<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: restrict device type connecting to wireless in ExtremeWireless (Identifi)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41806#M3063</link>
    <description>thanks, ill see where we get to with mac-authentication otherwise will suggest NAC if they really want this feature&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Thu, 02 Jul 2015 23:08:00 GMT</pubDate>
    <dc:creator>Renne_Stuart</dc:creator>
    <dc:date>2015-07-02T23:08:00Z</dc:date>
    <item>
      <title>restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41802#M3059</link>
      <description>Is there a way of restricting the type of device that is allowed to connect to an SSID? One of our customers has an SSID that is enabled for Radius authentication and unless you have a laptop that is part of the domain it will not be allowed to connect, which is what they want. However the exception to this is if a user has a mobile device such as an android or apple device they are able to download a certificate once they authenticate with their domain credentials and connect. Is there a way of stopping the mobile devices connecting?&lt;BR /&gt;
&lt;BR /&gt;
Customer comments below:&lt;BR /&gt;
    From what I can tell with the  wifi, is that  - with or without a Radius policy (if its not a domain joined  laptop) you can’t seem to logon with staff or student credentials which is  fine. However with Andrio\IOS tested on ipad and phone, you can log onto "staff_SSID" with staff or student credentials and also, even before you get to  smoothwall to sign in, Apps will update such as Facebook.&lt;BR /&gt;
&lt;BR /&gt;
    Ideally Id  like to lock down the Staff to work effectively without mobile and apple  devices being able to connect.&lt;BR /&gt;
&lt;BR /&gt;
    Ipad asks to trust the school DC Cert and then lets you in. Android lets  you straight in. &lt;BR /&gt;
&lt;BR /&gt;
They currently have a v9 wireless controller without NAC.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Jul 2015 16:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41802#M3059</guid>
      <dc:creator>Renne_Stuart</dc:creator>
      <dc:date>2015-07-02T16:26:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41803#M3060</link>
      <description>I think the solution you're looking for is MAC Authentication, which can be applied in addition to RADIUS authentication for a VNS/WLAN Service/SSID.  In this case, you are requiring that the MAC address of a given WLAN device be checked against a list of predetermined allowable MAC addresses, and if the device isn't in that list, then that client will be denied access.</description>
      <pubDate>Thu, 02 Jul 2015 18:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41803#M3060</guid>
      <dc:creator>Hawkins__Bruce</dc:creator>
      <dc:date>2015-07-02T18:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41804#M3061</link>
      <description>i might give this a try and see where we get to, thanks.&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Jul 2015 18:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41804#M3061</guid>
      <dc:creator>Renne_Stuart</dc:creator>
      <dc:date>2015-07-02T18:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41805#M3062</link>
      <description>If the customer was interested in NAC, this is where you would typically check for these types of settings. Our NAC solution has the ability to detect device types, and based off that device type, it can make a decision about what to do for that user. That decision may be to deny access to the SSID so they cannot connect.&lt;BR /&gt;
&lt;BR /&gt;
So for your scenario, users may be able to connect with their domain credentials or certificates, but if the device type is a mobile device, then it will be denied and they will not connect to the SSID.</description>
      <pubDate>Thu, 02 Jul 2015 23:08:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41805#M3062</guid>
      <dc:creator>TylerMarcotte</dc:creator>
      <dc:date>2015-07-02T23:08:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41806#M3063</link>
      <description>thanks, ill see where we get to with mac-authentication otherwise will suggest NAC if they really want this feature&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Jul 2015 23:08:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41806#M3063</guid>
      <dc:creator>Renne_Stuart</dc:creator>
      <dc:date>2015-07-02T23:08:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41807#M3064</link>
      <description>We have NAC and would like to block Game Devices like Playstations from our SSIDs. How would we go about doing that?</description>
      <pubDate>Thu, 02 Jul 2015 23:08:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41807#M3064</guid>
      <dc:creator>Kent_Sapp</dc:creator>
      <dc:date>2015-07-02T23:08:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41808#M3065</link>
      <description>1. neither support 802.1X as far as I'm aware&lt;BR /&gt;
2. you can't "block" them - you'd just put them in a "deny" role, so they would be connected to the SSID but can't rx/tx any data and hopefully the owner of the device will not longer try to access the SSID&lt;BR /&gt;
&lt;BR /&gt;
So in case you use a PSK SSID just enable MAC based authentication and use the NAC for authentication.&lt;BR /&gt;
Add a rule with "device type group" gaming and a deny profile.&lt;BR /&gt;
Add another rule which must be after the deny which allows all other devices.&lt;BR /&gt;
&lt;BR /&gt;
If the gaming device connects to the SSID the NAC should authenticate it with the deny role and other devices get the allow role.&lt;BR /&gt;
&lt;BR /&gt;
I've tried it and it works for the PS4 but unfortunately the XBOX One is identified as device type "Windows".&lt;BR /&gt;
&lt;BR /&gt;
So you'd need to open a ticket so the GTAC could try to add a better fingerprint.&lt;BR /&gt;
They have done it for me with the right data within a day for some other devices.&lt;BR /&gt;
Here a link what data they need from you....&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/NAC-Troubleshooting-Tips-Debug-Methodology-For-OS-Detection" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/NAC-Troubleshooting-Tips-Debug-Methodology...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
-Ron</description>
      <pubDate>Thu, 02 Jul 2015 23:08:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41808#M3065</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2015-07-02T23:08:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41809#M3066</link>
      <description>&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="e4f64c6168db4575bb8fa4cabed4fe84_RackMultipart20150826-27329-6q011n-NAC_gaming_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3555i75A5A933F7E78F0F/image-size/large?v=v2&amp;amp;px=999" role="button" title="e4f64c6168db4575bb8fa4cabed4fe84_RackMultipart20150826-27329-6q011n-NAC_gaming_inline.png" alt="e4f64c6168db4575bb8fa4cabed4fe84_RackMultipart20150826-27329-6q011n-NAC_gaming_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Jul 2015 23:08:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41809#M3066</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2015-07-02T23:08:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41810#M3067</link>
      <description>Could you please tell what kind of EAP authentication is used..... PEAP or TLS (username/password or client certificates).&lt;BR /&gt;
&lt;BR /&gt;
- connect to the staff SSID with student credentials&lt;BR /&gt;
That sounds like something is not configured correctly as I don't think that a student account should be able to connect to the staff SSID.&lt;BR /&gt;
&lt;BR /&gt;
-Ron</description>
      <pubDate>Thu, 02 Jul 2015 23:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41810#M3067</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2015-07-02T23:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41811#M3068</link>
      <description>I'm not sure Ron, ill check and get back to you.&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Jul 2015 23:34:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41811#M3068</guid>
      <dc:creator>Renne_Stuart</dc:creator>
      <dc:date>2015-07-02T23:34:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41812#M3069</link>
      <description>NAC BYOD would be the best solution. But what I would like to check is, anybody here done DHCP fingerprinting before?&lt;BR /&gt;
&lt;BR /&gt;
-Karthik.&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Jul 2015 11:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41812#M3069</guid>
      <dc:creator>Karthik1</dc:creator>
      <dc:date>2015-07-03T11:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: restrict device type connecting to wireless</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41813#M3070</link>
      <description>We recommend it and deploy it all the time Karthik, did you have any questions on it?</description>
      <pubDate>Fri, 03 Jul 2015 11:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/restrict-device-type-connecting-to-wireless/m-p/41813#M3070</guid>
      <dc:creator>Doug</dc:creator>
      <dc:date>2015-07-03T11:16:00Z</dc:date>
    </item>
  </channel>
</rss>

