<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: One SSID, One VLan, One IP Pool, Restrict Access by Role in ExtremeWireless (Identifi)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53916#M6049</link>
    <description>It's a coworking place and management wants it to be clean and easy.&lt;BR /&gt;
Therefore, they wish to have only one ssid and single ip pool.&lt;BR /&gt;
Wanted to do it using Extreme solutions like IdentiFI, NAC, Purview&lt;BR /&gt;</description>
    <pubDate>Fri, 06 May 2016 08:33:00 GMT</pubDate>
    <dc:creator>jaden</dc:creator>
    <dc:date>2016-05-06T08:33:00Z</dc:date>
    <item>
      <title>One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53914#M6047</link>
      <description>We have a requirement here.&lt;BR /&gt;
Situation as below.&lt;BR /&gt;
&lt;BR /&gt;
One SSID, One Vlan, One IP Pool.&lt;BR /&gt;
Differentiate by Roles such as Role A can access between Role A, internet and internal.&lt;BR /&gt;
Role B can only access to Internet and between Role B, means no internal.&lt;BR /&gt;
&lt;BR /&gt;
Is there a way to do this?&lt;BR /&gt;
&lt;BR /&gt;
Thanks.</description>
      <pubDate>Fri, 06 May 2016 08:23:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53914#M6047</guid>
      <dc:creator>jaden</dc:creator>
      <dc:date>2016-05-06T08:23:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53915#M6048</link>
      <description>Hmm. Is there a reason you have to have one vlan and ip pool?     If you were able to break from that you could use NPS like this.   https://community.extremenetworks.com/extreme/topics/one-ssid-redirect-to-two-different-vlans    Outside of that... I'd say you'd have to implement 802.1x and maybe use NAP.    https://technet.microsoft.com/en-us/network/bb545879.aspx    Anything more specific let me know. Good luck!!</description>
      <pubDate>Fri, 06 May 2016 08:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53915#M6048</guid>
      <dc:creator>Christopher_Dav</dc:creator>
      <dc:date>2016-05-06T08:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53916#M6049</link>
      <description>It's a coworking place and management wants it to be clean and easy.&lt;BR /&gt;
Therefore, they wish to have only one ssid and single ip pool.&lt;BR /&gt;
Wanted to do it using Extreme solutions like IdentiFI, NAC, Purview&lt;BR /&gt;</description>
      <pubDate>Fri, 06 May 2016 08:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53916#M6049</guid>
      <dc:creator>jaden</dc:creator>
      <dc:date>2016-05-06T08:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53917#M6050</link>
      <description>Understandable, although it'd be an easier solution to manage without this.   NAC is a solution. Well, IAC anyway.   http://learn.extremenetworks.com/rs/641-VMV-602/images/Identity-and-Access-Control-DS.pdf  This should be what you're looking for.</description>
      <pubDate>Fri, 06 May 2016 08:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53917#M6050</guid>
      <dc:creator>Christopher_Dav</dc:creator>
      <dc:date>2016-05-06T08:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53918#M6051</link>
      <description>Sorry of misunderstood, so NAC is called IAC now.&lt;BR /&gt;
How do I use this to achieve the objective.</description>
      <pubDate>Fri, 06 May 2016 08:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53918#M6051</guid>
      <dc:creator>jaden</dc:creator>
      <dc:date>2016-05-06T08:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53919#M6052</link>
      <description>The Keyword to this is "OnePolicy" . Based on the role the Client get's his own policy and can access exactly the targets you want. The only things you need are a wireless controller, several APs and a radius server. When you use Extreme Control (formerly NetSight and NAC), you can do this very easily.&lt;BR /&gt;
&lt;BR /&gt;
/André</description>
      <pubDate>Fri, 06 May 2016 10:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53919#M6052</guid>
      <dc:creator>André_Herkenrat</dc:creator>
      <dc:date>2016-05-06T10:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53920#M6053</link>
      <description>Is there any configuration example I could study on?&lt;BR /&gt;
Helps me to understand faster as I haven't configured any policy yet.&lt;BR /&gt;
&lt;BR /&gt;
Also, it could configured in OneView Policy sector right?</description>
      <pubDate>Fri, 06 May 2016 10:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53920#M6053</guid>
      <dc:creator>jaden</dc:creator>
      <dc:date>2016-05-06T10:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53921#M6054</link>
      <description>Hello, Jaden!&lt;BR /&gt;
&lt;BR /&gt;
I think simples way is to use authenticate roles based on MAC addresses of clients.&lt;BR /&gt;
Like Role A - accept all for MAC addresses A, B, C.&lt;BR /&gt;
Role B - (for example) deny dns, deny Internet gateway for MAC addresses D, E, F.&lt;BR /&gt;
&lt;BR /&gt;
Thank you!</description>
      <pubDate>Fri, 06 May 2016 10:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53921#M6054</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2016-05-06T10:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53922#M6055</link>
      <description>It's impossible to authenticate with MAC addresses as there will be Role B,C,D and so on.&lt;BR /&gt;
Tenant may come and go, this will be bulky of work.</description>
      <pubDate>Fri, 06 May 2016 10:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53922#M6055</guid>
      <dc:creator>jaden</dc:creator>
      <dc:date>2016-05-06T10:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53923#M6056</link>
      <description>So, in this case you have to use RADIUS/TACACS+, NAC and so on.&lt;BR /&gt;
(to have some condition on which map some role)&lt;BR /&gt;
&lt;BR /&gt;
Thank you!</description>
      <pubDate>Fri, 06 May 2016 10:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53923#M6056</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2016-05-06T10:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53924#M6057</link>
      <description>It is easy to accomplish that with EXtreme Control solution = NAC. In the management you will define criteria like MAC address or Username or hostname and based on that you assign the right profile. In the profile you define ACLs what such device/user can do...    Single SSID design is good.    Good luck.</description>
      <pubDate>Fri, 06 May 2016 11:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53924#M6057</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-05-06T11:26:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53925#M6058</link>
      <description>Any documentation can I refer to?&lt;BR /&gt;
I would like to use with the Radius server too.</description>
      <pubDate>Fri, 06 May 2016 11:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53925#M6058</guid>
      <dc:creator>jaden</dc:creator>
      <dc:date>2016-05-06T11:26:00Z</dc:date>
    </item>
    <item>
      <title>RE: One SSID, One VLan, One IP Pool, Restrict Access by Role</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53926#M6059</link>
      <description>If you have Radius-LDAP you can define de field Filter-ID attribute at the radius response, and create a rol with the same name at the Role tab.&lt;BR /&gt;
In the VirtualNetwork tab you configure the default role, but if the radius response can find a role with the same name that the Filter-ID attribute then role asigned change.&lt;BR /&gt;
I am not sure at all, but you can create a testing wlan</description>
      <pubDate>Fri, 06 May 2016 11:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/one-ssid-one-vlan-one-ip-pool-restrict-access-by-role/m-p/53926#M6059</guid>
      <dc:creator>FES</dc:creator>
      <dc:date>2016-05-06T11:26:00Z</dc:date>
    </item>
  </channel>
</rss>

