<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Wired Guest Network in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31339#M702</link>
    <description>You can create a network resource that maybe all of your servers are on.  10.0.1.0/24&lt;BR /&gt;
&lt;BR /&gt;
You can then block all access to that network resource, but use IP socket destination to punch a hole through it, say you have 10.0.1.4 and it's a DNS server.  You could create a rule to open up socket 53.  Anyway, you will have to make it your own and these things very greatly!</description>
    <pubDate>Fri, 07 Jul 2017 02:27:00 GMT</pubDate>
    <dc:creator>Jeremy_Gibbs</dc:creator>
    <dc:date>2017-07-07T02:27:00Z</dc:date>
    <item>
      <title>Wired Guest Network</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31336#M699</link>
      <description>How have you implemented guest access on your wired network?  I currently have a fully segregated guest network on wireless, but nothing in place on wired.  I would like to implement it on wired, but it needs to be able to switch to staff access based on domain credentials (derived from Windows if possible).  &lt;BR /&gt;
&lt;BR /&gt;
So, ideally:&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;User plugs into network and doesn't have a domain account (or is in a non-staff OU) they get internet only access. 
&lt;/LI&gt;&lt;LI&gt;User plugs into network and has logged onto their laptop with domain accepted credentials they get staff access (internet and internal resources).&lt;/LI&gt;&lt;/UL&gt;
It may be better to key on machines that are on the domain first.  So, if the user machine is on the domain, they will get staff access.  In this case, I would like to keep the wireless authentication as is (since work supplied phones are not on the domain).&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Jul 2017 23:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31336#M699</guid>
      <dc:creator>Terren_Crider</dc:creator>
      <dc:date>2017-07-06T23:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wired Guest Network</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31337#M700</link>
      <description>We do this using Extreme Policy and NAC.  If you are an unknown computer, not owned by the school and not in AD, you get redirected to a registration page.  You will then get an internet only policy that restricts you to the internet.  If you have a campus owned computer, you might be doing .1x or MAC AUTH based on groups, AD groups, end-system groups, location groups etc... The sky is the limit.</description>
      <pubDate>Fri, 07 Jul 2017 02:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31337#M700</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2017-07-07T02:27:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wired Guest Network</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31338#M701</link>
      <description>If possible, could you share your internet only policy?  There's one that was pre-built in my Policy but it does not restrict web traffic to internal resources.</description>
      <pubDate>Fri, 07 Jul 2017 02:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31338#M701</guid>
      <dc:creator>Terren_Crider</dc:creator>
      <dc:date>2017-07-07T02:27:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wired Guest Network</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31339#M702</link>
      <description>You can create a network resource that maybe all of your servers are on.  10.0.1.0/24&lt;BR /&gt;
&lt;BR /&gt;
You can then block all access to that network resource, but use IP socket destination to punch a hole through it, say you have 10.0.1.4 and it's a DNS server.  You could create a rule to open up socket 53.  Anyway, you will have to make it your own and these things very greatly!</description>
      <pubDate>Fri, 07 Jul 2017 02:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31339#M702</guid>
      <dc:creator>Jeremy_Gibbs</dc:creator>
      <dc:date>2017-07-07T02:27:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wired Guest Network</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31340#M703</link>
      <description>Hello Terren,&lt;BR /&gt;
&lt;BR /&gt;
If you are using EXOS, you could try Netlogin feature.&lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;For guest user: you could use Web-based authentication and associate one vlan for guest user only. 
&lt;/LI&gt;&lt;LI&gt;For staff user: you could use 802.1X authentication.&lt;/LI&gt;&lt;/UL&gt;
Network Login Overview&lt;BR /&gt;
&lt;A href="http://documentation.extremenetworks.com/exos/EXOS_21_1/Netlogin/c_overview.shtml" target="_blank" rel="nofollow noreferrer noopener"&gt;http://documentation.extremenetworks.com/exos/EXOS_21_1/Netlogin/c_overview.shtml&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Jul 2017 04:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wired-guest-network/m-p/31340#M703</guid>
      <dc:creator>Bin</dc:creator>
      <dc:date>2017-07-07T04:54:00Z</dc:date>
    </item>
  </channel>
</rss>

