<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled) in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121990#M3221</link>
    <description>&lt;P&gt;Hi Ludovico,&lt;/P&gt;&lt;P&gt;first of all, thanks for your feedback.&lt;/P&gt;&lt;P&gt;I actually manually created the corresponding platform VLAN on the test switch in our lab, so—in my opinion—the "Extreme VOSS" template should have worked.&lt;/P&gt;&lt;P&gt;Nevertheless, I also ran the same tests in our lab using the "Extreme VOSS - Fabric Attach" and "Extreme VOSS - Per-User-ACL" RADIUS templates which is illustrated in the “NAC in Campus Fabric Edge.pdf“ document.&lt;/P&gt;&lt;P&gt;The result was always the same. I never see the end-device port being pushed untagged into the correct C-VLAN (VLAN 10 in our case) after authentication; it always remains in the onboarding VLAN 4048.&lt;/P&gt;&lt;P&gt;Here the Control Rule Definition and the corresponding Radius Attribute Policy Mapping preview:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_8-1781859615177.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9418i291681D0D0FFC208/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_8-1781859615177.png" alt="JPavel_8-1781859615177.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And the corresponding switch outputs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_9-1781859615178.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9417iB348D513B0524767/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_9-1781859615178.png" alt="JPavel_9-1781859615178.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_10-1781859615178.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9419iF009D1BFB462F734/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_10-1781859615178.png" alt="JPavel_10-1781859615178.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_11-1781859615178.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9420i7FE71BA4AE35D8F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_11-1781859615178.png" alt="JPavel_11-1781859615178.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_12-1781859615179.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9421i51F0554E90ED43D2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_12-1781859615179.png" alt="JPavel_12-1781859615179.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But I probably just have a misunderstanding here, since I come from the EXOS world and am currently getting up to speed on Fabric Connect &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I would have expected the end-device port to be untagged in VLAN 10 at this point.&lt;/P&gt;&lt;P&gt;Regards, Joerg&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jun 2026 09:00:48 GMT</pubDate>
    <dc:creator>JPavel</dc:creator>
    <dc:date>2026-06-19T09:00:48Z</dc:date>
    <item>
      <title>ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121958#M3219</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;&lt;P&gt;we are looking to set up ZTP+ Fabric, including Extreme Control (NAC), for one of our customers.&lt;/P&gt;&lt;P&gt;In this case, the customer wants to minimize the need for CLI-based switch configuration as much as possible.&lt;/P&gt;&lt;P&gt;In principle, the onboarding of the fabric switches via the workflow is working as intended.&lt;/P&gt;&lt;P&gt;However, we are having trouble getting NAC to work on the end-device ports.&lt;/P&gt;&lt;P&gt;The customer wishes to continue using their legacy Control configuration to pass the VLAN to the switch via RADIUS attributes (using the "Extreme VOSS" RADIUS template).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_0-1781691551235.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9398iA4A82E046805EF5E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_0-1781691551235.png" alt="JPavel_0-1781691551235.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The rule set and mapping within Control appear to be correct, as the end-system logs clearly show the correct VLAN attributes being returned:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_1-1781691551237.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9399iEE645CD44976E065/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_1-1781691551237.png" alt="JPavel_1-1781691551237.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_2-1781691551238.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9400i62757331237E1D96/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_2-1781691551238.png" alt="JPavel_2-1781691551238.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, we observe that the switch port ignores the VLAN attribute, meaning the port is not authorized for the target VLAN.&lt;/P&gt;&lt;P&gt;Consequently, the port remains stuck in the onboarding VLAN (4048):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_3-1781691551238.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9403iE84895686114EF82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_3-1781691551238.png" alt="JPavel_3-1781691551238.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_4-1781691551239.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9402i1D2839C2748724E9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_4-1781691551239.png" alt="JPavel_4-1781691551239.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_5-1781691551239.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9401i7CC81EF515C81B91/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_5-1781691551239.png" alt="JPavel_5-1781691551239.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To check if the issue might be related to the legacy VLAN configuration, we also ran tests using the "Extreme VOSS - Fabric Attach" and "Extreme VOSS - Per-User-ACL" RADIUS templates, defining the corresponding policy roles in the policy domain.&lt;/P&gt;&lt;P&gt;The behavior, however, was exactly the same. The end-system logs showed that the correct policy role value was forwarded to the switch (FilterID=&amp;lt;Policy-Role&amp;gt;), but the switch ignored it, and the port remained stuck in the onboarding VLAN (4048).&lt;/P&gt;&lt;P&gt;To get NAC working, we had to enable "auto-sense" on the ports and configure eapol for the interfaces:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_6-1781691551239.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9404i40E676D5BF2E3BA7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_6-1781691551239.png" alt="JPavel_6-1781691551239.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;(Because we did a simple tests with MAC authentication we had to add the guest-vlan here)&lt;/P&gt;&lt;P&gt;Once that was done, the switch correctly recognized the RADIUS VLAN attribute and successfully moved the port into the appropriate VLAN:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_7-1781691551240.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9405i19F770F91781493C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_7-1781691551240.png" alt="JPavel_7-1781691551240.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_8-1781691551240.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9406i43B40AC9635A79BE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_8-1781691551240.png" alt="JPavel_8-1781691551240.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_9-1781691551241.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9407iA451DAB83681EFB1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_9-1781691551241.png" alt="JPavel_9-1781691551241.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_10-1781691551241.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9408iD7DC3D5CC81DC444/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_10-1781691551241.png" alt="JPavel_10-1781691551241.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am now wondering whether it is even possible to get NAC working when "auto-sense" is enabled on the end-device ports.&lt;/P&gt;&lt;P&gt;I tried setting the "auto-sense wait-interval" to 2 seconds to rule out potential timeout issues, but that didn't help.&lt;/P&gt;&lt;P&gt;Can anyone assist me with this?&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Joerg&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 10:20:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121958#M3219</guid>
      <dc:creator>JPavel</dc:creator>
      <dc:date>2026-06-17T10:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121963#M3220</link>
      <description>&lt;P&gt;The&amp;nbsp;Tunnel-Private-Group-Id attribute (Template Extreme VOSS) is not designed to work on auto-sense / flex-uni access ports. It will only work if there is already a platform VLAN object on the switch.&lt;/P&gt;&lt;P&gt;Auto-sense is what you want to keep on access ports, and NAC uses flex-uni on auto-sense ports, which can be added to any I-SID (without any need for platform VLANs on the switch).&amp;nbsp;&lt;/P&gt;&lt;P&gt;The correct RADIUS template is&amp;nbsp;Extreme VOSS - Fabric Attach" if not using XIQ-SE Policy, or&amp;nbsp; "Extreme VOSS - Per-User-ACL" if using XIQ-SE Policy.&lt;/P&gt;&lt;P&gt;There is a Sandbox that Extreme partners can reserve to understand how to deploy a fully zero-touch automated Fabric Edge with NAC; ask your Extreme sales rep to reserve it for you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 15:44:28 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121963#M3220</guid>
      <dc:creator>Ludovico</dc:creator>
      <dc:date>2026-06-17T15:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121990#M3221</link>
      <description>&lt;P&gt;Hi Ludovico,&lt;/P&gt;&lt;P&gt;first of all, thanks for your feedback.&lt;/P&gt;&lt;P&gt;I actually manually created the corresponding platform VLAN on the test switch in our lab, so—in my opinion—the "Extreme VOSS" template should have worked.&lt;/P&gt;&lt;P&gt;Nevertheless, I also ran the same tests in our lab using the "Extreme VOSS - Fabric Attach" and "Extreme VOSS - Per-User-ACL" RADIUS templates which is illustrated in the “NAC in Campus Fabric Edge.pdf“ document.&lt;/P&gt;&lt;P&gt;The result was always the same. I never see the end-device port being pushed untagged into the correct C-VLAN (VLAN 10 in our case) after authentication; it always remains in the onboarding VLAN 4048.&lt;/P&gt;&lt;P&gt;Here the Control Rule Definition and the corresponding Radius Attribute Policy Mapping preview:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_8-1781859615177.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9418i291681D0D0FFC208/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_8-1781859615177.png" alt="JPavel_8-1781859615177.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And the corresponding switch outputs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_9-1781859615178.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9417iB348D513B0524767/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_9-1781859615178.png" alt="JPavel_9-1781859615178.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_10-1781859615178.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9419iF009D1BFB462F734/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_10-1781859615178.png" alt="JPavel_10-1781859615178.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_11-1781859615178.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9420i7FE71BA4AE35D8F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_11-1781859615178.png" alt="JPavel_11-1781859615178.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_12-1781859615179.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9421i51F0554E90ED43D2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_12-1781859615179.png" alt="JPavel_12-1781859615179.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But I probably just have a misunderstanding here, since I come from the EXOS world and am currently getting up to speed on Fabric Connect &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I would have expected the end-device port to be untagged in VLAN 10 at this point.&lt;/P&gt;&lt;P&gt;Regards, Joerg&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 09:00:48 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121990#M3221</guid>
      <dc:creator>JPavel</dc:creator>
      <dc:date>2026-06-19T09:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121997#M3222</link>
      <description>&lt;P&gt;Hi Ludovico,&lt;/P&gt;&lt;P&gt;first of all, thanks for your feedback.&lt;/P&gt;&lt;P&gt;I actually manually created the corresponding platform VLAN on the test switch in our lab, so—in my opinion—the "Extreme VOSS" template should have worked.&lt;/P&gt;&lt;P&gt;Nevertheless, I also ran the same tests in our lab using the "Extreme VOSS - Fabric Attach" and "Extreme VOSS - Per-User-ACL" RADIUS templates which is illustrated in the “NAC in Campus Fabric Edge.pdf“ document.&lt;/P&gt;&lt;P&gt;The result was always the same. I never see the end-device port being pushed untagged into the correct C-VLAN (VLAN 10 in our case) after authentication; it always remains in the onboarding VLAN 4048.&lt;/P&gt;&lt;P&gt;Here the Control Rule Definition and the corresponding Radius Attribute Policy Mapping preview:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_13-1781859707107.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9423iEB1CF4BCDE418BFE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_13-1781859707107.png" alt="JPavel_13-1781859707107.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And the corresponding switch outputs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_14-1781859706888.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9422i9193547433F3D1ED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_14-1781859706888.png" alt="JPavel_14-1781859706888.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_15-1781859706830.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9424iE95D334FAC46CF82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_15-1781859706830.png" alt="JPavel_15-1781859706830.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_16-1781859706972.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9426i8D90142479F43A67/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_16-1781859706972.png" alt="JPavel_16-1781859706972.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavel_17-1781859707013.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/9427i631EC35528BCD32F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavel_17-1781859707013.png" alt="JPavel_17-1781859707013.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But I probably just have a misunderstanding here, since I come from the EXOS world and am currently getting up to speed on Fabric Connect &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I would have expected the end-device port to be untagged in VLAN 10 at this point.&lt;/P&gt;&lt;P&gt;Regards, Joerg&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 09:02:29 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/121997#M3222</guid>
      <dc:creator>JPavel</dc:creator>
      <dc:date>2026-06-19T09:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/122002#M3223</link>
      <description>&lt;P&gt;Hi Joerg&lt;/P&gt;&lt;P&gt;You have it working there; RADIUS returned 0:2000100 and you have I-SID 2000100 untagged on port 1/10.&lt;/P&gt;&lt;P&gt;Yes you also have Onboarding I-SID 15999999 untagged on same port, but keep in mind that any I-SID applied by RADIUS gets applied internally as a MAC-based-VLAN, so on your port 1/10, any untagged frame generated by your authenticated MAC address will always land untagged in I-SID 2000100; and if you happened to have some other non-authenticated devices on the same port they would go into the untagged Onboarding I-SID&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Ludovico&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2026 10:43:58 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/122002#M3223</guid>
      <dc:creator>Ludovico</dc:creator>
      <dc:date>2026-06-22T10:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/122005#M3225</link>
      <description>&lt;P&gt;Hi Lodovico,&lt;/P&gt;&lt;P&gt;I understand that we have an I-SID untagged on port 1/10.&lt;BR /&gt;But what I am missing is the binding from that I-SID to vlan 10 at this point.&lt;BR /&gt;There is no vlan configured on the switch and I also cannot see any cli output which shows that port 1/10 is untagged in vlan10.&lt;BR /&gt;The "show int gig i-sid 1/10" shows no vlan (N/A) under the line "VLANID" .&lt;/P&gt;&lt;P&gt;Shouldn´t the Radius Attribute also return the VLAN ID besides the I-SID if there is no mapping Vlan-to-I-SID mapping at all on the switch?&lt;BR /&gt;Do I miss something here or do I simply do not understand what´s going on here.&lt;/P&gt;&lt;P&gt;Sorry that I do not get it &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards, Joerg&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2026 17:23:04 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/122005#M3225</guid>
      <dc:creator>JPavel</dc:creator>
      <dc:date>2026-06-22T17:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/122011#M3226</link>
      <description>&lt;P&gt;Hi Joerg&lt;/P&gt;&lt;P&gt;Welcome to our Fabric. We don't need VLANs, we have I-SIDs!&lt;/P&gt;&lt;P&gt;The I-SID is applied untagged on the port 1/10 where your device is. Your device is sending untagged packets.&lt;/P&gt;&lt;P&gt;In our fabric, a L2 broadcast domain, is a L2VSN and it only needs an I-SID to exist. The switch has auto-sense on the access ports, which uses flex-uni mode and in that mode a VLAN-id is only really needed if you need to hand it off to a device which wants it q-tagged with a particular VLAN-id.&lt;/P&gt;&lt;P&gt;Why would we need a VLAN ?&lt;/P&gt;&lt;P&gt;If your switch is just a L2 access switch, you normally don't need a VLAN object; the packets from your client will get MACinMAC encapsualted to the destination using the I-SID to identify the L2VSN service.&lt;/P&gt;&lt;P&gt;Now, there are some exceptions where you might need a VLAN object on the switch anyway, for certain functionality, like if you wanted that switch to bind an IP interface to IP route traffic to/from that L2VSN; or if you needed IP Multicast to work on that segment, or if you wanted the L2VSN to be of type Private-VLAN, or if you wanted to use DHCP-Snooping to work on it, etc...&lt;/P&gt;&lt;P&gt;Now, if for those reasons you really wanted to have a VLAN object created at the same time via RADIUS, you need to use a different VSA:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Extreme-Dynamic-Client-Assignments=[create vlan|pvlan|none, pv=Primary VLANID, [sv=secondary VLANID]], vni=ISID, ev=EGRESS-VLAN-tag, [vn=vlan-name], [vnin=isid-name], [mvni=L3ISID], [igmpqaddr=IPv4addr]&lt;/P&gt;&lt;P&gt;You will find that on slide 16 of the document I attached to my first reply.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Ludovico&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 16:04:49 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/122011#M3226</guid>
      <dc:creator>Ludovico</dc:creator>
      <dc:date>2026-06-23T16:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: ZTP+ Fabric with NAC on edge ports not working (auto-sense enabled)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/122018#M3229</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I’ve finally got it now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I just successfully got the setup running in my lab and will implement it at our customer's site tomorrow.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; Thanks for your patience with me.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; Regards, Joerg&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 18:49:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/ztp-fabric-with-nac-on-edge-ports-not-working-auto-sense-enabled/m-p/122018#M3229</guid>
      <dc:creator>JPavel</dc:creator>
      <dc:date>2026-06-24T18:49:19Z</dc:date>
    </item>
  </channel>
</rss>

