<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: NAC Manager LDAP Integration with Sub Domain in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39327#M2274</link>
    <description>I'm glad that  I could help You </description>
    <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
    <dc:creator>Piotr_Owczarek</dc:creator>
    <dc:date>2015-06-15T10:53:00Z</dc:date>
    <item>
      <title>NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39316#M2263</link>
      <description>We are using NAC Manager with policys to authentificate our Staff which ist coming wireless from a EWC ...  &lt;BR /&gt;
&lt;BR /&gt;
The Authentification works with LDAP against the Domain.    ....   username\Domain &lt;BR /&gt;
&lt;BR /&gt;
Example :   &lt;A href="https://mailto:Hans.Mustermann@thhf.net" target="_blank" rel="nofollow noreferrer noopener"&gt;Hans.Mustermann@thhf.net&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Now we want to integrate also the students from our School into this ldap authentification,&lt;BR /&gt;
&lt;BR /&gt;
but they are located into an subdomain.&lt;BR /&gt;
&lt;BR /&gt;
Example : &lt;A href="https://mailto:Franz.Mustermann@stud.thhf.net" target="_blank" rel="nofollow noreferrer noopener"&gt;Franz.Mustermann@stud.thhf.net&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Does this work with Nac Manger from Extreme ?? , we are using Netsight / NAC Manager 6.1.0&lt;BR /&gt;
&lt;BR /&gt;
The Nac Manager know the ldap Connection to the Primary Domain and is joined into this Domain, rather a Student send a logon request with his subdomain logon, the ldap should forward this to the subdomain DC ... i think this is more a Windows Problem.&lt;BR /&gt;
&lt;BR /&gt;
I only want to know if here is anybody who has already a working Environment with subdomains and LDAP Authentification.&lt;BR /&gt;
&lt;BR /&gt;
Regards &lt;BR /&gt;
&lt;BR /&gt;
Christian&lt;BR /&gt;
&lt;BR /&gt;
PS : Sorry for bad gramma .. non native english author&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Jun 2015 10:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39316#M2263</guid>
      <dc:creator>info_systemhaus</dc:creator>
      <dc:date>2015-06-15T10:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39317#M2264</link>
      <description>Should work. Configure advanced AAA rules : based on the username part (subdimain) use different aaa server/method = different LDAP server/settings. Good luck </description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39317#M2264</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39318#M2265</link>
      <description>Many THX ... but should work is not enough....  &lt;BR /&gt;
&lt;BR /&gt;
I want to find someone who has a working NAC Manager LDAP Integration with Sub Domains &lt;BR /&gt;
&lt;BR /&gt;
As you write .. different LDAP Server Settings .. should not work, because as far as i know .. the Nac Manager LDAP join the Domain and Need every time the connect to the Primary Domain .... &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39318#M2265</guid>
      <dc:creator>info_systemhaus</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39319#M2266</link>
      <description>Hi Christian,&lt;BR /&gt;
&lt;BR /&gt;
I think the "Should work" of Pala goes more in the direction that you can't be 100% sure in IT &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
I deployed NAC in multi domain scenarios and you there you have different kind of deployments.&lt;BR /&gt;
&lt;BR /&gt;
If you are able to join the NAC into the different domains - all is fine. Eg. myDomain.comand stud.mydomain.com. But you need 2 LDAP Configurations. NAC gets Domain member of both domains.&lt;BR /&gt;
&lt;BR /&gt;
If you don't have the priveledge for the 2nd domain you've got a pretty good chance to fail even if the 2 domains have a full trust. In this scenario I would set up a pair of Windows NPS servers and use NAC for that domains as a radius proxy.&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
Michael</description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39319#M2266</guid>
      <dc:creator>Michael_Kirchne</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39320#M2267</link>
      <description>&lt;I&gt;&lt;B&gt;If you are able to join the NAC into the different domains - all is fine&lt;/B&gt;&lt;/I&gt;&lt;BR /&gt;
&lt;BR /&gt;
This will become the "Main Question"  .. and it´s to be feared .. that this will not work.&lt;BR /&gt;
&lt;BR /&gt;
The solution with using an own NPS on Windows .. and bring the Auth- Traffic from the EWS direct to the DC of the subdomain, was  our alternative  Idea ... &lt;BR /&gt;
&lt;BR /&gt;
To manage all LDAP Configurations on the netsight console would be more smart .. but if it´s not possible, we will bring the Auth direct over NPS to the Servers .&lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;&lt;BR /&gt;
&lt;/I&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39320#M2267</guid>
      <dc:creator>info_systemhaus</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39321#M2268</link>
      <description>Hello Christian,&lt;BR /&gt;
&lt;BR /&gt;
I have such solution working. Two different domains, LDAP Advanced config and users belonging to different domains. &lt;BR /&gt;
No problem at all.&lt;BR /&gt;
You just need to construct reliable criteria for checking domain membership for user being authenticated, and that is all.&lt;BR /&gt;
Piotr</description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39321#M2268</guid>
      <dc:creator>Piotr_Owczarek</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39322#M2269</link>
      <description>Hello Piotr,&lt;BR /&gt;
&lt;BR /&gt;
many thx .. you have configured the connection to 2 different LDAP Sources as i understand via the advancec AAA Config .... is this correct ? &lt;BR /&gt;
&lt;BR /&gt;
Could you post me an example how you can divide the users from different Domains ?  &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39322#M2269</guid>
      <dc:creator>info_systemhaus</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39323#M2270</link>
      <description>Hope that Attached pic will help You. If not do not hesitate to ask  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="b1b06c7cd073413f92e2cabe53c3d3b2_RackMultipart20150615-11317-1c74r4x-LDAP_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/17i1756C3F5EC95B504/image-size/large?v=v2&amp;amp;px=999" role="button" title="b1b06c7cd073413f92e2cabe53c3d3b2_RackMultipart20150615-11317-1c74r4x-LDAP_inline.jpg" alt="b1b06c7cd073413f92e2cabe53c3d3b2_RackMultipart20150615-11317-1c74r4x-LDAP_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39323#M2270</guid>
      <dc:creator>Piotr_Owczarek</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39324#M2271</link>
      <description>ok .. thx i will try this ..&lt;BR /&gt;
&lt;BR /&gt;
The Domain there is :&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;thhf.local&lt;/B&gt;  and the subdomain is ... &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;stud.thhf.local&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
Actualy .. there is only * asterisk on the Place for User Match. and the users with ldap are loging through wireless Clients ... with thhf\username .&lt;BR /&gt;
&lt;BR /&gt;
So i only should separate the two ldap Connections with ...&lt;BR /&gt;
&lt;BR /&gt;
User Match :   stud.thhf\*&lt;BR /&gt;
&lt;BR /&gt;
User Match :  thhf\*&lt;BR /&gt;
&lt;BR /&gt;
I will try this into next days ... and will give a reply ..&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39324#M2271</guid>
      <dc:creator>info_systemhaus</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39325#M2272</link>
      <description>It should work. You can check if the condition of domain name containing "stud" is met and then classify user to be authenticated by one LDAP server and if not classify by the second.</description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39325#M2272</guid>
      <dc:creator>Piotr_Owczarek</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39326#M2273</link>
      <description>Hello Piotr,&lt;BR /&gt;
&lt;BR /&gt;
many thx .. it works ..&lt;BR /&gt;
&lt;BR /&gt;
I have separated the Domains by the Logon Praefix ...an it works ..&lt;BR /&gt;
&lt;BR /&gt;
Screenshot for all others &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  ... having the same Problem.&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="975feb16f2c34149b6fa6d642094e262_RackMultipart20150616-30865-19splu0-THH_Domain_2_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/705i312EB495E31EDA0F/image-size/large?v=v2&amp;amp;px=999" role="button" title="975feb16f2c34149b6fa6d642094e262_RackMultipart20150616-30865-19splu0-THH_Domain_2_inline.png" alt="975feb16f2c34149b6fa6d642094e262_RackMultipart20150616-30865-19splu0-THH_Domain_2_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39326#M2273</guid>
      <dc:creator>info_systemhaus</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC Manager LDAP Integration with Sub Domain</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39327#M2274</link>
      <description>I'm glad that  I could help You </description>
      <pubDate>Mon, 15 Jun 2015 10:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-manager-ldap-integration-with-sub-domain/m-p/39327#M2274</guid>
      <dc:creator>Piotr_Owczarek</dc:creator>
      <dc:date>2015-06-15T10:53:00Z</dc:date>
    </item>
  </channel>
</rss>

