<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Does Extreme still have technological partnership with Fortinet? in ExtremeSwitching (Other)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9322#M350</link>
    <description>Hi Ilya,&lt;BR /&gt;
&lt;BR /&gt;
the current integration is meant to use Extreme Control to authenticate the users and then send this data to the Fortigate - not the other way around.&lt;BR /&gt;
&lt;BR /&gt;
With XMC v8.1 we will introduce a new API that allows us to create new end-systems via a REST interface. This could be used to implement what you are asking for but this feature is not yet planned.&lt;BR /&gt;
&lt;BR /&gt;
Do you know how Fortigate could send authentication data to XMC? Or does Fortigate provide a scripting engine that can be triggered whenever a new user is authenticated?</description>
    <pubDate>Tue, 16 Jan 2018 16:44:00 GMT</pubDate>
    <dc:creator>Kurt_Semba</dc:creator>
    <dc:date>2018-01-16T16:44:00Z</dc:date>
    <item>
      <title>Does Extreme still have technological partnership with Fortinet?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9319#M347</link>
      <description>Hello, everybody,&lt;BR /&gt;
&lt;BR /&gt;
I have a client which has FG-600 and X430 access switches with Netsight&amp;amp;NAC.&lt;BR /&gt;
&lt;BR /&gt;
What benefits could I get from Forti&amp;amp;Extreme integration in this case? If it's still possible...&lt;BR /&gt;
&lt;BR /&gt;
Thanks.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Jan 2018 16:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9319#M347</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2018-01-16T16:36:00Z</dc:date>
    </item>
    <item>
      <title>RE: Does Extreme still have technological partnership with Fortinet?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9320#M348</link>
      <description>Hi Ilya,&lt;BR /&gt;
&lt;BR /&gt;
the FortiGate solutions are actually 2 integrations. &lt;BR /&gt;
&lt;BR /&gt;
    The first integration is the single sign-on which uses RADIUS  accounting.  The integration uses the ExtremeControl notification engine  and listens for end system updates.  When an end system that has a  username and IP address transitions to an accept state, we send a RADIUS  accounting start message to the FortiGate to start the session.  When the  end system transitions to the disconnected state, we send a RADIUS accounting  stop message to end the session.  We have the option to send the RADIUS accounting  interim message to keep the session alive. &lt;BR /&gt;
&lt;BR /&gt;
  The Fortinet filtering rules are accomplished by adding a RADIUS attribute  called profile.  The value of profile is the ExtremeControl profile  name.  This creates a mapping in the FortiGate where the ExtremeControl  profile name is associated to a user group.  Filtering rules can now be  created where rules are applied to specific user groups.&lt;BR /&gt;
&lt;BR /&gt;
    The 2nd integration is the distributed IPS.  This  solution is generic and works with multiple firewalls.  It’s an event driven  solution that relies on matching a regular expression with the event  message.  When a regular expression match is found, we parse out the  threat IP, threat MAC, or threat name and take action.  Currently the  action is adding the threat to an end system group and applying different  network access for the device.&lt;BR /&gt;
&lt;BR /&gt;
    Hope that helps and makes sense.&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Jan 2018 16:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9320#M348</guid>
      <dc:creator>Kurt_Semba</dc:creator>
      <dc:date>2018-01-16T16:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Does Extreme still have technological partnership with Fortinet?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9321#M349</link>
      <description>Hi, Kurt! Thanks for your reply!&lt;BR /&gt;
&lt;BR /&gt;
At the moment Fortigate authenticate Wi-Fi users with their Active Directory Credentials.&lt;BR /&gt;
&lt;BR /&gt;
Could I make Fortigate to send authentication data to the Netsight? I want to see usernames in Netsight &amp;gt; Control &amp;gt; Endsystems&lt;BR /&gt;
&lt;BR /&gt;
Is it possible?</description>
      <pubDate>Tue, 16 Jan 2018 16:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9321#M349</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2018-01-16T16:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Does Extreme still have technological partnership with Fortinet?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9322#M350</link>
      <description>Hi Ilya,&lt;BR /&gt;
&lt;BR /&gt;
the current integration is meant to use Extreme Control to authenticate the users and then send this data to the Fortigate - not the other way around.&lt;BR /&gt;
&lt;BR /&gt;
With XMC v8.1 we will introduce a new API that allows us to create new end-systems via a REST interface. This could be used to implement what you are asking for but this feature is not yet planned.&lt;BR /&gt;
&lt;BR /&gt;
Do you know how Fortigate could send authentication data to XMC? Or does Fortigate provide a scripting engine that can be triggered whenever a new user is authenticated?</description>
      <pubDate>Tue, 16 Jan 2018 16:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9322#M350</guid>
      <dc:creator>Kurt_Semba</dc:creator>
      <dc:date>2018-01-16T16:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Does Extreme still have technological partnership with Fortinet?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9323#M351</link>
      <description>Kurt,&lt;BR /&gt;
&lt;BR /&gt;
I would like to authorize Active Directory users through customized NAC portal. I know it is possible. &lt;BR /&gt;
&lt;BR /&gt;
Could AD usernames be sent to Fortigate from NAC?&lt;BR /&gt;
&lt;BR /&gt;
Thank you!</description>
      <pubDate>Tue, 16 Jan 2018 16:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9323#M351</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2018-01-16T16:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Does Extreme still have technological partnership with Fortinet?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9324#M352</link>
      <description>Ilya,&lt;BR /&gt;
&lt;BR /&gt;
yes, as far as I know you can configure the NAC portal to perform user authentication against an AD (LDAP). Once the user authenticated, you should see the username and IP address within the NAC end-system list and the user should be in ACCEPT state - is that the case?&lt;BR /&gt;
&lt;BR /&gt;
If so, then the Connect Fortigate integration will forward that data to the Fortigate. No matter where the username is coming from (AD, 1X, portal, etc.). Give it a try and let me know how it goes.&lt;BR /&gt;
&lt;BR /&gt;
Kurt</description>
      <pubDate>Tue, 16 Jan 2018 16:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/does-extreme-still-have-technological-partnership-with-fortinet/m-p/9324#M352</guid>
      <dc:creator>Kurt_Semba</dc:creator>
      <dc:date>2018-01-16T16:44:00Z</dc:date>
    </item>
  </channel>
</rss>

