<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: EOS NAC: What happen (in this config) when the RADIUS/NetSight Server (for MAC Auth Only) is not reachable? in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30199#M483</link>
    <description>you can limit the amount of concurrent authenticated MACs by CLI or XMC (NetSight) and there is also some hardware limit. different hardware limit for D2, B2, B3, C3, C5, XOS...&lt;BR /&gt;
&lt;BR /&gt;
each MAC address is authenticated and can be authorized with different policy profile (VLAN, QOS, rules)&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Thu, 06 Sep 2018 21:16:00 GMT</pubDate>
    <dc:creator>Zdeněk_Pala</dc:creator>
    <dc:date>2018-09-06T21:16:00Z</dc:date>
    <item>
      <title>EOS NAC: What happen (in this config) when the RADIUS/NetSight Server (for MAC Auth Only) is not reachable?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30194#M478</link>
      <description>Hello Community,&lt;BR /&gt;
&lt;BR /&gt;
I'm looking for details if Clients connected to "auth-reg" Ports will still have connectivity, If the Radius/NetSight Server is offline?&lt;BR /&gt;
&lt;BR /&gt;
set multiauth mode multi&lt;BR /&gt;
set multiauth precedence mac quarantine-agent dot1x pwa cep radius-snooping auto-tracking&lt;BR /&gt;
set multiauth port mode force-auth ge.1.1&lt;BR /&gt;
set multiauth port mode force-auth ge.1.2&lt;BR /&gt;
set multiauth port mode auth-reqd ge.1.3&lt;BR /&gt;
set multiauth port mode force-auth ge.1.4&lt;BR /&gt;
set multiauth port mode auth-reqd ge.1.5&lt;BR /&gt;
[..]&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
&lt;BR /&gt;
Jan&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Aug 2018 18:02:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30194#M478</guid>
      <dc:creator>SchmuFoo</dc:creator>
      <dc:date>2018-08-30T18:02:00Z</dc:date>
    </item>
    <item>
      <title>RE: EOS NAC: What happen (in this config) when the RADIUS/NetSight Server (for MAC Auth Only) is not reachable?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30195#M479</link>
      <description>BTW, with regards to auth-reqd VS. force-auth:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-disable-authentication-on-a-port-to-disable-authentication-on-a-SecureStack" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-disable-authentication-on-a-port-to...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Aug 2018 18:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30195#M479</guid>
      <dc:creator>SchmuFoo</dc:creator>
      <dc:date>2018-08-30T18:04:00Z</dc:date>
    </item>
    <item>
      <title>RE: EOS NAC: What happen (in this config) when the RADIUS/NetSight Server (for MAC Auth Only) is not reachable?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30196#M480</link>
      <description>Force-auth = the port is authorized no authentication will happen&lt;BR /&gt;
Auth-req = no traffic will pass until accept is received&lt;BR /&gt;
&lt;BR /&gt;
the third option is authentication optional (auto) = if the auth is not successful then the default port config is used (vlan, default policy, QoS...)&lt;BR /&gt;
&lt;BR /&gt;
You can have more radius servers = to accomplish HA</description>
      <pubDate>Fri, 31 Aug 2018 17:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30196#M480</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2018-08-31T17:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: EOS NAC: What happen (in this config) when the RADIUS/NetSight Server (for MAC Auth Only) is not reachable?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30197#M481</link>
      <description>Just to add to Zdenek points. If you are using ExtremeControl for NAC, then you can deploy two ExtremeControl NAC Engines (there is no extra licensing cost) that sync-up from the XMC Server upstream so the switch will fail-over from primary RADIUS engine to secondary RADIUS engine without disruption to network access.&lt;BR /&gt;
&lt;BR /&gt;
Shmulik&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 31 Aug 2018 20:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30197#M481</guid>
      <dc:creator>Shmulik</dc:creator>
      <dc:date>2018-08-31T20:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: EOS NAC: What happen (in this config) when the RADIUS/NetSight Server (for MAC Auth Only) is not reachable?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30198#M482</link>
      <description>Thanks for clarification!    As an follow-up:    What happens on one auth-reg Port with an, lets asume, 5 Port SOHO Switch connected to it? Does the Enterasys Switch allow/dissallow connected Clients also seperately?     Verbose: Multiple Clients connected through on single Enterasys Port through an additional unmanaged Switch. Does the NAC Access is still working on an individual Frame Level?    Thanks,    Jan</description>
      <pubDate>Thu, 06 Sep 2018 01:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30198#M482</guid>
      <dc:creator>SchmuFoo</dc:creator>
      <dc:date>2018-09-06T01:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: EOS NAC: What happen (in this config) when the RADIUS/NetSight Server (for MAC Auth Only) is not reachable?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30199#M483</link>
      <description>you can limit the amount of concurrent authenticated MACs by CLI or XMC (NetSight) and there is also some hardware limit. different hardware limit for D2, B2, B3, C3, C5, XOS...&lt;BR /&gt;
&lt;BR /&gt;
each MAC address is authenticated and can be authorized with different policy profile (VLAN, QOS, rules)&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Sep 2018 21:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30199#M483</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2018-09-06T21:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: EOS NAC: What happen (in this config) when the RADIUS/NetSight Server (for MAC Auth Only) is not reachable?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30200#M484</link>
      <description>Depends  if the switch is configured for single-auth or multi-auth on the port. If  single-auth then only the first mac is authenticated and following mac will  flow through untagged without authentication. If port is configured for  multi-auth, then each mac will get authenticated and assigned its own specific  VLAN even though it is coming from a SOHO switch connected to the port.&lt;BR /&gt;
&lt;BR /&gt;
Thanks!&lt;BR /&gt;
&lt;BR /&gt;
Shmulik</description>
      <pubDate>Fri, 07 Sep 2018 01:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/eos-nac-what-happen-in-this-config-when-the-radius-netsight/m-p/30200#M484</guid>
      <dc:creator>Shmulik</dc:creator>
      <dc:date>2018-09-07T01:52:00Z</dc:date>
    </item>
  </channel>
</rss>

