X mac&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;enable netlogin port X mac&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;BR /&gt;Stefan</description>
      <pubDate>Thu, 04 Aug 2022 12:22:50 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78929#M19811</guid>
      <dc:creator>StefanW</dc:creator>
      <dc:date>2022-08-04T12:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: 5420F and macmon</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78930#M19812</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;after going through the mib file for several hours i think i found the right OIDs to do what we need. I have not tested it through. Maybe someone can tell me if i am on the right way &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I have just imported the mib file (for our envirement it was for exos Version 31.5.1.6) into a mib file explorer and going through every OID.&lt;BR /&gt;&lt;BR /&gt;With this table you are able to read out if mac based authentication is enabled on which port. You are also able to make changes regarding mac-based authentication on a specific port.&lt;BR /&gt;etsysMACAuthenticationPortConfigTable&lt;BR /&gt;1.3.6.1.4.1.5624.1.2.25.1.2.1&lt;BR /&gt;&lt;BR /&gt;Example:&lt;BR /&gt;Port 1 MAC based auth Off/on&lt;BR /&gt;etsysMACAuthenticationPortEnable&lt;BR /&gt;1.3.6.1.4.1.5624.1.2.25.1.2.1.1.4.1001 = 2(disabled) 1 (enabled)&lt;BR /&gt;&lt;BR /&gt;Reauthenticate Devices on Port 1 -&amp;gt; A Read allways return 2(false)&lt;BR /&gt;etsysMACAuthenticationPortInitialize&lt;BR /&gt;1.3.6.1.4.1.5624.1.2.25.1.2.1.1.2.1001 = 1(true) 2(false) &lt;BR /&gt;&lt;BR /&gt;This OID reads out the current mac-based authenticated devices and lists them with the index number of the port:&lt;BR /&gt;etsysMACAuthenticationMACConfigTable&lt;BR /&gt;1.3.6.1.4.1.5624.1.2.25.1.3.1&lt;BR /&gt;&lt;BR /&gt;To read out the Authentication State of a specific Port you can use this table&lt;BR /&gt;etsysMultiAuthSessionPortTable&lt;BR /&gt;1.3.6.1.4.1.5624.1.2.46.1.4.2&lt;BR /&gt;&lt;BR /&gt;In this table you can find a list of index numbers (ports) and if a device is authenticated or not on this port. Also you can see which authentication methode works or not. For Exampel dot1x fails but mac-based authentication was successful.&lt;BR /&gt;The possible Authentication States are:&lt;BR /&gt;authSuccess(1), authFailed(2), authInProgress(3), authServerTimeout(4), authTerminated(5)&lt;BR /&gt;&lt;BR /&gt;The status of authentication for this session. A value of authSuccess(1) means authentication was attempted and succeeded. A value of authFailed(2) means authentication was attempted and failed for a reason other than communication timing out with the authorization server. A value of authInProgress(3) means that the authorization process has been started but has not completed yet. A value of authServerTimeout(4) means that the request to the authorization server for this session timed out without a reply from the server. A value of authTerminated(5) indicates that the session was active or in progress and was subsequently terminated. A session may be terminated for several reasons, including but not limited to, session timeout, idle timeout, the ifOperStatus of the interface on which the session was authenticated transitioning out of the up(1) state, or explicit administrative management action.&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;BR /&gt;Stefan</description>
      <pubDate>Fri, 05 Aug 2022 15:36:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/5420f-and-macmon/m-p/78930#M19812</guid>
      <dc:creator>StefanW</dc:creator>
      <dc:date>2022-08-05T15:36:51Z</dc:date>
    </item>
  </channel>
</rss>

