<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: 4500 802.1x EAP behavior in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8374#M47</link>
    <description>Brian - Martin is correct. The 45xx platform final code is 5.7.3. 4800/4900 are 5.11+ capable.&lt;BR /&gt;
&lt;BR /&gt;
However your symptomatic issue tied to defaults suggests you have multihost enabled on the port and mac-max &amp;gt; 1. If there is only one device on the port with mac-max &amp;gt; 1 the switch will send Identity requests every timeout=30s. This causes the existing authenticated client to reconnect unnecessarily.&lt;BR /&gt;
&lt;BR /&gt;
Either mac-max = 1, tweak timeouts &amp;gt;30s but definitely not 1h so the re-auth isn't as disruptive to existing clients or disable multihost on those ports. The latter stops the switch from 'soliciting' clients every xx seconds using EAPOL Identity. It expects clients to send EAPOL Start to begin the EAP process and rely on client-side timers to handle any issues/timeouts, etc.</description>
    <pubDate>Wed, 25 Jul 2018 18:51:00 GMT</pubDate>
    <dc:creator>Robert_Haynes</dc:creator>
    <dc:date>2018-07-25T18:51:00Z</dc:date>
    <item>
      <title>4500 802.1x EAP behavior</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8372#M45</link>
      <description>We have a 4500 switch running SW:v5.11.1.101&lt;BR /&gt;
&lt;BR /&gt;
When we connect an 802.1x client, the switch is sending a new authentication request every 30 seconds.&lt;BR /&gt;
&lt;BR /&gt;
We can increase this time by modifying this in the config from the default of 30:&lt;BR /&gt;
&lt;BR /&gt;
eapol port 27-28 supplicant-timeout 3600&lt;BR /&gt;
&lt;BR /&gt;
We do not see this same behavior on a 4800 or 4900 with the same 30 second default.&lt;BR /&gt;
&lt;BR /&gt;
Is this a known difference or bug in the 4500 code?&lt;BR /&gt;
&lt;BR /&gt;
Anyone see a problem with setting this to 3600 as a default?</description>
      <pubDate>Fri, 22 Jun 2018 18:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8372#M45</guid>
      <dc:creator>Brian_Holmes</dc:creator>
      <dc:date>2018-06-22T18:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: 4500 802.1x EAP behavior</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8373#M46</link>
      <description>Hello Brian,&lt;BR /&gt;
&lt;BR /&gt;
are you sure you are running 5.11 on ERS 4500?  Until today I thought the last version for these switches is 5.7.3.  The release notes for the version 5.11.2 say that supported platforms are all 4800 models.&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Martin Sebek</description>
      <pubDate>Fri, 20 Jul 2018 14:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8373#M46</guid>
      <dc:creator>Martin_Sebek</dc:creator>
      <dc:date>2018-07-20T14:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: 4500 802.1x EAP behavior</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8374#M47</link>
      <description>Brian - Martin is correct. The 45xx platform final code is 5.7.3. 4800/4900 are 5.11+ capable.&lt;BR /&gt;
&lt;BR /&gt;
However your symptomatic issue tied to defaults suggests you have multihost enabled on the port and mac-max &amp;gt; 1. If there is only one device on the port with mac-max &amp;gt; 1 the switch will send Identity requests every timeout=30s. This causes the existing authenticated client to reconnect unnecessarily.&lt;BR /&gt;
&lt;BR /&gt;
Either mac-max = 1, tweak timeouts &amp;gt;30s but definitely not 1h so the re-auth isn't as disruptive to existing clients or disable multihost on those ports. The latter stops the switch from 'soliciting' clients every xx seconds using EAPOL Identity. It expects clients to send EAPOL Start to begin the EAP process and rely on client-side timers to handle any issues/timeouts, etc.</description>
      <pubDate>Wed, 25 Jul 2018 18:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8374#M47</guid>
      <dc:creator>Robert_Haynes</dc:creator>
      <dc:date>2018-07-25T18:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: 4500 802.1x EAP behavior</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8375#M48</link>
      <description>Sorry.  We are running 5.7.3.031.  Setting mac-max back to 1 fixes the issue.   Thanks</description>
      <pubDate>Thu, 26 Jul 2018 16:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8375#M48</guid>
      <dc:creator>Brian_Holmes</dc:creator>
      <dc:date>2018-07-26T16:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: 4500 802.1x EAP behavior</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8376#M49</link>
      <description>For the record:&lt;BR /&gt;
&lt;BR /&gt;
Global config:&lt;BR /&gt;
eapol multihost eap-packet-mode unicast&lt;BR /&gt;
&lt;BR /&gt;
Port config:&lt;BR /&gt;
eapol multihost port 1/ALL,2/ALL,3/ALL,4/ALL enable eap-mac-max 2 allow-non-eap-enable radius-non-eap-enable non-eap-phone-enable use-radius-assigned-vlan non-eap-use-radius-assigned-vlan eap-packet-mode unicast mac-max 2&lt;BR /&gt;
&lt;BR /&gt;
The above configuration changes the behavior of the switch  in EAP/NEAP modes to no longer solicit for clients on the ports by sending an  EAPOL Identity request. This solicitation has the negative effect of forcing  any existing clients to re-authenticate. As clients/switches scale, this can  become a problem with several dozens/hundreds of clients re-authenticating  continuously subject to the supplicantTimeout = 30s default.&lt;BR /&gt;</description>
      <pubDate>Thu, 26 Jul 2018 22:06:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/4500-802-1x-eap-behavior/m-p/8376#M49</guid>
      <dc:creator>Robert_Haynes</dc:creator>
      <dc:date>2018-07-26T22:06:00Z</dc:date>
    </item>
  </channel>
</rss>

