<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Wireless DNS Proxy NAC (Captive Portal) via Eth1 in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32089#M854</link>
    <description>Hi Martin,&lt;BR /&gt;
&lt;BR /&gt;
eth0 and eth1 are just interface as per my understanding and there shouldnt be any issues when you use them.&lt;BR /&gt;
&lt;BR /&gt;
As i can see only DNS is not doing its job here.&lt;BR /&gt;
&lt;BR /&gt;
We have to select end system service with rest of the services &lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;&lt;B&gt;&lt;U&gt;End system&lt;/U&gt;&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
The communication to and from end-systems.&lt;BR /&gt;
  &lt;I&gt;Sub-Services:&lt;/I&gt; Portal: Registration &amp;amp; Remediation, Assessment, NetBIOS &amp;amp; DNS Proxy &lt;BR /&gt;
&lt;BR /&gt;
even eth0 is also responding the same way then we have to check the configuration , you might need to create GTAC case.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Suresh,B&lt;BR /&gt;
&lt;BR /&gt;&lt;/I&gt;</description>
    <pubDate>Wed, 20 Dec 2017 11:18:00 GMT</pubDate>
    <dc:creator>Bharathiraja__S</dc:creator>
    <dc:date>2017-12-20T11:18:00Z</dc:date>
    <item>
      <title>Wireless DNS Proxy NAC (Captive Portal) via Eth1</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32085#M850</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Do you know if DNS Proxy is supported on Eth1 via NAC?&lt;BR /&gt;&lt;BR /&gt;The reason this is required is that we have a Guest wireless bridged directly out the second interface on a pair of wireless controllers to a a dedicated DMZ network for Guest internet traffic only.&lt;BR /&gt;&lt;BR /&gt;Currently we have a pair of NAC appliances whom Eth1 interfaces are in the Guest DMZ network.&lt;BR /&gt;&lt;BR /&gt;Currently I have this working by redirecting to Captive Portal using controller based redirect with the redirect URL pointing to the IP address of one of the NAC appliances.&lt;BR /&gt;&lt;BR /&gt;The reason I have to change this to DNS proxy is that although I have some load balancers available that would support fail-over to either of the NAC's, these do not have direct access to the internal DNS servers in the DMZ network to resolve any URLs I send to them.&lt;BR /&gt;&lt;BR /&gt;With the use of the Load Balancers I just need to configure the controller based redirect to point to a single URL that points to the load balancers, which in turn resolves to either of the NAC devices (via an internal DNS) dependant on which NAC is available.&lt;BR /&gt;&lt;BR /&gt;The problem I have is that in this particular case I'm not able to plum in the DNS directly into the DMZ network so I have nothing to resolve too, so will need to be reliant on DNS Proxy.&lt;BR /&gt;&lt;BR /&gt;Have confiugred DNS proxy as per the following GTAC article:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000079035" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000079035&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If I connect to the Guest Wireless I don't get redirected to captive portal, although if I put in the IP address of the NAC device in the client you get the captive portal.&lt;BR /&gt;&lt;BR /&gt;In addition if I put in a URL it does get resolved to the correct IP instead of the NACs, so just seems to be a problem with DNS proxy not doing its job and replacing the IP address of the URL with NAC's instead to display the captive portal page.&lt;BR /&gt;&lt;BR /&gt;My concern is that I need an option on the Eth1 interface that is greyed out, as per below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="fbd47bc0e637485d8271288acd91207b_RackMultipart20171218-128533-uto6ad-DNSProxy1_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/278i9AECDC00C7787DD7/image-size/large?v=v2&amp;amp;px=999" role="button" title="fbd47bc0e637485d8271288acd91207b_RackMultipart20171218-128533-uto6ad-DNSProxy1_inline.png" alt="fbd47bc0e637485d8271288acd91207b_RackMultipart20171218-128533-uto6ad-DNSProxy1_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is a summary of my wireless rules:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="fbd47bc0e637485d8271288acd91207b_RackMultipart20171218-28567-7ycf7c-DNSProxy02_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1600iC36BB47413E7F60B/image-size/large?v=v2&amp;amp;px=999" role="button" title="fbd47bc0e637485d8271288acd91207b_RackMultipart20171218-28567-7ycf7c-DNSProxy02_inline.png" alt="fbd47bc0e637485d8271288acd91207b_RackMultipart20171218-28567-7ycf7c-DNSProxy02_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Wireless controller is running version 10.41.01.0082&lt;BR /&gt;&lt;BR /&gt;NAC / Netsight is running version 8.0.3.46&lt;BR /&gt;&lt;BR /&gt;Many thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 00:24:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32085#M850</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2017-12-19T00:24:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless DNS Proxy NAC (Captive Portal) via Eth1</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32086#M851</link>
      <description>&lt;P&gt;Hi Martin,&lt;BR /&gt;&lt;BR /&gt;Please check below KB for basic debug about DNS proxy issue in NAC.&lt;BR /&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000080258" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000080258&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;also just make sure eth1 is enabled in NAC interface configuration.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000078313" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000078313&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Suresh.B&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 15:14:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32086#M851</guid>
      <dc:creator>Bharathiraja__S</dc:creator>
      <dc:date>2017-12-19T15:14:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless DNS Proxy NAC (Captive Portal) via Eth1</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32087#M852</link>
      <description>Hi Martin,&lt;BR /&gt;
&lt;BR /&gt;
Just wanted to make sure , if you use eth0 will you be able to get this set up working ?&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Suresh.B &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 19 Dec 2017 15:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32087#M852</guid>
      <dc:creator>Bharathiraja__S</dc:creator>
      <dc:date>2017-12-19T15:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless DNS Proxy NAC (Captive Portal) via Eth1</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32088#M853</link>
      <description>Hi Suresh,&lt;BR /&gt;
&lt;BR /&gt;
Thanks for replying.&lt;BR /&gt;
&lt;BR /&gt;
Captive portal is currently working via Eth1 but using the wireless controller redirect, and it also works if I manually point the client to either Eth1 interface of either NAC. The bit I'm not sure about is DNS Proxy support on Eth1, or in addition the way that I am trying to do it.&lt;BR /&gt;
&lt;BR /&gt;
That's a good point, I'll see if I can set something up to try this on Eth0, and do some of the debugging you have suggesting in the GTAC article.&lt;BR /&gt;
&lt;BR /&gt;
Here is a diagram of the setup, help you visualise what I have described:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="199474feb8854ffa96bc36da8ee0af61_RackMultipart20171219-41275-1h9u6e4-LoadBalancers_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1327iB41893D7984E8C17/image-size/large?v=v2&amp;amp;px=999" role="button" title="199474feb8854ffa96bc36da8ee0af61_RackMultipart20171219-41275-1h9u6e4-LoadBalancers_inline.png" alt="199474feb8854ffa96bc36da8ee0af61_RackMultipart20171219-41275-1h9u6e4-LoadBalancers_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
In addition, from the screenshot of my initial post of the Eth1 interface do I need to set the 'mode' to 'Advanced Configuration' and if so what services do I need (if any) to select?&lt;BR /&gt;
&lt;BR /&gt;
My assumption here is also that you believe DNSProxy should work in this scenario, which is at least one main hurdle out the way with as I can then get down to just debugging it?&lt;BR /&gt;
&lt;BR /&gt;
Many thanks.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 19 Dec 2017 16:00:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32088#M853</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2017-12-19T16:00:00Z</dc:date>
    </item>
    <item>
      <title>RE: Wireless DNS Proxy NAC (Captive Portal) via Eth1</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32089#M854</link>
      <description>Hi Martin,&lt;BR /&gt;
&lt;BR /&gt;
eth0 and eth1 are just interface as per my understanding and there shouldnt be any issues when you use them.&lt;BR /&gt;
&lt;BR /&gt;
As i can see only DNS is not doing its job here.&lt;BR /&gt;
&lt;BR /&gt;
We have to select end system service with rest of the services &lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;&lt;B&gt;&lt;U&gt;End system&lt;/U&gt;&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
The communication to and from end-systems.&lt;BR /&gt;
  &lt;I&gt;Sub-Services:&lt;/I&gt; Portal: Registration &amp;amp; Remediation, Assessment, NetBIOS &amp;amp; DNS Proxy &lt;BR /&gt;
&lt;BR /&gt;
even eth0 is also responding the same way then we have to check the configuration , you might need to create GTAC case.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Suresh,B&lt;BR /&gt;
&lt;BR /&gt;&lt;/I&gt;</description>
      <pubDate>Wed, 20 Dec 2017 11:18:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/wireless-dns-proxy-nac-captive-portal-via-eth1/m-p/32089#M854</guid>
      <dc:creator>Bharathiraja__S</dc:creator>
      <dc:date>2017-12-20T11:18:00Z</dc:date>
    </item>
  </channel>
</rss>

