<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Netlogin Assign VLAN not working in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/netlogin-assign-vlan-not-working/m-p/87296#M20816</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt; &lt;P&gt;We want netlogin to work a follows:&lt;/P&gt; &lt;OL&gt;&lt;LI&gt;authenticated by dot1x then keep port native vlan&lt;/LI&gt; &lt;LI&gt;if no dot1x, authenticated by RADIUS MAC auth then&amp;nbsp;keep port native vlan&lt;/LI&gt; &lt;LI&gt;if no dot1x or mac auth, RADIUS will still authenticate the port, but place it in a specific VLAN&lt;/LI&gt; &lt;/OL&gt;&lt;P&gt;dot1x and radius mac auth both work independently, however, the vlan is not set when the radius engine sends the attribute (Extreme-Netlogin-Extended-VLAN = U&amp;lt;vlan name&amp;gt;)&lt;/P&gt; &lt;P&gt;I see in the logs (see excerpt below) that the switch is correctly receiving the vlan (TCC_Main) and assigning it, and I can see this on the port - it quickly switches to the new VLAN, before reverting to the port native VLAN, but then the switch seems to send a radius accouting stop which kills the process.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;03/20/2020 11:39:23.09 &amp;lt;Info:AAA.RADIUS.RecvRspns&amp;gt; Received an Accounting Stop Response (packet length 20, destination UDP port 32769, id 162) from accounting server #primary netlogin for 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') on port 2.&lt;BR /&gt; 03/20/2020 11:39:23.09 &amp;lt;Info:AAA.RADIUS.sendSuccess&amp;gt; Accounting Stop Request(packet length 133, source UDP port 32769, id 162) sent to server #primary netlogin for user 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') for the macauthentication agent on port 2&lt;BR /&gt; 03/20/2020 11:39:23.08 &amp;lt;Info:AAA.RADIUS.ApiReq&amp;gt; Accounting stop for 04-0E-3C-D5-AB-5C(username '040E3CD5AB5C') on port 2.&lt;BR /&gt; 03/20/2020 11:39:23.08 &amp;lt;Info:AAA.RADIUS.RecvRspns&amp;gt; Received an Accounting Start Response (packet length 20, destination UDP port 32769, id 161) from accounting server #primary netlogin for 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') on port 2.&lt;BR /&gt; 03/20/2020 11:39:23.07 &amp;lt;Info:AAA.RADIUS.sendSuccess&amp;gt; Accounting Start Request(packet length 121, source UDP port 32769, id 161) sent to server #primary netlogin for user 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') for the macauthentication agent on port 2&lt;BR /&gt; 03/20/2020 11:39:23.06 &amp;lt;Info:AAA.RADIUS.ApiReq&amp;gt; Accounting start for 04-0E-3C-D5-AB-5C(username '040E3CD5AB5C') on port 2.&lt;BR /&gt; 03/20/2020 11:39:23.04 &amp;lt;Info:nl.ClientAuthenticated&amp;gt; Network Login MAC user 040E3CD5AB5C logged in MAC 04:0E:3C:D5:AB:5C port 2 VLAN(s) "TCC_Main", authentication Radius&lt;BR /&gt; 03/20/2020 11:39:22.98 &amp;lt;Info:AAA.RADIUS.RecvRspns&amp;gt; Received an access accept (packet length 51, destination UDP port 32769, id 160) from authentication server #primary netlogin for 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') on port 2.&lt;BR /&gt; 03/20/2020 11:39:22.97 &amp;lt;Info:AAA.RADIUS.sendSuccess&amp;gt; Access Request(packet length 136, source UDP port 32769, id 160) sent to server #primary netlogin for user 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') for the macauthentication agent on port 2&lt;BR /&gt; &amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Netlogin config:&lt;/P&gt; &lt;P&gt;enable netlogin dot1x mac&lt;BR /&gt; configure netlogin mac authentication database-order radius&lt;BR /&gt; configure netlogin authentication protocol-order dot1x mac web-based&lt;BR /&gt; configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48&lt;BR /&gt; enable netlogin ports 2 dot1x&lt;BR /&gt; enable netlogin ports 2 mac&lt;BR /&gt; configure netlogin ports 2 mode port-based-vlans&lt;BR /&gt; configure netlogin ports 2 no-restart&lt;BR /&gt; configure netlogin ports 2 allow egress-traffic all_cast&lt;BR /&gt; &amp;nbsp;&lt;/P&gt; &lt;P&gt;How do I need to configure the switch for it to work as intended?&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Thanks,&lt;/P&gt; &lt;P&gt;Shannon&lt;/P&gt;</description>
    <pubDate>Fri, 20 Mar 2020 05:46:30 GMT</pubDate>
    <dc:creator>Shannon_Rowe1</dc:creator>
    <dc:date>2020-03-20T05:46:30Z</dc:date>
    <item>
      <title>Netlogin Assign VLAN not working</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/netlogin-assign-vlan-not-working/m-p/87296#M20816</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt; &lt;P&gt;We want netlogin to work a follows:&lt;/P&gt; &lt;OL&gt;&lt;LI&gt;authenticated by dot1x then keep port native vlan&lt;/LI&gt; &lt;LI&gt;if no dot1x, authenticated by RADIUS MAC auth then&amp;nbsp;keep port native vlan&lt;/LI&gt; &lt;LI&gt;if no dot1x or mac auth, RADIUS will still authenticate the port, but place it in a specific VLAN&lt;/LI&gt; &lt;/OL&gt;&lt;P&gt;dot1x and radius mac auth both work independently, however, the vlan is not set when the radius engine sends the attribute (Extreme-Netlogin-Extended-VLAN = U&amp;lt;vlan name&amp;gt;)&lt;/P&gt; &lt;P&gt;I see in the logs (see excerpt below) that the switch is correctly receiving the vlan (TCC_Main) and assigning it, and I can see this on the port - it quickly switches to the new VLAN, before reverting to the port native VLAN, but then the switch seems to send a radius accouting stop which kills the process.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;03/20/2020 11:39:23.09 &amp;lt;Info:AAA.RADIUS.RecvRspns&amp;gt; Received an Accounting Stop Response (packet length 20, destination UDP port 32769, id 162) from accounting server #primary netlogin for 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') on port 2.&lt;BR /&gt; 03/20/2020 11:39:23.09 &amp;lt;Info:AAA.RADIUS.sendSuccess&amp;gt; Accounting Stop Request(packet length 133, source UDP port 32769, id 162) sent to server #primary netlogin for user 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') for the macauthentication agent on port 2&lt;BR /&gt; 03/20/2020 11:39:23.08 &amp;lt;Info:AAA.RADIUS.ApiReq&amp;gt; Accounting stop for 04-0E-3C-D5-AB-5C(username '040E3CD5AB5C') on port 2.&lt;BR /&gt; 03/20/2020 11:39:23.08 &amp;lt;Info:AAA.RADIUS.RecvRspns&amp;gt; Received an Accounting Start Response (packet length 20, destination UDP port 32769, id 161) from accounting server #primary netlogin for 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') on port 2.&lt;BR /&gt; 03/20/2020 11:39:23.07 &amp;lt;Info:AAA.RADIUS.sendSuccess&amp;gt; Accounting Start Request(packet length 121, source UDP port 32769, id 161) sent to server #primary netlogin for user 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') for the macauthentication agent on port 2&lt;BR /&gt; 03/20/2020 11:39:23.06 &amp;lt;Info:AAA.RADIUS.ApiReq&amp;gt; Accounting start for 04-0E-3C-D5-AB-5C(username '040E3CD5AB5C') on port 2.&lt;BR /&gt; 03/20/2020 11:39:23.04 &amp;lt;Info:nl.ClientAuthenticated&amp;gt; Network Login MAC user 040E3CD5AB5C logged in MAC 04:0E:3C:D5:AB:5C port 2 VLAN(s) "TCC_Main", authentication Radius&lt;BR /&gt; 03/20/2020 11:39:22.98 &amp;lt;Info:AAA.RADIUS.RecvRspns&amp;gt; Received an access accept (packet length 51, destination UDP port 32769, id 160) from authentication server #primary netlogin for 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') on port 2.&lt;BR /&gt; 03/20/2020 11:39:22.97 &amp;lt;Info:AAA.RADIUS.sendSuccess&amp;gt; Access Request(packet length 136, source UDP port 32769, id 160) sent to server #primary netlogin for user 04-0E-3C-D5-AB-5C(userName '040E3CD5AB5C') for the macauthentication agent on port 2&lt;BR /&gt; &amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Netlogin config:&lt;/P&gt; &lt;P&gt;enable netlogin dot1x mac&lt;BR /&gt; configure netlogin mac authentication database-order radius&lt;BR /&gt; configure netlogin authentication protocol-order dot1x mac web-based&lt;BR /&gt; configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48&lt;BR /&gt; enable netlogin ports 2 dot1x&lt;BR /&gt; enable netlogin ports 2 mac&lt;BR /&gt; configure netlogin ports 2 mode port-based-vlans&lt;BR /&gt; configure netlogin ports 2 no-restart&lt;BR /&gt; configure netlogin ports 2 allow egress-traffic all_cast&lt;BR /&gt; &amp;nbsp;&lt;/P&gt; &lt;P&gt;How do I need to configure the switch for it to work as intended?&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Thanks,&lt;/P&gt; &lt;P&gt;Shannon&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 05:46:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/netlogin-assign-vlan-not-working/m-p/87296#M20816</guid>
      <dc:creator>Shannon_Rowe1</dc:creator>
      <dc:date>2020-03-20T05:46:30Z</dc:date>
    </item>
  </channel>
</rss>

