<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAC authentication and mgmt authentication with the same radius servers in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61463#M2417</link>
    <description>In my test environment I have a switch (X440G2 22.7.1.2) configured for NAC with two radius servers.&lt;BR /&gt;
&lt;BR /&gt;
In the AAA configuration I see two netlogin radius entry’s and the radius mgmt.-access is disabled and the policy works fine.&lt;BR /&gt;
 &lt;BR /&gt;
As expansion on the configuration I want also that management requests are done by the radius servers.&lt;BR /&gt;
So I configure the same radius server as for authentication .&lt;BR /&gt;
&lt;BR /&gt;
Now I see in the AAA configuration that the netlogin rules are replaced by mgmt.-access rules and that the radius netlogin is disabled.&lt;BR /&gt;
&lt;BR /&gt;
Cann’t I use the same radius servers for mgmt. as for authentication?</description>
    <pubDate>Thu, 01 Aug 2019 13:26:43 GMT</pubDate>
    <dc:creator>JohanHendrikx</dc:creator>
    <dc:date>2019-08-01T13:26:43Z</dc:date>
    <item>
      <title>NAC authentication and mgmt authentication with the same radius servers</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61463#M2417</link>
      <description>In my test environment I have a switch (X440G2 22.7.1.2) configured for NAC with two radius servers.&lt;BR /&gt;
&lt;BR /&gt;
In the AAA configuration I see two netlogin radius entry’s and the radius mgmt.-access is disabled and the policy works fine.&lt;BR /&gt;
 &lt;BR /&gt;
As expansion on the configuration I want also that management requests are done by the radius servers.&lt;BR /&gt;
So I configure the same radius server as for authentication .&lt;BR /&gt;
&lt;BR /&gt;
Now I see in the AAA configuration that the netlogin rules are replaced by mgmt.-access rules and that the radius netlogin is disabled.&lt;BR /&gt;
&lt;BR /&gt;
Cann’t I use the same radius servers for mgmt. as for authentication?</description>
      <pubDate>Thu, 01 Aug 2019 13:26:43 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61463#M2417</guid>
      <dc:creator>JohanHendrikx</dc:creator>
      <dc:date>2019-08-01T13:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAC authentication and mgmt authentication with the same radius servers</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61464#M2418</link>
      <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
You can use the same RADIUS server fore mgmt and network authentication. You must set the Au&lt;BR /&gt;
&lt;BR /&gt;
Make sure that the X440G2 is set to "Any Access":&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="5bc5befc98c645b5b4eb31f635b68323_194c928e-d0c2-4a96-a934-30fa6f793ed0.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2532iEC74342034B8E4C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="5bc5befc98c645b5b4eb31f635b68323_194c928e-d0c2-4a96-a934-30fa6f793ed0.png" alt="5bc5befc98c645b5b4eb31f635b68323_194c928e-d0c2-4a96-a934-30fa6f793ed0.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 05:18:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61464#M2418</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2019-08-05T05:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: NAC authentication and mgmt authentication with the same radius servers</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61465#M2419</link>
      <description>When I change the auth Access type to any access, the only configuration rule are the radius mgmt-access rules .&lt;BR /&gt;
radius mgmt-access and radius netlogin are enabled.&lt;BR /&gt;
There are no config rules for netlogin.</description>
      <pubDate>Mon, 05 Aug 2019 13:50:38 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61465#M2419</guid>
      <dc:creator>JohanHendrikx</dc:creator>
      <dc:date>2019-08-05T13:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAC authentication and mgmt authentication with the same radius servers</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61466#M2420</link>
      <description>Hello Johan,&lt;BR /&gt;
&lt;BR /&gt;
I'm not sure what you mean by  config rules for netlogin.&lt;BR /&gt;
&lt;BR /&gt;
Are you referring to XMC control rules that determine authorization levels? &lt;BR /&gt;
&lt;BR /&gt;
Are you referring to switch configuration to enable netlogin for mac/802.1x auth on a per port or global basis?&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
-Ryan</description>
      <pubDate>Mon, 05 Aug 2019 20:09:41 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61466#M2420</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2019-08-05T20:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: NAC authentication and mgmt authentication with the same radius servers</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61467#M2421</link>
      <description>I'm refering to th switch configuration of the AAA section.&lt;BR /&gt;
&lt;BR /&gt;
At the moment I configure the management radius the config of the primairy and secondary engin are gone.&lt;BR /&gt;
&lt;BR /&gt;
Config exaples:&lt;BR /&gt;
&lt;BR /&gt;
Switch is configured for only primairy and secondary engins.&lt;BR /&gt;
&lt;BR /&gt;
configure radius 1 server  1812 client-ip  vr VR-Default&lt;BR /&gt;
configure radius 1 shared-secret encrypted "#$QHoAV1JRHL25Psky9286ihA/eQb5twIipuhGzDsLDrL3fId9ua4zlQA6tElrf8XmjmCsk55g"&lt;BR /&gt;
configure radius 2 server  1812 client-ip  vr VR-Default&lt;BR /&gt;
configure radius 2 shared-secret encrypted "#$3YuouBFWEkEJ3aeHDxVM+YcELVg0sPdr67z3lZouVh/r+QyCfaG/bfQ7GI1MPpu/X5ed7Xc1"&lt;BR /&gt;
configure radius-accounting 1 server 10.2.112.2 1813 client-ip 10.2.112.209 vr VR-Default&lt;BR /&gt;
configure radius-accounting 1 shared-secret encrypted "#$qdZB1R6z+Up25O4vjfhESlE3MvJhBdSaOdCuaG/stlu6uNlfXpNJbAdUMTFwdifnKnPlmCFc"&lt;BR /&gt;
configure radius-accounting 1 timeout 10&lt;BR /&gt;
configure radius-accounting 2 server 10.2.113.2 1813 client-ip 10.2.112.209 vr VR-Default&lt;BR /&gt;
configure radius-accounting 2 shared-secret encrypted "#$6ygkfu3I9oANOxxLOXakeFXo1/6A38wnFhe1gWuENAqkCzjZI158UJ/UNs3XviNa0DnZ/Xrw"&lt;BR /&gt;
configure radius-accounting 2 timeout 10&lt;BR /&gt;
enable radius&lt;BR /&gt;
enable radius mgmt-access&lt;BR /&gt;
enable radius netlogin&lt;BR /&gt;
&lt;BR /&gt;
Switch is configured for  the both engins and both management radius:&lt;BR /&gt;
&lt;BR /&gt;
configure radius mgmt-access 1 server  1812 client-ip  vr VR-Default&lt;BR /&gt;
configure radius 1 shared-secret encrypted "#$fipO29phKcl+o6SgtbPEZ6unyZrmd6sZ+nT58kRLJJFVq1lx0QXIXO5QyxHrm5y6rzWgp7H6"&lt;BR /&gt;
configure radius mgmt-access 2 server  1812 client-ip  vr VR-Default&lt;BR /&gt;
configure radius 2 shared-secret encrypted "#$la/QbhlmQf2p7xkkNHgaE2pR9SWjFaQ7cGCbBbr3BueEieI5Iy65o7XwAqNXx2DLlECTwJBp"&lt;BR /&gt;
enable radius&lt;BR /&gt;
enable radius mgmt-access&lt;BR /&gt;
enable radius netlogin&lt;BR /&gt;
configure radius timeout 15&lt;BR /&gt;
enable radius-accounting&lt;BR /&gt;
enable radius-accounting mgmt-access&lt;BR /&gt;
enable radius-accounting netlogin&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="7137611bf09c433d96c297421c15aa70_e0b74740-2846-436a-8c2e-2674d2e481d7.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/914i5BA6A5FAD6442C21/image-size/large?v=v2&amp;amp;px=999" role="button" title="7137611bf09c433d96c297421c15aa70_e0b74740-2846-436a-8c2e-2674d2e481d7.jpg" alt="7137611bf09c433d96c297421c15aa70_e0b74740-2846-436a-8c2e-2674d2e481d7.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 21:21:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61467#M2421</guid>
      <dc:creator>JohanHendrikx</dc:creator>
      <dc:date>2019-08-05T21:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAC authentication and mgmt authentication with the same radius servers</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61468#M2422</link>
      <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
Remove the "Management RADIUS server" and "Management RADIUS server 2" servers. Set them to none.&lt;BR /&gt;
&lt;BR /&gt;
If you identify Primary Engine and Secondary Engine as the NAC appliances you only need to set the "Auth Access Type" to any. This will identify them to be used for netlogin and mgmt access and configure the switch accordingly.&lt;BR /&gt;
&lt;BR /&gt;
That should configure  the AAA to use the NAC appliances for both netlogin and mgmt login.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
-Ryan</description>
      <pubDate>Mon, 05 Aug 2019 22:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61468#M2422</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2019-08-05T22:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAC authentication and mgmt authentication with the same radius servers</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61469#M2423</link>
      <description>Ryan,&lt;BR /&gt;
&lt;BR /&gt;
I  will test it</description>
      <pubDate>Tue, 06 Aug 2019 12:56:41 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61469#M2423</guid>
      <dc:creator>JohanHendrikx</dc:creator>
      <dc:date>2019-08-06T12:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: NAC authentication and mgmt authentication with the same radius servers</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61470#M2424</link>
      <description>Ryan,&lt;BR /&gt;
&lt;BR /&gt;
it works.&lt;BR /&gt;
&lt;BR /&gt;
Thanks for your support.</description>
      <pubDate>Tue, 06 Aug 2019 16:02:31 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/nac-authentication-and-mgmt-authentication-with-the-same-radius/m-p/61470#M2424</guid>
      <dc:creator>JohanHendrikx</dc:creator>
      <dc:date>2019-08-06T16:02:31Z</dc:date>
    </item>
  </channel>
</rss>

