<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: NAC + Active Directory + Wifi Users authentication in ExtremeSwitching (Other)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10546#M1574</link>
    <description>Hi, Ilya!&lt;BR /&gt;
&lt;BR /&gt;
NAC gateway - is NAC appliance.&lt;BR /&gt;
(gateway is exactly NAC, management from XMC GUI)&lt;BR /&gt;
&lt;BR /&gt;
Thank you!</description>
    <pubDate>Tue, 16 Jan 2018 23:19:00 GMT</pubDate>
    <dc:creator>Alexandr_P</dc:creator>
    <dc:date>2018-01-16T23:19:00Z</dc:date>
    <item>
      <title>NAC + Active Directory + Wifi Users authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10542#M1570</link>
      <description>Hello, everybody,&lt;BR /&gt;
&lt;BR /&gt;
please, let me know whether goals below are possible or not and answer some of my questions:&lt;BR /&gt;
&lt;BR /&gt;
1) I would like to create NAC authorization portal for desktop and mobile users like this (I mean - exactly the same):&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="833e34aecddb444aaf2aa7a1ee74a01f_RackMultipart20180116-44568-suhk0s-222_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4688iC9AC2D6104ED4A02/image-size/large?v=v2&amp;amp;px=999" role="button" title="833e34aecddb444aaf2aa7a1ee74a01f_RackMultipart20180116-44568-suhk0s-222_inline.jpg" alt="833e34aecddb444aaf2aa7a1ee74a01f_RackMultipart20180116-44568-suhk0s-222_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
2) I would like to authorize Internet access for wired and wireless (V2110) users using their AD credentials (so, NAC has to get AD account information from several domains)&lt;BR /&gt;
&lt;BR /&gt;
3) I would like to see AD account names for authorized users in Netsight &amp;gt; Control &amp;gt; Endpoints (like OS type and version data)&lt;BR /&gt;
&lt;BR /&gt;
4) I would like to send these usernames to Fortigate FG-600 and get all possible benefits from Extreme&amp;amp;Fortinet integration&lt;BR /&gt;
&lt;BR /&gt;
Is it all possible?&lt;BR /&gt;
&lt;BR /&gt;
My questions are:&lt;BR /&gt;
&lt;BR /&gt;
1) Are there any separated or combined step-by-step manuals for all goals above? Please, share them!&lt;BR /&gt;
&lt;BR /&gt;
2) How to make wired users get authenticated through NAC? For wireless I just set in V2110: VNS &amp;gt; WLAN Services &amp;gt; Auth &amp;amp; Acct &amp;gt; Mode: Authentication type External and set Redirection URL, but how about wired users?&lt;BR /&gt;
&lt;BR /&gt;
3) How could I make NAC to authorize AD users account in several domains?&lt;BR /&gt;
&lt;BR /&gt;
4) And the most difficult question: how could I make Netsight NAC to send usernames in Fortigate? I want get benefits described by Kurt Semba here: &lt;A href="https://community.extremenetworks.com/extreme/topics/does-extreme-still-have-technological-partnership-with-fortinet" target="_blank" rel="nofollow noreferrer noopener"&gt;https://community.extremenetworks.com/extreme/topics/does-extreme-still-have-technological-partnersh...&lt;/A&gt;  &lt;BR /&gt;
&lt;BR /&gt;
I had already bought all the hardware - there are about 100 Summits + Netsight + NAC + V2110 + 100APs + Fortigate FG-600.&lt;BR /&gt;
&lt;BR /&gt;
At the moment authorization portal is on FG-600. It gets user names but, I want to see them in Netsight!&lt;BR /&gt;
&lt;BR /&gt;
Please, help!&lt;BR /&gt;
&lt;BR /&gt;
Many thanks in advance,&lt;BR /&gt;
Ilya&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Jan 2018 22:47:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10542#M1570</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2018-01-16T22:47:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC + Active Directory + Wifi Users authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10543#M1571</link>
      <description>That´s all possible !&lt;BR /&gt;
&lt;BR /&gt;
1. You need to understand what you do. Step-by-step guides can help you to setup the solution but the don´t help you troubleshooting this. User a qualified partner for that or take trainings.&lt;BR /&gt;
2. You can use policies or policy based routing to redirect traffic from wired ports to the NAC portal.&lt;BR /&gt;
3. NAC gateway can deal with domain prefix and contact different LDAP servers&lt;BR /&gt;
4. It´s included in the OneFabric connect install guide&lt;BR /&gt;
&lt;BR /&gt;
Option: Use the FG-600 Portal and redirect RADIUS to NAC-Gateway. You will see the users in XMC.&lt;BR /&gt;
&lt;BR /&gt;
You will need some experience and knowledge of the interfaces to other systems, but it will work.&lt;BR /&gt;
&lt;BR /&gt;
br&lt;BR /&gt;
Volker</description>
      <pubDate>Tue, 16 Jan 2018 23:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10543#M1571</guid>
      <dc:creator>Volker_Kull</dc:creator>
      <dc:date>2018-01-16T23:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC + Active Directory + Wifi Users authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10544#M1572</link>
      <description>Thanks, Volker!&lt;BR /&gt;
&lt;BR /&gt;
What the NAC-Gateway is? &lt;BR /&gt;
&lt;BR /&gt;
You mean, from FG-600 side set NAC as radius server, so FG-600 will authorize users not with AD Domain controllers directly, but through NAC?&lt;BR /&gt;
&lt;BR /&gt;
Am I right?</description>
      <pubDate>Tue, 16 Jan 2018 23:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10544#M1572</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2018-01-16T23:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC + Active Directory + Wifi Users authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10545#M1573</link>
      <description>Hi Ilya !&lt;BR /&gt;
&lt;BR /&gt;
NAC-Gateway is the appliance (virtual or HW) working as a authentication proxy. That means you confg wifi , switch, FW etc. to connect via RADIUS to the NAC-GW. Using the NAC rules you configure via XMC and push it to all NAC-GW, it will connect via RADIUS or LADP to directory services based on the user match rules you define (&lt;DOMAIN1&gt;\* to AD1,  &lt;DOMAIN2&gt;\* to AD2 and so on). Radius proxy means that NAC-GW can change the authentication protocol or use internal DB(f.e. for MAC-Auth) . NAC-GW provide also a web portal with different options: splash, account, sponsoring, social media login, self service.&lt;BR /&gt;
&lt;BR /&gt;
We use NAC for brach office authentication on FG-50/60..., Juniper, ...&lt;BR /&gt;
All is absolutely conform with the standards (802.1X, PEAP, TLS, RADIUS, RFC3580, ...)&lt;BR /&gt;
&lt;BR /&gt;
So you will have a lot of options that makes XMC/NAC/Analytics a pearl in infrastructure&amp;amp;security management and monitoring. No other vendor can beat this !&lt;BR /&gt;
&lt;BR /&gt;
br&lt;BR /&gt;
Volker&lt;BR /&gt;
&lt;BR /&gt;&lt;/DOMAIN2&gt;&lt;/DOMAIN1&gt;</description>
      <pubDate>Tue, 16 Jan 2018 23:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10545#M1573</guid>
      <dc:creator>Volker_Kull</dc:creator>
      <dc:date>2018-01-16T23:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC + Active Directory + Wifi Users authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10546#M1574</link>
      <description>Hi, Ilya!&lt;BR /&gt;
&lt;BR /&gt;
NAC gateway - is NAC appliance.&lt;BR /&gt;
(gateway is exactly NAC, management from XMC GUI)&lt;BR /&gt;
&lt;BR /&gt;
Thank you!</description>
      <pubDate>Tue, 16 Jan 2018 23:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/nac-active-directory-wifi-users-authentication/m-p/10546#M1574</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2018-01-16T23:19:00Z</dc:date>
    </item>
  </channel>
</rss>

