<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to allow IP phone on netlogin port but authenticate Computer behind IP Phone? in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-allow-ip-phone-on-netlogin-port-but-authenticate-computer/m-p/97644#M22123</link>
    <description>&lt;P&gt;As the title suggests, i would like to know how to allow a IP Phone (Specifically Avaya phones) to connect to a port with netlogin enabled, but it would still authenticate the device that connects through the IP Phone.&lt;/P&gt;&lt;P&gt;We are trying to move setup from ERS4900 series to a 5320 series switch, so the commands on the two are different and how to set up authentication on the ports are also different. And with the new Exos having Eapol commands removed we are trying to figure out how to use netlogin for our setup.&lt;/P&gt;&lt;P&gt;Currently what we tried is to have 802.1x netlogin configured with vlans changing based on our NAC rules. but we cant seem to get the IP phone to be authenticated, we even tried making a rule on the NAC to allow it but it isnt doing so at the moment and we even tried MAC authentication but that is not working.&lt;/P&gt;&lt;P&gt;currently the setup for just dot1x is like this:&lt;BR /&gt;create vlan nt_login&lt;BR /&gt;configure netlogin vlan nt_login&lt;BR /&gt;enable netlogin dot1x&lt;BR /&gt;enable netlogin ports 1-6 dot1x&lt;BR /&gt;configure radius netlogin primary server NAC_IP client-ip Switch_IP vr VR-Default shared-secret Kanoo@123&lt;BR /&gt;create vlan VLAN1 tag 40&lt;BR /&gt;create vlan VLAN2 tag 50&lt;BR /&gt;create vlan Voip tag 60&lt;BR /&gt;enable ports 1-6,24&lt;BR /&gt;configure vlan VLAN1 add ports 24 tagged&lt;BR /&gt;configure vlan VLAN2 add ports 24 tagged&lt;BR /&gt;configure vlan Voip add ports 24 tagged&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are the sources i used so far:&lt;BR /&gt;&lt;A href="https://extreme-networks.my.site.com/ExtrArticleDetail?an=000081809" target="_blank"&gt;https://extreme-networks.my.site.com/ExtrArticleDetail?an=000081809&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://extreme-networks.my.site.com/ExtrArticleDetail?an=000080274&amp;amp;q=netlogin%20and%20access%20ports" target="_blank"&gt;https://extreme-networks.my.site.com/ExtrArticleDetail?an=000080274&amp;amp;q=netlogin%20and%20access%20ports&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2023 06:11:46 GMT</pubDate>
    <dc:creator>Sami117</dc:creator>
    <dc:date>2023-10-24T06:11:46Z</dc:date>
    <item>
      <title>How to allow IP phone on netlogin port but authenticate Computer behind IP Phone?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-allow-ip-phone-on-netlogin-port-but-authenticate-computer/m-p/97644#M22123</link>
      <description>&lt;P&gt;As the title suggests, i would like to know how to allow a IP Phone (Specifically Avaya phones) to connect to a port with netlogin enabled, but it would still authenticate the device that connects through the IP Phone.&lt;/P&gt;&lt;P&gt;We are trying to move setup from ERS4900 series to a 5320 series switch, so the commands on the two are different and how to set up authentication on the ports are also different. And with the new Exos having Eapol commands removed we are trying to figure out how to use netlogin for our setup.&lt;/P&gt;&lt;P&gt;Currently what we tried is to have 802.1x netlogin configured with vlans changing based on our NAC rules. but we cant seem to get the IP phone to be authenticated, we even tried making a rule on the NAC to allow it but it isnt doing so at the moment and we even tried MAC authentication but that is not working.&lt;/P&gt;&lt;P&gt;currently the setup for just dot1x is like this:&lt;BR /&gt;create vlan nt_login&lt;BR /&gt;configure netlogin vlan nt_login&lt;BR /&gt;enable netlogin dot1x&lt;BR /&gt;enable netlogin ports 1-6 dot1x&lt;BR /&gt;configure radius netlogin primary server NAC_IP client-ip Switch_IP vr VR-Default shared-secret Kanoo@123&lt;BR /&gt;create vlan VLAN1 tag 40&lt;BR /&gt;create vlan VLAN2 tag 50&lt;BR /&gt;create vlan Voip tag 60&lt;BR /&gt;enable ports 1-6,24&lt;BR /&gt;configure vlan VLAN1 add ports 24 tagged&lt;BR /&gt;configure vlan VLAN2 add ports 24 tagged&lt;BR /&gt;configure vlan Voip add ports 24 tagged&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are the sources i used so far:&lt;BR /&gt;&lt;A href="https://extreme-networks.my.site.com/ExtrArticleDetail?an=000081809" target="_blank"&gt;https://extreme-networks.my.site.com/ExtrArticleDetail?an=000081809&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://extreme-networks.my.site.com/ExtrArticleDetail?an=000080274&amp;amp;q=netlogin%20and%20access%20ports" target="_blank"&gt;https://extreme-networks.my.site.com/ExtrArticleDetail?an=000080274&amp;amp;q=netlogin%20and%20access%20ports&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 06:11:46 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-to-allow-ip-phone-on-netlogin-port-but-authenticate-computer/m-p/97644#M22123</guid>
      <dc:creator>Sami117</dc:creator>
      <dc:date>2023-10-24T06:11:46Z</dc:date>
    </item>
  </channel>
</rss>

