<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled) in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121963#M3220</link>
    <description>&lt;P&gt;The&amp;nbsp;Tunnel-Private-Group-Id attribute (Template Extreme VOSS) is not designed to work on auto-sense / flex-uni access ports. It will only work if there is already a platform VLAN object on the switch.&lt;/P&gt;&lt;P&gt;Auto-sense is what you want to keep on access ports, and NAC uses flex-uni on auto-sense ports, which can be added to any I-SID (without any need for platform VLANs on the switch).&amp;nbsp;&lt;/P&gt;&lt;P&gt;The correct RADIUS template is&amp;nbsp;Extreme VOSS - Fabric Attach" if not using XIQ-SE Policy, or&amp;nbsp; "Extreme VOSS - Per-User-ACL" if using XIQ-SE Policy.&lt;/P&gt;&lt;P&gt;There is a Sandbox that Extreme partners can reserve to understand how to deploy a fully zero-touch automated Fabric Edge with NAC; ask your Extreme sales rep to reserve it for you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jun 2026 15:44:28 GMT</pubDate>
    <dc:creator>Ludovico</dc:creator>
    <dc:date>2026-06-17T15:44:28Z</dc:date>
    <item>
      <title>ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121958#M3219</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;we are looking to set up ZTP+ Fabric, including Extreme Control (NAC), for one of our customers.&lt;/P&gt;&lt;P&gt;In this case, the customer wants to minimize the need for CLI-based switch configuration as much as possible.&lt;/P&gt;&lt;P&gt;In principle, the onboarding of the fabric switches via the workflow is working as intended.&lt;/P&gt;&lt;P&gt;However, we are having trouble getting NAC to work on the end-device ports.&lt;/P&gt;&lt;P&gt;The customer wishes to continue using their legacy Control configuration to pass the VLAN to the switch via RADIUS attributes (using the "Extreme VOSS" RADIUS template).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_0-1781691551235.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9398iA4A82E046805EF5E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_0-1781691551235.png" alt="JPavel_0-1781691551235.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The rule set and mapping within Control appear to be correct, as the end-system logs clearly show the correct VLAN attributes being returned:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_1-1781691551237.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9399iEE645CD44976E065/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_1-1781691551237.png" alt="JPavel_1-1781691551237.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_2-1781691551238.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9400i62757331237E1D96/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_2-1781691551238.png" alt="JPavel_2-1781691551238.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, we observe that the switch port ignores the VLAN attribute, meaning the port is not authorized for the target VLAN.&lt;/P&gt;&lt;P&gt;Consequently, the port remains stuck in the onboarding VLAN (4048):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_3-1781691551238.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9403iE84895686114EF82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_3-1781691551238.png" alt="JPavel_3-1781691551238.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_4-1781691551239.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9402i1D2839C2748724E9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_4-1781691551239.png" alt="JPavel_4-1781691551239.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_5-1781691551239.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9401i7CC81EF515C81B91/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_5-1781691551239.png" alt="JPavel_5-1781691551239.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To check if the issue might be related to the legacy VLAN configuration, we also ran tests using the "Extreme VOSS - Fabric Attach" and "Extreme VOSS - Per-User-ACL" RADIUS templates, defining the corresponding policy roles in the policy domain.&lt;/P&gt;&lt;P&gt;The behavior, however, was exactly the same. The end-system logs showed that the correct policy role value was forwarded to the switch (FilterID=&amp;lt;Policy-Role&amp;gt;), but the switch ignored it, and the port remained stuck in the onboarding VLAN (4048).&lt;/P&gt;&lt;P&gt;To get NAC working, we had to enable "auto-sense" on the ports and configure eapol for the interfaces:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_6-1781691551239.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9404i40E676D5BF2E3BA7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_6-1781691551239.png" alt="JPavel_6-1781691551239.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;(Because we did a simple tests with MAC authentication we had to add the guest-vlan here)&lt;/P&gt;&lt;P&gt;Once that was done, the switch correctly recognized the RADIUS VLAN attribute and successfully moved the port into the appropriate VLAN:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_7-1781691551240.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9405i19F770F91781493C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_7-1781691551240.png" alt="JPavel_7-1781691551240.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_8-1781691551240.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9406i43B40AC9635A79BE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_8-1781691551240.png" alt="JPavel_8-1781691551240.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_9-1781691551241.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9407iA451DAB83681EFB1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_9-1781691551241.png" alt="JPavel_9-1781691551241.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_10-1781691551241.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9408iD7DC3D5CC81DC444/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_10-1781691551241.png" alt="JPavel_10-1781691551241.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am now wondering whether it is even possible to get NAC working when "auto-sense" is enabled on the end-device ports.&lt;/P&gt;&lt;P&gt;I tried setting the "auto-sense wait-interval" to 2 seconds to rule out potential timeout issues, but that didn't help.&lt;/P&gt;&lt;P&gt;Can anyone assist me with this?&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Joerg&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 10:20:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121958#M3219</guid>
      <dc:creator>JPavel</dc:creator>
      <dc:date>2026-06-17T10:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121963#M3220</link>
      <description>&lt;P&gt;The&amp;nbsp;Tunnel-Private-Group-Id attribute (Template Extreme VOSS) is not designed to work on auto-sense / flex-uni access ports. It will only work if there is already a platform VLAN object on the switch.&lt;/P&gt;&lt;P&gt;Auto-sense is what you want to keep on access ports, and NAC uses flex-uni on auto-sense ports, which can be added to any I-SID (without any need for platform VLANs on the switch).&amp;nbsp;&lt;/P&gt;&lt;P&gt;The correct RADIUS template is&amp;nbsp;Extreme VOSS - Fabric Attach" if not using XIQ-SE Policy, or&amp;nbsp; "Extreme VOSS - Per-User-ACL" if using XIQ-SE Policy.&lt;/P&gt;&lt;P&gt;There is a Sandbox that Extreme partners can reserve to understand how to deploy a fully zero-touch automated Fabric Edge with NAC; ask your Extreme sales rep to reserve it for you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 15:44:28 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121963#M3220</guid>
      <dc:creator>Ludovico</dc:creator>
      <dc:date>2026-06-17T15:44:28Z</dc:date>
    </item>
  </channel>
</rss>

