<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EXOS VSA 211 untagged not working in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-vsa-211-untagged-not-working/m-p/99113#M22276</link>
    <description>&lt;P&gt;Have you enabled policy (I assume so as you have dynamic authorization enabled) ?&lt;/P&gt;&lt;P&gt;If so, then EXOS does not honor VSA211, only the attributes mentioned in the userguide for policy and only if you enable maptable response both and vlanauthorization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jan 2024 13:15:51 GMT</pubDate>
    <dc:creator>OscarK</dc:creator>
    <dc:date>2024-01-30T13:15:51Z</dc:date>
    <item>
      <title>EXOS VSA 211 untagged not working</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-vsa-211-untagged-not-working/m-p/99104#M22274</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i'm trying to authenticate client via dot1x (EAP-TLS), RADIUS and netlogin.&lt;BR /&gt;Our Radius Server is sending the VSA211 Attribute in the Accept Message but the EXOS Switch does not put the Client in the specified VLAN.&lt;BR /&gt;&lt;BR /&gt;Radius Attribut:&lt;BR /&gt;&lt;SPAN&gt;Extreme-Netlogin-Extended-Vlan=U5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Wireshark Capture:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="netjradm_0-1706601802201.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6975i60E94CE5A1E676A4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="netjradm_0-1706601802201.png" alt="netjradm_0-1706601802201.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;exos debug&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="netjradm_1-1706601949375.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6976i27FF86349C9B6CE0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="netjradm_1-1706601949375.png" alt="netjradm_1-1706601949375.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;when i configure the radius server to send the vlan via Tunnel-Group-ID the end device is moved to the correct vlan.&lt;/P&gt;&lt;P&gt;wireshark capture&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="netjradm_3-1706603014008.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6978iDB947DEF334A833D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="netjradm_3-1706603014008.png" alt="netjradm_3-1706603014008.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;netlogin debug&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="netjradm_2-1706602995720.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6977iD0441DEBB887DF31/image-size/medium?v=v2&amp;amp;px=400" role="button" title="netjradm_2-1706602995720.png" alt="netjradm_2-1706602995720.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Switch Config:&amp;nbsp;&lt;/P&gt;&lt;P&gt;configure radius netlogin primary server XXX.XXX.XXX.XXX 1812 client-ip XXX.XXX.XXX.XXX vr VR-Default&lt;BR /&gt;configure radius netlogin primary shared-secret encrypted "secret"&lt;BR /&gt;configure radius netlogin secondary server XXX.XXX.XXX.XXX 1812 client-ip XXX.XXX.XXX.XXX vr VR-Default&lt;BR /&gt;configure radius netlogin secondary shared-secret encrypted "secret"&lt;BR /&gt;configure radius dynamic-authorization 1 server XXX.XXX.XXX.XXX client-ip XXX.XXX.XXX.XXX vr VR-Default shared-secret encrypted "secret"&lt;BR /&gt;configure radius dynamic-authorization 2 server XXX.XXX.XXX.XXX client-ip XXX.XXX.XXX.XXX vr VR-Default shared-secret encrypted "secret"&lt;BR /&gt;enable radius&lt;BR /&gt;disable radius mgmt-access&lt;BR /&gt;enable radius netlogin&lt;BR /&gt;enable radius dynamic-authorization&lt;BR /&gt;enable netlogin dot1x&lt;BR /&gt;enable netlogin ports 3-8 dot1x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 08:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-vsa-211-untagged-not-working/m-p/99104#M22274</guid>
      <dc:creator>netjradm</dc:creator>
      <dc:date>2024-01-30T08:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS VSA 211 untagged not working</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-vsa-211-untagged-not-working/m-p/99113#M22276</link>
      <description>&lt;P&gt;Have you enabled policy (I assume so as you have dynamic authorization enabled) ?&lt;/P&gt;&lt;P&gt;If so, then EXOS does not honor VSA211, only the attributes mentioned in the userguide for policy and only if you enable maptable response both and vlanauthorization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:15:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-vsa-211-untagged-not-working/m-p/99113#M22276</guid>
      <dc:creator>OscarK</dc:creator>
      <dc:date>2024-01-30T13:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS VSA 211 untagged not working</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-vsa-211-untagged-not-working/m-p/99178#M22296</link>
      <description>&lt;P&gt;yes i have configured one policy for the ap's ( Tagging multiple vlans and activate auth override)&lt;BR /&gt;So the VSA211 only works when there is no policy on the switch?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 14:13:53 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-vsa-211-untagged-not-working/m-p/99178#M22296</guid>
      <dc:creator>netjradm</dc:creator>
      <dc:date>2024-02-01T14:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS VSA 211 untagged not working</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-vsa-211-untagged-not-working/m-p/99252#M22303</link>
      <description>&lt;P&gt;yes., but as you can assign vlans through the policy itself (pvid) you don't need VSA 211. Checkout table 114 in the userguide for vsa's supported with OnePolicy enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;Table 114: Supported Access-Accept Attributes for ONEPolicy&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 13:34:52 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-vsa-211-untagged-not-working/m-p/99252#M22303</guid>
      <dc:creator>OscarK</dc:creator>
      <dc:date>2024-02-06T13:34:52Z</dc:date>
    </item>
  </channel>
</rss>

