<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Strange NAC Lost Contact alarms in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/strange-nac-lost-contact-alarms/m-p/29132#M252</link>
    <description>Hi Steve,&lt;BR /&gt;
&lt;BR /&gt;
Please correct me if I am wrong. &lt;BR /&gt;
&lt;BR /&gt;
You have NAC server which has default route to switch mgmt interface and netsight receives alarms from other vlans .&lt;BR /&gt;
&lt;BR /&gt;
1) What is the switch hardware model and current status ?&lt;BR /&gt;
&lt;BR /&gt;
2) Do you see any link flaps from 2.2.2.2 vlan.&lt;BR /&gt;
&lt;BR /&gt;
3) Please check the show log and show management from switch.&lt;BR /&gt;
&lt;BR /&gt;
4) What is the expected behavior from switch as per your Trap/alarm configuration,&lt;BR /&gt;
was it working earlier ?&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Suresh.B&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Tue, 01 Mar 2016 10:47:00 GMT</pubDate>
    <dc:creator>Bharathiraja__S</dc:creator>
    <dc:date>2016-03-01T10:47:00Z</dc:date>
    <item>
      <title>Strange NAC Lost Contact alarms</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/strange-nac-lost-contact-alarms/m-p/29131#M251</link>
      <description>Hello All,&lt;BR /&gt;
&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
    we have a  strange behavior with NAC and Extreme switches.&lt;BR /&gt;
&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
    On the  switch there are different vlans with different ip addresses.&lt;BR /&gt;
&lt;BR /&gt;
    All vlans  are in the same VR (vr-default).&lt;BR /&gt;
&lt;BR /&gt;
    The  connection for management between NAC and the switches is located in a  management vlan (vr-default, too).&lt;BR /&gt;
&lt;BR /&gt;
    NAC has  only a direct route to the management ip address (Management vlan) on the switch.&lt;BR /&gt;
&lt;BR /&gt;
    Only the management  ip of the switch is configured on the NAC.&lt;BR /&gt;
&lt;BR /&gt;
    All ip  addresses on the switch are reachable from NAC (managmenet vlan and the other  vlans).&lt;BR /&gt;
&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
    But now  what we see:&lt;BR /&gt;
&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
    The link  between the NAC and the switch are working and NetSight and NAC shows green for  the connection.&lt;BR /&gt;
&lt;BR /&gt;
    All works  fine.&lt;BR /&gt;
&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
    BUT we  receive alarm messages in the NetSight as below:&lt;BR /&gt;
&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
    Critical NAC Lost Contact with Switch          1.1.1.1 / 2.2.2.2          Full Loss of Contact to Switch  detected: 2.2.2.2due to: Unable to make SNMP contact                                                                               &lt;BR /&gt;
&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
    The 1.1.1.1  (as example) is the ip address from the nac, 2.2.2.2 is the ip address from the  Switch ( but NOT the management ip address).&lt;BR /&gt;
&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
    Now the  questions: &lt;BR /&gt;
&lt;BR /&gt;
Why detects the NAC a contact lost in a network not used for management  and authentication? How can I avoid these alarms?&lt;BR /&gt;
&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
    One further  hint: The NAC receives DHCP-Messages on the vlans not used for management.  Maybe this is the cause why the NAC knows the vlans and ips on the switch (not  used for management).&lt;BR /&gt;
&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
    Best  regards&lt;BR /&gt;
&lt;BR /&gt;
    Steve&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Feb 2016 17:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/strange-nac-lost-contact-alarms/m-p/29131#M251</guid>
      <dc:creator>Steve14</dc:creator>
      <dc:date>2016-02-29T17:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: Strange NAC Lost Contact alarms</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/strange-nac-lost-contact-alarms/m-p/29132#M252</link>
      <description>Hi Steve,&lt;BR /&gt;
&lt;BR /&gt;
Please correct me if I am wrong. &lt;BR /&gt;
&lt;BR /&gt;
You have NAC server which has default route to switch mgmt interface and netsight receives alarms from other vlans .&lt;BR /&gt;
&lt;BR /&gt;
1) What is the switch hardware model and current status ?&lt;BR /&gt;
&lt;BR /&gt;
2) Do you see any link flaps from 2.2.2.2 vlan.&lt;BR /&gt;
&lt;BR /&gt;
3) Please check the show log and show management from switch.&lt;BR /&gt;
&lt;BR /&gt;
4) What is the expected behavior from switch as per your Trap/alarm configuration,&lt;BR /&gt;
was it working earlier ?&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Suresh.B&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Mar 2016 10:47:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/strange-nac-lost-contact-alarms/m-p/29132#M252</guid>
      <dc:creator>Bharathiraja__S</dc:creator>
      <dc:date>2016-03-01T10:47:00Z</dc:date>
    </item>
    <item>
      <title>RE: Strange NAC Lost Contact alarms</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/strange-nac-lost-contact-alarms/m-p/29133#M253</link>
      <description>Hello Suresh,&lt;BR /&gt;
&lt;BR /&gt;
there is only a layer 3 connection between NAC and switches. Switches and NAC are in different networks and the connection is routed.  Therefore the NAC default gw is not the same as the default gw of the switches.&lt;BR /&gt;
&lt;BR /&gt;
1)The behavior is for all used switches the same. We use X450G2.&lt;BR /&gt;
&lt;BR /&gt;
2)No we have no link flaps in the vlan.&lt;BR /&gt;
&lt;BR /&gt;
3)As you mentioned I checked the the show log on a switch and I can see this message: &lt;BR /&gt;
&lt;BR /&gt;
"03/01/2016 07:28:50.93  Slot-1: Login failed through SNMPv1/v2c - bad community name (1.1.1.1)"&lt;BR /&gt;
&lt;BR /&gt;
We have two NAC-GW. Both are configured in the same way (we think so) and in our opinion we haven't configure SNMPv1/v2c only SNMPv3.  The message are only received for one NAC (1.1.1.1) not for the second NAC.&lt;BR /&gt;
&lt;BR /&gt;
Maybe this is the hint, but we don't know why NAC tries to open a connection via SNMPv1/v2c.&lt;BR /&gt;
&lt;BR /&gt;
4) We are using only the standard alarms form NAC "NAC Lost Contact with Switch" in the alarm manager and we expect only a alarm message if the connection configured in the “NAC-Manager” on the “switch tab” is broken.  Please be aware the alarm message is generated on the NAC and not on the switch. The NAC detects the "Lost Contact".&lt;BR /&gt;
&lt;BR /&gt;
Is there a place in the NAC config where we can configure SNMP (not for the connection between NAC and NetSight but rather for the connection between NAC and Switch)?&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 01 Mar 2016 16:18:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/strange-nac-lost-contact-alarms/m-p/29133#M253</guid>
      <dc:creator>Steve14</dc:creator>
      <dc:date>2016-03-01T16:18:00Z</dc:date>
    </item>
    <item>
      <title>RE: Strange NAC Lost Contact alarms</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/strange-nac-lost-contact-alarms/m-p/29134#M254</link>
      <description>Is the issue resolved if you uncheck router discovery as explained in this article ?&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/Solution/NAC-Manager-is-polling-devices-not-in-the-switch-tab" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/Solution/NAC-Manager-is-polling-devices-not-in-th...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Apr 2016 16:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/strange-nac-lost-contact-alarms/m-p/29134#M254</guid>
      <dc:creator>OscarK</dc:creator>
      <dc:date>2016-04-05T16:03:00Z</dc:date>
    </item>
  </channel>
</rss>

