<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MAC Auth Rejected but still allowing access to the network? in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81593#M20121</link>
    <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
Currently have 802.1x and MAC authentication enabled on a port. The authentication method is set to optional, and the port also has a default role associated.&lt;BR /&gt;
&lt;BR /&gt;
No VLAN's have been configured on the port, all VLANs are assigned via Netlogin.&lt;BR /&gt;
&lt;BR /&gt;
The reason I have both 802.1x and MAC on the same port is to allow authentication for both a PC and a phone on the same port.&lt;BR /&gt;
&lt;BR /&gt;
The reason I have a default role and optional authentication set is so that if both of the NAC's where to go offline then the default role would be applied to the port that also has a VLAN associated to it, for phones I'm using CEP.&lt;BR /&gt;
&lt;BR /&gt;
The issue I have is that I have a phone and PC attached to a port. The phone is authenticates successfully and the PC is rejected - This is what I want as the PC isn't a known corporate device. &lt;BR /&gt;
&lt;BR /&gt;
NAC and session data shows the PC has been rejected, and that no policy is being applied, and thereby no VLAN should be dynamically assigned and the PC shouldn't be able to connect to the network, but it can, but everything else says it shouldn't!?&lt;BR /&gt;
&lt;BR /&gt;
See information below showing the PC has been rejected and not assigned any policy?&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Slot-1 Far-B20_23-L-GND.24 # show netlogin session ports 2:31&lt;BR /&gt;Multiple authentication session entries&lt;BR /&gt;---------------------------------------&lt;BR /&gt;&lt;BR /&gt;Port      : 2:31    Station address  : 08:00:0f:3a:e8:f7 &lt;BR /&gt;Auth status   : success   Last attempt   : Fri Mar 29 14:17:45 2019    &lt;BR /&gt;Agent type   : mac     Session applied  : true&lt;BR /&gt;Server type   : radius   VLAN-Tunnel-Attr : None&lt;BR /&gt;Policy index  : 11     Policy name    : Mitel Phones (active)&lt;BR /&gt;Session timeout : 0      Session duration : 0:02:39            &lt;BR /&gt;Idle timeout  : 300     Idle time     : 0:00:00            &lt;BR /&gt;Auth-Override  : disabled  Termination time : Not Terminated&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Port      : 2:31    Station address  : 8c:ec:4b:e2:9c:65 &lt;BR /&gt;Auth status   : failed   Last attempt   : Fri Mar 29 14:20:06 2019    &lt;BR /&gt;Agent type   : mac     Session applied  : false&lt;BR /&gt;Server type   : radius   VLAN-Tunnel-Attr : None&lt;BR /&gt;Policy index  : 0      Policy name    : No Policy applied&lt;BR /&gt;Session timeout : 0      Session duration : 0:00:00            &lt;BR /&gt;Idle timeout  : 300     Idle time     : 0:00:00            &lt;BR /&gt;Auth-Override  : disabled  Termination time : Not Terminated&lt;BR /&gt;&lt;BR /&gt;Slot-1 Far-B20_23-L-GND.25 # show netlogin port 2:31&lt;BR /&gt;Port             : 2:31&lt;BR /&gt;Authentication        : 802.1x, mac-based&lt;BR /&gt;Port State          : Enabled&lt;BR /&gt;Authentication Mode      : Optional (Policy Enabled only)&lt;BR /&gt;Max Supported Users      : 6144 (Policy Enabled only)&lt;BR /&gt;Allowed Users         : 128 (Policy Enabled only)&lt;BR /&gt;Current Users         : 1 (Policy Enabled only)&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    802.1x Port Configuration&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;Quiet Period         : 60&lt;BR /&gt;Supplicant Response Timeout  : 30&lt;BR /&gt;Re-authentication       : On&lt;BR /&gt;Re-authentication period   : 3600&lt;BR /&gt;Max Re-authentications    : 3&lt;BR /&gt;RADIUS server timeout     : 30&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    MAC Mode Port Configuration&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;Re-authentication period   : 3600&lt;BR /&gt;Re-authentication       : Off&lt;BR /&gt;Authentication Delay     : 0 seconds (Default)&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    Netlogin Clients&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;MAC                IP address       Authenticated     Type    ReAuth-Timer   User          &lt;BR /&gt;08:00:0f:3a:e8:f7  0.0.0.0          Yes, Radius       MAC     0              08000F3AE8F7&lt;BR /&gt;8c:ec:4b:e2:9c:65  0.0.0.0          No                802.1x  0              &lt;BR /&gt;-----------------------------------------------&lt;BR /&gt;(B) - Client entry Blackholed in FDB&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
Here is the end-system showing a reject on the XMC / NAC and the policy defining the reject authentication request:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="66bda8a28243458fb69cb7a48cb00c00_acc6b621-51fe-4e99-9ca3-b020cf17285f.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1535iB5136171094DDBE0/image-size/large?v=v2&amp;amp;px=999" role="button" title="66bda8a28243458fb69cb7a48cb00c00_acc6b621-51fe-4e99-9ca3-b020cf17285f.png" alt="66bda8a28243458fb69cb7a48cb00c00_acc6b621-51fe-4e99-9ca3-b020cf17285f.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="66bda8a28243458fb69cb7a48cb00c00_4424ea0e-fc8a-43bf-953f-c4c5a560c5f6.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4907i3D52E88E7F33F889/image-size/large?v=v2&amp;amp;px=999" role="button" title="66bda8a28243458fb69cb7a48cb00c00_4424ea0e-fc8a-43bf-953f-c4c5a560c5f6.png" alt="66bda8a28243458fb69cb7a48cb00c00_4424ea0e-fc8a-43bf-953f-c4c5a560c5f6.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Could it be that the authentication is showing failed rather than rejected. In netlogin session it shows MAC authenticated and the other shows the method 802.1x?&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;03/29/2019 14:37:53.14  Slot-1: Authentication failed for Network Login MAC user 8CEC4BE29C65 Mac 8C:EC:4B:E2:9C:65 port 2:31&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
Here is the logs from the switch clearly showing the reject being returned for that device by NAC:&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;03/29/2019 14:58:06.98  Slot-1: Received an Accounting Start Response (packet length 20, destination UDP port 32769, id 132) from accounting server #1 for 08-00-0F-3A-E8-F7(userName '08000F3AE8F7') on port 2:31.&lt;BR /&gt;03/29/2019 14:58:06.96  Slot-1: Received an access accept (packet length 61, destination UDP port 32769, id 131) from authentication server #2 for 08-00-0F-3A-E8-F7(userName '08000F3AE8F7') on port 2:31.&lt;BR /&gt;03/29/2019 14:58:05.38  Slot-1: Authentication failed for Network Login MAC user 8CEC4BE29C65 Mac 8C:EC:4B:E2:9C:65 port 2:31&lt;BR /&gt;03/29/2019 14:58:05.38  Slot-1: Received an Authentication Access Reject (packet length 20, destination UDP port 32769, id 130) from authentication server #1 for 8C-EC-4B-E2-9C-65(userName '8CEC4BE29C65') on port 2:31.&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
Currently running XMC version 8.2.4.42&lt;BR /&gt;
Switch X450G2 version 22.6.1.4&lt;BR /&gt;
&lt;BR /&gt;
Many thanks in advance</description>
    <pubDate>Fri, 29 Mar 2019 20:38:55 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2019-03-29T20:38:55Z</dc:date>
    <item>
      <title>MAC Auth Rejected but still allowing access to the network?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81593#M20121</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
Currently have 802.1x and MAC authentication enabled on a port. The authentication method is set to optional, and the port also has a default role associated.&lt;BR /&gt;
&lt;BR /&gt;
No VLAN's have been configured on the port, all VLANs are assigned via Netlogin.&lt;BR /&gt;
&lt;BR /&gt;
The reason I have both 802.1x and MAC on the same port is to allow authentication for both a PC and a phone on the same port.&lt;BR /&gt;
&lt;BR /&gt;
The reason I have a default role and optional authentication set is so that if both of the NAC's where to go offline then the default role would be applied to the port that also has a VLAN associated to it, for phones I'm using CEP.&lt;BR /&gt;
&lt;BR /&gt;
The issue I have is that I have a phone and PC attached to a port. The phone is authenticates successfully and the PC is rejected - This is what I want as the PC isn't a known corporate device. &lt;BR /&gt;
&lt;BR /&gt;
NAC and session data shows the PC has been rejected, and that no policy is being applied, and thereby no VLAN should be dynamically assigned and the PC shouldn't be able to connect to the network, but it can, but everything else says it shouldn't!?&lt;BR /&gt;
&lt;BR /&gt;
See information below showing the PC has been rejected and not assigned any policy?&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;Slot-1 Far-B20_23-L-GND.24 # show netlogin session ports 2:31&lt;BR /&gt;Multiple authentication session entries&lt;BR /&gt;---------------------------------------&lt;BR /&gt;&lt;BR /&gt;Port      : 2:31    Station address  : 08:00:0f:3a:e8:f7 &lt;BR /&gt;Auth status   : success   Last attempt   : Fri Mar 29 14:17:45 2019    &lt;BR /&gt;Agent type   : mac     Session applied  : true&lt;BR /&gt;Server type   : radius   VLAN-Tunnel-Attr : None&lt;BR /&gt;Policy index  : 11     Policy name    : Mitel Phones (active)&lt;BR /&gt;Session timeout : 0      Session duration : 0:02:39            &lt;BR /&gt;Idle timeout  : 300     Idle time     : 0:00:00            &lt;BR /&gt;Auth-Override  : disabled  Termination time : Not Terminated&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Port      : 2:31    Station address  : 8c:ec:4b:e2:9c:65 &lt;BR /&gt;Auth status   : failed   Last attempt   : Fri Mar 29 14:20:06 2019    &lt;BR /&gt;Agent type   : mac     Session applied  : false&lt;BR /&gt;Server type   : radius   VLAN-Tunnel-Attr : None&lt;BR /&gt;Policy index  : 0      Policy name    : No Policy applied&lt;BR /&gt;Session timeout : 0      Session duration : 0:00:00            &lt;BR /&gt;Idle timeout  : 300     Idle time     : 0:00:00            &lt;BR /&gt;Auth-Override  : disabled  Termination time : Not Terminated&lt;BR /&gt;&lt;BR /&gt;Slot-1 Far-B20_23-L-GND.25 # show netlogin port 2:31&lt;BR /&gt;Port             : 2:31&lt;BR /&gt;Authentication        : 802.1x, mac-based&lt;BR /&gt;Port State          : Enabled&lt;BR /&gt;Authentication Mode      : Optional (Policy Enabled only)&lt;BR /&gt;Max Supported Users      : 6144 (Policy Enabled only)&lt;BR /&gt;Allowed Users         : 128 (Policy Enabled only)&lt;BR /&gt;Current Users         : 1 (Policy Enabled only)&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    802.1x Port Configuration&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;Quiet Period         : 60&lt;BR /&gt;Supplicant Response Timeout  : 30&lt;BR /&gt;Re-authentication       : On&lt;BR /&gt;Re-authentication period   : 3600&lt;BR /&gt;Max Re-authentications    : 3&lt;BR /&gt;RADIUS server timeout     : 30&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    MAC Mode Port Configuration&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;Re-authentication period   : 3600&lt;BR /&gt;Re-authentication       : Off&lt;BR /&gt;Authentication Delay     : 0 seconds (Default)&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;    Netlogin Clients&lt;BR /&gt;------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;MAC                IP address       Authenticated     Type    ReAuth-Timer   User          &lt;BR /&gt;08:00:0f:3a:e8:f7  0.0.0.0          Yes, Radius       MAC     0              08000F3AE8F7&lt;BR /&gt;8c:ec:4b:e2:9c:65  0.0.0.0          No                802.1x  0              &lt;BR /&gt;-----------------------------------------------&lt;BR /&gt;(B) - Client entry Blackholed in FDB&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
Here is the end-system showing a reject on the XMC / NAC and the policy defining the reject authentication request:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="66bda8a28243458fb69cb7a48cb00c00_acc6b621-51fe-4e99-9ca3-b020cf17285f.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1535iB5136171094DDBE0/image-size/large?v=v2&amp;amp;px=999" role="button" title="66bda8a28243458fb69cb7a48cb00c00_acc6b621-51fe-4e99-9ca3-b020cf17285f.png" alt="66bda8a28243458fb69cb7a48cb00c00_acc6b621-51fe-4e99-9ca3-b020cf17285f.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="66bda8a28243458fb69cb7a48cb00c00_4424ea0e-fc8a-43bf-953f-c4c5a560c5f6.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4907i3D52E88E7F33F889/image-size/large?v=v2&amp;amp;px=999" role="button" title="66bda8a28243458fb69cb7a48cb00c00_4424ea0e-fc8a-43bf-953f-c4c5a560c5f6.png" alt="66bda8a28243458fb69cb7a48cb00c00_4424ea0e-fc8a-43bf-953f-c4c5a560c5f6.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Could it be that the authentication is showing failed rather than rejected. In netlogin session it shows MAC authenticated and the other shows the method 802.1x?&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;03/29/2019 14:37:53.14  Slot-1: Authentication failed for Network Login MAC user 8CEC4BE29C65 Mac 8C:EC:4B:E2:9C:65 port 2:31&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
Here is the logs from the switch clearly showing the reject being returned for that device by NAC:&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;03/29/2019 14:58:06.98  Slot-1: Received an Accounting Start Response (packet length 20, destination UDP port 32769, id 132) from accounting server #1 for 08-00-0F-3A-E8-F7(userName '08000F3AE8F7') on port 2:31.&lt;BR /&gt;03/29/2019 14:58:06.96  Slot-1: Received an access accept (packet length 61, destination UDP port 32769, id 131) from authentication server #2 for 08-00-0F-3A-E8-F7(userName '08000F3AE8F7') on port 2:31.&lt;BR /&gt;03/29/2019 14:58:05.38  Slot-1: Authentication failed for Network Login MAC user 8CEC4BE29C65 Mac 8C:EC:4B:E2:9C:65 port 2:31&lt;BR /&gt;03/29/2019 14:58:05.38  Slot-1: Received an Authentication Access Reject (packet length 20, destination UDP port 32769, id 130) from authentication server #1 for 8C-EC-4B-E2-9C-65(userName '8CEC4BE29C65') on port 2:31.&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
Currently running XMC version 8.2.4.42&lt;BR /&gt;
Switch X450G2 version 22.6.1.4&lt;BR /&gt;
&lt;BR /&gt;
Many thanks in advance</description>
      <pubDate>Fri, 29 Mar 2019 20:38:55 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81593#M20121</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-03-29T20:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Auth Rejected but still allowing access to the network?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81594#M20122</link>
      <description>Ok, so the issue went when setting the authentication to required.&lt;BR /&gt;
&lt;BR /&gt;
So this ends up contradicting what was answered in this post:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://extreme.connectedcommunity.org/communities/community-home/digestviewer/viewthread?MessageKey=f498f266-45ec-40dc-8839-ca080a75ee4e&amp;amp;CommunityKey=929e6d1f-141a-4b6d-b66e-7ebfd2f3f952&amp;amp;tab=digestviewer#bmf498f266-45ec-40dc-8839-ca080a75ee4e" target="_blank" rel="nofollow noreferrer noopener"&gt;https://community.extremenetworks.com/extremeswitching-exos-223284/fail-open-port-user-authentication-7798069&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Wondered if its because the device is hanging off the back of a phone?&lt;BR /&gt;
&lt;BR /&gt;
The problem this causes me is if both NAC devices go offline, which the customer wants me to protect, if the port is set to authentication required the device will locked out of the network?</description>
      <pubDate>Fri, 29 Mar 2019 22:15:02 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81594#M20122</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-03-29T22:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Auth Rejected but still allowing access to the network?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81595#M20123</link>
      <description>So managed to get around this, by assigning a role that is set to Deny instead or a profile that's set to reject.&lt;BR /&gt;
&lt;BR /&gt;
Still can't explain the behaviour, as I know for sure in the past even with the authentication set to optional if a reject is sent by RADIUS it stops the device getting on the network?&lt;BR /&gt;
&lt;BR /&gt;
Maybe it is because its daisy chained off a phone, will be my next test.</description>
      <pubDate>Fri, 29 Mar 2019 22:27:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81595#M20123</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-03-29T22:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Auth Rejected but still allowing access to the network?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81596#M20124</link>
      <description>I don't have an answer for you, Martin, but I wanted to mention that I've submitted a ticket to see about not parsing MAC addresses with emojis in code tags. ?</description>
      <pubDate>Fri, 29 Mar 2019 23:59:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81596#M20124</guid>
      <dc:creator>Drew_C</dc:creator>
      <dc:date>2019-03-29T23:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Auth Rejected but still allowing access to the network?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81597#M20125</link>
      <description>&lt;BR /&gt;
No problem, did wonder why that showed up. Thanks.</description>
      <pubDate>Mon, 01 Apr 2019 02:25:25 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81597#M20125</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-04-01T02:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Auth Rejected but still allowing access to the network?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81598#M20126</link>
      <description>Do you have a move-fail-action configured for netlogin?</description>
      <pubDate>Tue, 02 Apr 2019 03:33:53 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81598#M20126</guid>
      <dc:creator>StephenW</dc:creator>
      <dc:date>2019-04-02T03:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Auth Rejected but still allowing access to the network?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81599#M20127</link>
      <description>Hi Stephen,&lt;BR /&gt;
&lt;BR /&gt;
I've managed this for the time being by changing the authentication to required, and instead of sending a reject I am assigning a 'Deny' policy. This seems to work.&lt;BR /&gt;
&lt;BR /&gt;
The problem I need to solve later is configuring a method that allows devices to connect to the network should both the NAC's fail. A very unlikely scenario, but the scare is it still being a slight possibly nonetheless and the worry of being completely locked out of the network.&lt;BR /&gt;
&lt;BR /&gt;
Anyway, none of these commands seem to be available on the switch?&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;enable netlogin authentication failure vlan ports &lt;BR /&gt;configure netlogin authentication failure vlan &lt;BR /&gt;configure netlogin authentication service-unavailable vlan&lt;BR /&gt;enable netlogin authentication service-unavailable vlan ports&lt;BR /&gt;configure netlogin move-fail-action authenticate&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
Could be missing something from my NetLogin configuration, which was all added via XMC:&lt;BR /&gt;
&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;enable netlogin dot1x mac &lt;BR /&gt;enable netlogin ports 1:1-40,2:1-40,3:1-40,4:1-40 dot1x &lt;BR /&gt;enable netlogin ports 1:1-48,2:1-48,3:1-48,4:1-48 mac &lt;BR /&gt;configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48 encrypted "#$6f3bLrPkp2YVthcq0KVaUTd3tAiE5g=="&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;
&lt;BR /&gt;
Switch X450G2 version 22.6.1.4&lt;BR /&gt;
&lt;BR /&gt;
Thanks.</description>
      <pubDate>Mon, 08 Apr 2019 20:23:04 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81599#M20127</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2019-04-08T20:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: MAC Auth Rejected but still allowing access to the network?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81600#M20128</link>
      <description>With your config, each authenticated device should be assigned VLANs based on their MAC address.  The behavior you are seeing is wrong.  I would recommend running a quick test on 22.5 patch 1-3 to see if you get different results.</description>
      <pubDate>Mon, 08 Apr 2019 21:10:57 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mac-auth-rejected-but-still-allowing-access-to-the-network/m-p/81600#M20128</guid>
      <dc:creator>StephenW</dc:creator>
      <dc:date>2019-04-08T21:10:57Z</dc:date>
    </item>
  </channel>
</rss>

