<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to configure XCA or XCC to authenticate domain computers using certificates EAP-TLS in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72057#M2573</link>
    <description>&lt;P&gt;Hello community,&lt;BR /&gt;&lt;BR /&gt;has anybody found a way to use a modern wireless controller like XCA or XCC with a client auth based on certifcates without using an NPS (we have dozens of ipad´s)&lt;BR /&gt;&lt;BR /&gt;I want to find a way where i can create a machine certificate on a system and then join an SSID without username and passwort but only check this certifcate.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 24 Oct 2020 04:56:38 GMT</pubDate>
    <dc:creator>Christian_K_</dc:creator>
    <dc:date>2020-10-24T04:56:38Z</dc:date>
    <item>
      <title>How to configure XCA or XCC to authenticate domain computers using certificates EAP-TLS</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72057#M2573</link>
      <description>&lt;P&gt;Hello community,&lt;BR /&gt;&lt;BR /&gt;has anybody found a way to use a modern wireless controller like XCA or XCC with a client auth based on certifcates without using an NPS (we have dozens of ipad´s)&lt;BR /&gt;&lt;BR /&gt;I want to find a way where i can create a machine certificate on a system and then join an SSID without username and passwort but only check this certifcate.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Oct 2020 04:56:38 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72057#M2573</guid>
      <dc:creator>Christian_K_</dc:creator>
      <dc:date>2020-10-24T04:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure XCA or XCC to authenticate domain computers using certificates EAP-TLS</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72058#M2574</link>
      <description>&lt;P&gt;Christian,&lt;/P&gt;&lt;P&gt;There are 3 authentication mechanisms in XCC:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Local (username/password)&lt;/LI&gt;	&lt;LI&gt;Radius (all the radius supported auth types)&lt;/LI&gt;	&lt;LI&gt;LDAP (mainly used to validate user or computers on MSAD. with username/password)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you don’t use local (usrername/password) authentication, you need an external Radius server to perform the authentication.&lt;/P&gt;&lt;P&gt;You can use NPS or another.&lt;/P&gt;&lt;P&gt;The advantage of the Extreme Access Control is the integration with the XCC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To perform TLS Auth the Radius has to have the Root certificate of the CA used to generate the Client certificate.&lt;/P&gt;&lt;P&gt;With this Root certificate he can validate the Client certificate and give a positive answer to the XCC.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Oct 2020 15:59:56 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72058#M2574</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2020-10-24T15:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure XCA or XCC to authenticate domain computers using certificates EAP-TLS</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72059#M2575</link>
      <description>&lt;P&gt;Hello Mig,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thx for the awnser, i don´t want to use NPS because the customer has a lot of IPAD´s and NPS is very focused on windows machines.&lt;BR /&gt;&lt;BR /&gt;I have EAC on the customer site and do LDAP Auth with this.&lt;BR /&gt;&lt;BR /&gt;Do you know a “how to”&amp;nbsp; or “Step by Step” , to configure XCC and EAC using Certificates with EAP Auth ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can only find old “How To´s” with NPS and&amp;nbsp; V2110 Controller but nothing with modern controllers like XCA or XCC.&lt;BR /&gt;&lt;BR /&gt;Regards&amp;nbsp;&lt;BR /&gt;Christian&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Oct 2020 16:06:57 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72059#M2575</guid>
      <dc:creator>Christian_K_</dc:creator>
      <dc:date>2020-10-24T16:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure XCA or XCC to authenticate domain computers using certificates EAP-TLS</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72060#M2576</link>
      <description>&lt;P&gt;Christian,&lt;/P&gt;&lt;P&gt;What you request is quite broad and need&amp;nbsp;some professional services to analyse your specific use cases and implementation.&lt;/P&gt;&lt;P&gt;You could&amp;nbsp;have to go in so many menus and options on NAC that it will not possible to share this on this forum.&lt;/P&gt;&lt;P&gt;You’ll also have to manage the certificate deployment on iOS devices for 802.1X authentication.&amp;nbsp;It is quite tricky to do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here some step-by-step guides found&amp;nbsp;on the Internet to give you some indications on the configuration steps for NAC:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://www.securew2.com/solutions/radius-aaa-solutions/integrating-eap-tls-authentication-with-extremecontrol-radius/" target="_blank" rel="nofollow noreferrer noopener"&gt;https://www.securew2.com/solutions/radius-aaa-solutions/integrating-eap-tls-authentication-with-extremecontrol-radius/&lt;/A&gt;&lt;/LI&gt;	&lt;LI&gt;&lt;A href="https://www.securew2.com/solutions/wi-fi-integrations/how-to-setup-eap-tls-wpa2-enterprise-extreme-networks/" target="_blank" rel="nofollow noreferrer noopener"&gt;https://www.securew2.com/solutions/wi-fi-integrations/how-to-setup-eap-tls-wpa2-enterprise-extreme-networks/&lt;/A&gt;&lt;/LI&gt;	&lt;LI&gt;On top of this I recommend to add the XCC to the NAC policy Domain to ensure the correct deployment of the Roles to be used&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Oct 2020 16:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72060#M2576</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2020-10-24T16:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure XCA or XCC to authenticate domain computers using certificates EAP-TLS</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72061#M2577</link>
      <description>&lt;P&gt;Christian,&lt;/P&gt;&lt;P&gt;Much of the config will need to be on the NAC/Extreme Control side of things.&amp;nbsp; On the XCA/XCC side, you should only need to point to NAC/EC as the RADIUS Server to authenticate against.&amp;nbsp; There may be more information regarding certificates and NAC in the knowledgebase.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no step-by-step guide that I know of for this.&lt;/P&gt;&lt;P&gt;I do believe that it is shown in the Extreme Control class - or you can connect with a Partner that has experience with NAC/EC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if we can help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bill&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 20:34:20 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72061#M2577</guid>
      <dc:creator>Bill_Handler</dc:creator>
      <dc:date>2020-10-26T20:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure XCA or XCC to authenticate domain computers using certificates EAP-TLS</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72062#M2578</link>
      <description>&lt;P&gt;Hi Christian,&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can setup computer/machine cert based authentication by following these steps. You would also need to take care of the certificate distribution to your iOS and non-windows devices, that can’t be done with EAC.&lt;/P&gt;&lt;P&gt;1- Point your XCC to the EAC as radius server using the AAA configuration the XCC. Make sure NOT&amp;nbsp;to use local onboarding option in WLAN&amp;nbsp;settings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2- On the EAC, you need two types of certificates i.e.&lt;/P&gt;&lt;OL type="a"&gt;&lt;LI&gt;Root CA of the domain that is issuing/signing the certs for your client devices.&lt;/LI&gt;	&lt;LI&gt;Radius cert issued by the same domain.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;3- Load the CA cert on the “&lt;STRONG&gt;Update Trusted Authorities” &lt;/STRONG&gt;under AAA settings in EAC.&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ff84c0e9b1314bd489d4c90e88690563_acca2528-15ee-4267-b517-ff55611e673e.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5825i97CCFBB753988C54/image-size/large?v=v2&amp;amp;px=999" role="button" title="ff84c0e9b1314bd489d4c90e88690563_acca2528-15ee-4267-b517-ff55611e673e.png" alt="ff84c0e9b1314bd489d4c90e88690563_acca2528-15ee-4267-b517-ff55611e673e.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;4- Update&amp;nbsp;the Radius cert on the EAC as follows:&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ff84c0e9b1314bd489d4c90e88690563_60985aa1-dd79-4a83-9d79-4551e4d9f2f7.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5266i1883939D0AF066AC/image-size/large?v=v2&amp;amp;px=999" role="button" title="ff84c0e9b1314bd489d4c90e88690563_60985aa1-dd79-4a83-9d79-4551e4d9f2f7.png" alt="ff84c0e9b1314bd489d4c90e88690563_60985aa1-dd79-4a83-9d79-4551e4d9f2f7.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5- Setup LDAP on EAC to authenticate your machines/computers, make sure you set it up with AD machine default values as per following:&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ff84c0e9b1314bd489d4c90e88690563_746792af-56e0-47ba-968e-61f88021c60c.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4625i5524B094B36E19FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="ff84c0e9b1314bd489d4c90e88690563_746792af-56e0-47ba-968e-61f88021c60c.png" alt="ff84c0e9b1314bd489d4c90e88690563_746792af-56e0-47ba-968e-61f88021c60c.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;6- Configure AAA rule as per below and make sure you have correct match pattern for host and LDAP settings selected, usually it is host/* or *@* depending on how your directory service is setup.&amp;nbsp;&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ff84c0e9b1314bd489d4c90e88690563_b9e5dc5c-24b3-4302-b8c2-0629560082e0.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4249iC8F9299E80C72C4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="ff84c0e9b1314bd489d4c90e88690563_b9e5dc5c-24b3-4302-b8c2-0629560082e0.png" alt="ff84c0e9b1314bd489d4c90e88690563_b9e5dc5c-24b3-4302-b8c2-0629560082e0.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;7- Finally, create an appropriate rule to address the cert based authentication, you either set it to a more generic auth type 802.1x or be more specific and set it to 802.1x EAP-TLS.&lt;/P&gt;&lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ff84c0e9b1314bd489d4c90e88690563_f3f1b8a1-d87b-4ab1-95af-dbdc987bd724.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4717iF47E3294D972A148/image-size/large?v=v2&amp;amp;px=999" role="button" title="ff84c0e9b1314bd489d4c90e88690563_f3f1b8a1-d87b-4ab1-95af-dbdc987bd724.png" alt="ff84c0e9b1314bd489d4c90e88690563_f3f1b8a1-d87b-4ab1-95af-dbdc987bd724.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;8- And most importantly, don’t&amp;nbsp;&amp;nbsp;forget to press the magic “Enforce” button&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper" image-alt="ff84c0e9b1314bd489d4c90e88690563_1f600.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4479iA83BE957BDA4AB34/image-size/large?v=v2&amp;amp;px=999" role="button" title="ff84c0e9b1314bd489d4c90e88690563_1f600.png" alt="ff84c0e9b1314bd489d4c90e88690563_1f600.png" /&gt;&lt;/span&gt; to ensure settings are pushed to EAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let us know how it goes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ovais&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 04:39:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/how-to-configure-xca-or-xcc-to-authenticate-domain-computers/m-p/72062#M2578</guid>
      <dc:creator>Ovais_Qayyum</dc:creator>
      <dc:date>2020-11-03T04:39:16Z</dc:date>
    </item>
  </channel>
</rss>

