<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to dynamically assign a user to a VLAN depending on the AP location? in ExtremeWireless (Identifi)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-identifi/how-to-dynamically-assign-a-user-to-a-vlan-depending-on-the-ap/m-p/42252#M3187</link>
    <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;my goal is to use same SSID and (dynamically) assign users to a VLAN depending on location.&lt;BR /&gt;&lt;BR /&gt;I am looking into "Replace BSSID with Zone name" in RADIUS TLVs (RADIUS Access Request Message Options) but had no success making it work. I can see the proper "Called Station Identifier: Location x" in NPS Event Viewer though. Now I need to find a way to assign a proper VLAN to it at the AP ...&lt;BR /&gt;&lt;BR /&gt;I followed procedure on &lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000082506" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000082506&lt;/A&gt; but am missing something here ...&lt;BR /&gt;&lt;BR /&gt;Setup: B@AP topology, EAP-TLS, NPS, NAC (RADIUS Proxy mode)&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2017 14:25:00 GMT</pubDate>
    <dc:creator>Dusan_K_</dc:creator>
    <dc:date>2017-12-05T14:25:00Z</dc:date>
    <item>
      <title>How to dynamically assign a user to a VLAN depending on the AP location?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/how-to-dynamically-assign-a-user-to-a-vlan-depending-on-the-ap/m-p/42252#M3187</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;my goal is to use same SSID and (dynamically) assign users to a VLAN depending on location.&lt;BR /&gt;&lt;BR /&gt;I am looking into "Replace BSSID with Zone name" in RADIUS TLVs (RADIUS Access Request Message Options) but had no success making it work. I can see the proper "Called Station Identifier: Location x" in NPS Event Viewer though. Now I need to find a way to assign a proper VLAN to it at the AP ...&lt;BR /&gt;&lt;BR /&gt;I followed procedure on &lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000082506" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000082506&lt;/A&gt; but am missing something here ...&lt;BR /&gt;&lt;BR /&gt;Setup: B@AP topology, EAP-TLS, NPS, NAC (RADIUS Proxy mode)&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 14:25:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/how-to-dynamically-assign-a-user-to-a-vlan-depending-on-the-ap/m-p/42252#M3187</guid>
      <dc:creator>Dusan_K_</dc:creator>
      <dc:date>2017-12-05T14:25:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to dynamically assign a user to a VLAN depending on the AP location?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/how-to-dynamically-assign-a-user-to-a-vlan-depending-on-the-ap/m-p/42253#M3188</link>
      <description>Hi Dusan!&lt;BR /&gt;
&lt;BR /&gt;
you need :&lt;BR /&gt;
- location groups with APs&lt;BR /&gt;
- a rule on EWC for every VLAN you use (matching the rule you get from NAC via RADIUS !) with the configured VLAN topoogy&lt;BR /&gt;
- a NAC aaa rule for every location using this EWC rules. Radius request will overwrite the default rule on EWC&lt;BR /&gt;
- on EWC (Global/Authentication/RFC3580): choose: "Both RADIUS Filter-ID and Tunnel-Private-Group-ID attributes"&lt;BR /&gt;
- VLANs tagged on AP wired port&lt;BR /&gt;
&lt;BR /&gt;
try WLAN config without TLS and NPS ! Use NAC user store to prevent issues from NPS.&lt;BR /&gt;
&lt;BR /&gt;
br&lt;BR /&gt;
Volker</description>
      <pubDate>Tue, 05 Dec 2017 14:56:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/how-to-dynamically-assign-a-user-to-a-vlan-depending-on-the-ap/m-p/42253#M3188</guid>
      <dc:creator>Volker_Kull</dc:creator>
      <dc:date>2017-12-05T14:56:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to dynamically assign a user to a VLAN depending on the AP location?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/how-to-dynamically-assign-a-user-to-a-vlan-depending-on-the-ap/m-p/42254#M3189</link>
      <description>You'd take a look into this post to get some ideas how to troubleshoot the issue...&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://community.extremenetworks.com/extreme/topics/how-to-configure-windows-2012-nps-for-radius-authentication-with-extremewireless-controller" target="_blank" rel="nofollow noreferrer noopener"&gt;https://community.extremenetworks.com/extreme/topics/how-to-configure-windows-2012-nps-for-radius-au...&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Dec 2017 19:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/how-to-dynamically-assign-a-user-to-a-vlan-depending-on-the-ap/m-p/42254#M3189</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2017-12-05T19:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to dynamically assign a user to a VLAN depending on the AP location?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/how-to-dynamically-assign-a-user-to-a-vlan-depending-on-the-ap/m-p/42255#M3190</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
found a working solution w/ EAC!&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Client  EWC/B@AP  EAC (Radius Proxy)  NPS (EAP-TLS)&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
Here's my community contribution (based on &lt;A href="https://community.extremenetworks.com/extreme/people/volker_kull" target="_blank" rel="nofollow noreferrer noopener"&gt;Volker Kull&lt;/A&gt;'s advice):&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;@EWC&lt;/B&gt;&lt;BR /&gt;
&lt;OL&gt; VNS &amp;gt; Global &amp;gt; Authentication &amp;gt; RFC 3580 (ACCESS-ACCEPT) Options: &lt;B&gt;"Both RADIUS Filter-ID and Tunnel-Private-Group-ID attributes"&lt;/B&gt;  VNS &amp;gt; WLAN Service &amp;gt; Auth &amp;amp; Acct &amp;gt; RADIUS TLVs &amp;gt; Zone Support &amp;gt;  
RADIUS Request Called Station ID Options &amp;gt; &lt;B&gt;Replace BSSID with Zone name&lt;/B&gt;  AP &amp;gt; Edit selected AP &amp;gt; AP Properies &amp;gt; &lt;B&gt;Zone: &lt;/B&gt;  &lt;/OL&gt;
&lt;B&gt;@EAC&lt;BR /&gt;
&lt;/B&gt;&lt;BR /&gt;
&lt;B&gt;Access Control &amp;gt;&lt;/B&gt;&lt;BR /&gt;
&lt;OL&gt; Group Editor &amp;gt; Location Group:  
+ Add New Group (for each location):  
   + Switches: "List" 
   +  
   + Interface: "Wireless" 
   + AP ID:  
 
  Access Control Profiles &amp;gt; Policy Mappings &amp;gt; 
+ Add New:   
+ Map to Location: &lt;B&gt;Select Location&lt;/B&gt; 
+ Policy Role: "Enterprise Access" 
+ VLAN [id] Name: Add New:  +  
+ VLAN Egress: "&lt;B&gt;Tagged&lt;/B&gt;" 
 
  Access Control Profile 
+ Add New (for each location) 
+ Accept Policy: &lt;B&gt;Select Policy Mapping&lt;/B&gt; (step #2) 
+ Replace RADIUS Attributes with Accept Policy  
 
  Access Control Configurations &amp;gt; Default 
+ Add New Rule (for each location) 
+ Authentication Rule: &lt;B&gt;802.1X (EAP-TLS)&lt;/B&gt; 
+ Location Group: &lt;B&gt;Select Location &lt;/B&gt;(step #1)&lt;B&gt; 
&lt;/B&gt;+ Profile: &lt;B&gt;Select Access Control Profiles &lt;/B&gt;(step #2)&lt;B&gt; 
 
&lt;/B&gt;  Enforce &lt;/OL&gt;&lt;B&gt;Policy &amp;gt;&lt;/B&gt;&lt;BR /&gt;
&lt;OL&gt; Roles/Services &amp;gt; Enterprise Access &amp;gt; Mappings 
+ Add (Type: &lt;B&gt;RFC3580&lt;/B&gt;) VLAN:  for each location 
 
  Save Domain Enforce Domain (Ignore Errors) &lt;/OL&gt;
&lt;U&gt;Note: &lt;/U&gt;&lt;BR /&gt;
Client is authenticated against NPS.&lt;BR /&gt;
Policy (Role/VLAN mapping) is applied directly from EAC.&lt;BR /&gt;
Role &lt;B&gt;Enterprise Access&lt;/B&gt; is used as an example&lt;BR /&gt;
&lt;BR /&gt;
Cheers!</description>
      <pubDate>Tue, 05 Dec 2017 20:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/how-to-dynamically-assign-a-user-to-a-vlan-depending-on-the-ap/m-p/42255#M3190</guid>
      <dc:creator>Dusan_K_</dc:creator>
      <dc:date>2017-12-05T20:44:00Z</dc:date>
    </item>
  </channel>
</rss>

