<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VLAN-Tunnel-Attr change on reauthentication has no effect in ExtremeSwitching (Other)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-other/vlan-tunnel-attr-change-on-reauthentication-has-no-effect/m-p/10238#M1266</link>
    <description>Say the VLAN-Tunnel-Attr as previously returned by Radius is X.&lt;BR /&gt;
We change the Radius config to return Y.&lt;BR /&gt;
After reauthentication (via "set macauth macreauthenticate MACADDRESS") we correctly see  the new VLAN-Tunnel-Attr Y using "show vlanauth session" etc.&lt;BR /&gt;
However the device apparently still is in the old VLAN X. (still pings)&lt;BR /&gt;
When I disable/enable the port, the VLAN is set alright according to the current Radius setting to Y. (device no longer pings (which is normal since here Y is an isolated VLAN)&lt;BR /&gt;
Is this normal that I have to port down/up, and that reauth has no effect here?&lt;BR /&gt;
&lt;BR /&gt;
(C3 6.61.13)&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;UPDATE&lt;/B&gt; Seems to behave that way only when either VLAN X or Y is set as the static PVID for that port too. Why do I do that? Well, I don't want to completely rely on Radius. I want to have all connections working even if Radius is not there, except for MACs that I specifically like to "blackhole" which I would do by a Radius-Accept with a "blackhole" VLAN. (In essence the static PVID is the default/fallback VLAN in case all else fails.)&lt;BR /&gt;</description>
    <pubDate>Mon, 08 Dec 2014 09:39:00 GMT</pubDate>
    <dc:creator>jeronimo</dc:creator>
    <dc:date>2014-12-08T09:39:00Z</dc:date>
    <item>
      <title>VLAN-Tunnel-Attr change on reauthentication has no effect</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/vlan-tunnel-attr-change-on-reauthentication-has-no-effect/m-p/10238#M1266</link>
      <description>Say the VLAN-Tunnel-Attr as previously returned by Radius is X.&lt;BR /&gt;
We change the Radius config to return Y.&lt;BR /&gt;
After reauthentication (via "set macauth macreauthenticate MACADDRESS") we correctly see  the new VLAN-Tunnel-Attr Y using "show vlanauth session" etc.&lt;BR /&gt;
However the device apparently still is in the old VLAN X. (still pings)&lt;BR /&gt;
When I disable/enable the port, the VLAN is set alright according to the current Radius setting to Y. (device no longer pings (which is normal since here Y is an isolated VLAN)&lt;BR /&gt;
Is this normal that I have to port down/up, and that reauth has no effect here?&lt;BR /&gt;
&lt;BR /&gt;
(C3 6.61.13)&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;UPDATE&lt;/B&gt; Seems to behave that way only when either VLAN X or Y is set as the static PVID for that port too. Why do I do that? Well, I don't want to completely rely on Radius. I want to have all connections working even if Radius is not there, except for MACs that I specifically like to "blackhole" which I would do by a Radius-Accept with a "blackhole" VLAN. (In essence the static PVID is the default/fallback VLAN in case all else fails.)&lt;BR /&gt;</description>
      <pubDate>Mon, 08 Dec 2014 09:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/vlan-tunnel-attr-change-on-reauthentication-has-no-effect/m-p/10238#M1266</guid>
      <dc:creator>jeronimo</dc:creator>
      <dc:date>2014-12-08T09:39:00Z</dc:date>
    </item>
  </channel>
</rss>

