<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: MAC authentication error on X440-G2 in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/mac-authentication-error-on-x440-g2/m-p/31864#M812</link>
    <description>Hi Robert,&lt;BR /&gt;
&lt;BR /&gt;
Have you tried configuring from NAC already? Also, the authentication configuration on the 440-G2 can be accomplished from enabling via Policy in Management Center as well.&lt;BR /&gt;
&lt;BR /&gt;
The main item that I see that is problematic is: "configure netlogin mac authentication database-order local"&lt;BR /&gt;
&lt;BR /&gt;
You want this to be sent to RADIUS (which is the NAC) so that it can authenticate it and pass back a response. &lt;BR /&gt;
&lt;BR /&gt;
Hope that helps.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
&lt;BR /&gt;
Tyler</description>
    <pubDate>Tue, 14 Feb 2017 22:31:00 GMT</pubDate>
    <dc:creator>TylerMarcotte</dc:creator>
    <dc:date>2017-02-14T22:31:00Z</dc:date>
    <item>
      <title>MAC authentication error on X440-G2</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/mac-authentication-error-on-x440-g2/m-p/31863#M811</link>
      <description>Hello Guys !  I was trying to setup passive NAC (pass-through) with X440- G2-48p-10G4 switch.  I keep getting following error in the log: 02/14/2017 14:28:40.49 &lt;I&gt; Authentication failed for Network Login MAC user 001AE87F49D2 Mac 00:1A:E8:7F:49:D2 port 5  Here is my netlogin config:   * X440G2-48p-10G4.100 # sh configuration "netlogin" # # Module netLogin configuration. # enable netlogin mac configure netlogin mac authentication database-order local configure netlogin authentication protocol-order mac dot1x web-based configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48 encrypted "}eqrthug" enable netlogin ports 1-44 mac   and aaa config (NAC is my radius):  # Module aaa configuration. # configure radius netlogin 1 server 192.168.36.80 1812 client-ip 192.168.36.231 vr VR-Default configure radius 1 shared-secret encrypted "#$fPXY767cV5/sPn3skPxEgMScJGlMOi9B7tKPIpB7" configure radius-accounting netlogin 1 server 192.168.36.80 1813 client-ip 192.168.36.231 vr VR-Default configure radius-accounting 1 shared-secret encrypted "#$MHHPB8XKQVHhmbrvq4Og9d3stHCRr9PE29nNW5Ev" configure radius-accounting 1 timeout 10 enable radius disable radius mgmt-access enable radius netlogin configure radius timeout 15 enable radius-accounting disable radius-accounting mgmt-access enable radius-accounting netlogin configure account admin encrypted "$5$DDz7LO$enRGUuZ8/kFW74TqsMOXX2WrJhPZD1B1rxPuzhI4ifC"  On each access port I have: configure netlogin port &lt;NO.&gt; authentication mode optional  What is wrong ? Beside, I cannot enter the command: configure netlogin vlan &lt;VLAN_NAME&gt; - CLI doesn't allow me to put this command (?).  EXOS version is 21.1.1.4&lt;/VLAN_NAME&gt;&lt;/NO.&gt;&lt;/I&gt;</description>
      <pubDate>Tue, 14 Feb 2017 22:15:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/mac-authentication-error-on-x440-g2/m-p/31863#M811</guid>
      <dc:creator>Robert_Zdzieblo</dc:creator>
      <dc:date>2017-02-14T22:15:00Z</dc:date>
    </item>
    <item>
      <title>RE: MAC authentication error on X440-G2</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/mac-authentication-error-on-x440-g2/m-p/31864#M812</link>
      <description>Hi Robert,&lt;BR /&gt;
&lt;BR /&gt;
Have you tried configuring from NAC already? Also, the authentication configuration on the 440-G2 can be accomplished from enabling via Policy in Management Center as well.&lt;BR /&gt;
&lt;BR /&gt;
The main item that I see that is problematic is: "configure netlogin mac authentication database-order local"&lt;BR /&gt;
&lt;BR /&gt;
You want this to be sent to RADIUS (which is the NAC) so that it can authenticate it and pass back a response. &lt;BR /&gt;
&lt;BR /&gt;
Hope that helps.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
&lt;BR /&gt;
Tyler</description>
      <pubDate>Tue, 14 Feb 2017 22:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/mac-authentication-error-on-x440-g2/m-p/31864#M812</guid>
      <dc:creator>TylerMarcotte</dc:creator>
      <dc:date>2017-02-14T22:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: MAC authentication error on X440-G2</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/mac-authentication-error-on-x440-g2/m-p/31865#M813</link>
      <description>I'm not an XOS export but as far as I unterstand...&lt;BR /&gt;
&lt;BR /&gt;
"configure netlogin mac authentication database-order local" will use the local user database and doesn't use the RADIUS=NAC for authentication&lt;BR /&gt;
&lt;BR /&gt;
"configure netlogin add mac-list ff:ff:ff:ff:ff:ff 48 encrypted "}eqrthug"" the password will be used for all the MAC authentication clients - but I'd say they don't send one or the password is the MAC so I'd remove the "encrypted " option&lt;BR /&gt;
&lt;BR /&gt;
Could you post a "show netlogin mac" from the switch,&lt;BR /&gt;
&lt;BR /&gt;
I think you'd need to set the netlogin vlan before you enable netlogin.</description>
      <pubDate>Tue, 14 Feb 2017 22:32:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/mac-authentication-error-on-x440-g2/m-p/31865#M813</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2017-02-14T22:32:00Z</dc:date>
    </item>
    <item>
      <title>RE: MAC authentication error on X440-G2</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/mac-authentication-error-on-x440-g2/m-p/31866#M814</link>
      <description>Nice try, Tyler and Ronald! You both were right -I changed "configure netlogin mac authentication database-order local" to "radius" and then I have in my log: 02/14/2017 15:39:01.51 &lt;I&gt; Network Login MAC user 001AE87F49D2 logged in MAC 00:1A:E8:7F:49:D2 port 1 VLAN(s) "&lt;U&gt;", authentication Radius. I can also see the end-system in NAC database. Thank you !&lt;/U&gt;&lt;/I&gt;</description>
      <pubDate>Tue, 14 Feb 2017 22:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/mac-authentication-error-on-x440-g2/m-p/31866#M814</guid>
      <dc:creator>Robert_Zdzieblo</dc:creator>
      <dc:date>2017-02-14T22:44:00Z</dc:date>
    </item>
  </channel>
</rss>

