<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to configure guest vlan in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-configure-guest-vlan/m-p/21608#M1582</link>
    <description>Create Date: Jan 18 2013 10:56AM&lt;BR /&gt;
&lt;BR /&gt;
Hello Ethernation,&lt;BR /&gt;
&lt;BR /&gt;
I'm trying to configure netlogin mode 802.1x with guest vlan feature enable.&lt;BR /&gt;
Configuration is working for an authenticated supplicant which is receiving his destination VLAN from a NPS Server.&lt;BR /&gt;
&lt;BR /&gt;
Now i want to drop a unauthenticated supplicant on a guest vlan.&lt;BR /&gt;
I tried this :&lt;BR /&gt;
 # conf netlogin dot1x guest-vlan "invite" ports 3:20&lt;BR /&gt;
WARNING: Ports on which 802.1X is not enabled or is not the only enabled Netlogin protocol were ignored.&lt;BR /&gt;
 # ena netlogin dot1x guest-vlan port 3:20&lt;BR /&gt;
WARNING: Ports on which 802.1X is not enabled or is not the only enabled Netlogin protocol were ignored.&lt;BR /&gt;
&lt;BR /&gt;
So guest vlan remains not configured and disabled.&lt;BR /&gt;
&lt;BR /&gt;
802.1X is the only enabled netlogin protocol on that port.&lt;BR /&gt;
My netlogin configuration :&lt;BR /&gt;
NetLogin Authentication Mode : web-based DISABLED;  802.1x ENABLED;  mac-based DISABLED&lt;BR /&gt;
NetLogin VLAN                : "authlan"&lt;BR /&gt;
NetLogin move-fail-action    : Deny&lt;BR /&gt;
NetLogin Client Aging Time   : 5 minutes&lt;BR /&gt;
Dynamic VLAN Creation        : Disabled&lt;BR /&gt;
Dynamic VLAN Uplink Ports    : None&lt;BR /&gt;
&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
        Web-based Mode Global Configuration&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
Base-URL                 : network-access.com&lt;BR /&gt;
Default-Redirect-Page    : ENABLED; http://www.extremenetworks.com&lt;BR /&gt;
Logout-privilege         : YES&lt;BR /&gt;
Netlogin Session-Refresh : ENABLED; 3 minute(s) 0 second(s)&lt;BR /&gt;
Refresh failures allowed : 0&lt;BR /&gt;
Reauthenticate on refresh: Disabled&lt;BR /&gt;
Authentication Database  : Radius, Local-User database&lt;BR /&gt;
Proxy Ports              : 80(http),443(https)&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
        802.1x Mode Global Configuration&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
Quiet Period                    : 60&lt;BR /&gt;
Supplicant Response Timeout     : 30&lt;BR /&gt;
Re-authentication period        : 3600&lt;BR /&gt;
Max Re-authentications          : 3&lt;BR /&gt;
RADIUS server timeout           : 30&lt;BR /&gt;
EAPOL MPDU version to transmit  : v1&lt;BR /&gt;
Authentication Database         : Radius&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
          MAC Mode Global Configuration&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
Re-authentication period        : 0 (Re-authentication disabled)&lt;BR /&gt;
Authentication Database         : Radius, Local-User database&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
&lt;BR /&gt;
Port: 3:20,  Vlan: userftp,  State: Enabled,  Authentication: 802.1x&lt;BR /&gt;
Guest Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
Authentication Failure Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
Authentication Service-Unavailable Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
&lt;BR /&gt;
MAC                IP address       Authenticated     Type    ReAuth-Timer   User&lt;BR /&gt;
00:17:08:46:39:24  0.0.0.0          No                802.1x  0&lt;BR /&gt;
-----------------------------------------------&lt;BR /&gt;
(B) - Client entry Blackholed in FDB&lt;BR /&gt;
&lt;BR /&gt;
Port: 4:17,  Vlan: userftp,  State: Enabled,  Authentication: 802.1x&lt;BR /&gt;
Guest Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
Authentication Failure Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
Authentication Service-Unavailable Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
&lt;BR /&gt;
MAC                IP address       Authenticated     Type    ReAuth-Timer   User&lt;BR /&gt;
08:2e:5f:06:02:26  0.0.0.0          Yes, Radius       802.1x  155            FTV-PUBLICITE\fdu&lt;BR /&gt;
&lt;BR /&gt;
Any idea please?&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
FrÉdÉric.&lt;BR /&gt;
&lt;BR /&gt;
  (from fredftp)&lt;/NOT&gt;&lt;/NOT&gt;&lt;/NOT&gt;&lt;/NOT&gt;&lt;/NOT&gt;&lt;/NOT&gt;</description>
    <pubDate>Wed, 08 Jan 2014 05:58:00 GMT</pubDate>
    <dc:creator>EtherNation_Use</dc:creator>
    <dc:date>2014-01-08T05:58:00Z</dc:date>
    <item>
      <title>How to configure guest vlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-configure-guest-vlan/m-p/21608#M1582</link>
      <description>Create Date: Jan 18 2013 10:56AM&lt;BR /&gt;
&lt;BR /&gt;
Hello Ethernation,&lt;BR /&gt;
&lt;BR /&gt;
I'm trying to configure netlogin mode 802.1x with guest vlan feature enable.&lt;BR /&gt;
Configuration is working for an authenticated supplicant which is receiving his destination VLAN from a NPS Server.&lt;BR /&gt;
&lt;BR /&gt;
Now i want to drop a unauthenticated supplicant on a guest vlan.&lt;BR /&gt;
I tried this :&lt;BR /&gt;
 # conf netlogin dot1x guest-vlan "invite" ports 3:20&lt;BR /&gt;
WARNING: Ports on which 802.1X is not enabled or is not the only enabled Netlogin protocol were ignored.&lt;BR /&gt;
 # ena netlogin dot1x guest-vlan port 3:20&lt;BR /&gt;
WARNING: Ports on which 802.1X is not enabled or is not the only enabled Netlogin protocol were ignored.&lt;BR /&gt;
&lt;BR /&gt;
So guest vlan remains not configured and disabled.&lt;BR /&gt;
&lt;BR /&gt;
802.1X is the only enabled netlogin protocol on that port.&lt;BR /&gt;
My netlogin configuration :&lt;BR /&gt;
NetLogin Authentication Mode : web-based DISABLED;  802.1x ENABLED;  mac-based DISABLED&lt;BR /&gt;
NetLogin VLAN                : "authlan"&lt;BR /&gt;
NetLogin move-fail-action    : Deny&lt;BR /&gt;
NetLogin Client Aging Time   : 5 minutes&lt;BR /&gt;
Dynamic VLAN Creation        : Disabled&lt;BR /&gt;
Dynamic VLAN Uplink Ports    : None&lt;BR /&gt;
&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
        Web-based Mode Global Configuration&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
Base-URL                 : network-access.com&lt;BR /&gt;
Default-Redirect-Page    : ENABLED; http://www.extremenetworks.com&lt;BR /&gt;
Logout-privilege         : YES&lt;BR /&gt;
Netlogin Session-Refresh : ENABLED; 3 minute(s) 0 second(s)&lt;BR /&gt;
Refresh failures allowed : 0&lt;BR /&gt;
Reauthenticate on refresh: Disabled&lt;BR /&gt;
Authentication Database  : Radius, Local-User database&lt;BR /&gt;
Proxy Ports              : 80(http),443(https)&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
        802.1x Mode Global Configuration&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
Quiet Period                    : 60&lt;BR /&gt;
Supplicant Response Timeout     : 30&lt;BR /&gt;
Re-authentication period        : 3600&lt;BR /&gt;
Max Re-authentications          : 3&lt;BR /&gt;
RADIUS server timeout           : 30&lt;BR /&gt;
EAPOL MPDU version to transmit  : v1&lt;BR /&gt;
Authentication Database         : Radius&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
          MAC Mode Global Configuration&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
Re-authentication period        : 0 (Re-authentication disabled)&lt;BR /&gt;
Authentication Database         : Radius, Local-User database&lt;BR /&gt;
------------------------------------------------&lt;BR /&gt;
&lt;BR /&gt;
Port: 3:20,  Vlan: userftp,  State: Enabled,  Authentication: 802.1x&lt;BR /&gt;
Guest Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
Authentication Failure Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
Authentication Service-Unavailable Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
&lt;BR /&gt;
MAC                IP address       Authenticated     Type    ReAuth-Timer   User&lt;BR /&gt;
00:17:08:46:39:24  0.0.0.0          No                802.1x  0&lt;BR /&gt;
-----------------------------------------------&lt;BR /&gt;
(B) - Client entry Blackholed in FDB&lt;BR /&gt;
&lt;BR /&gt;
Port: 4:17,  Vlan: userftp,  State: Enabled,  Authentication: 802.1x&lt;BR /&gt;
Guest Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
Authentication Failure Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
Authentication Service-Unavailable Vlan &lt;NOT configured=""&gt;: Disabled&lt;BR /&gt;
&lt;BR /&gt;
MAC                IP address       Authenticated     Type    ReAuth-Timer   User&lt;BR /&gt;
08:2e:5f:06:02:26  0.0.0.0          Yes, Radius       802.1x  155            FTV-PUBLICITE\fdu&lt;BR /&gt;
&lt;BR /&gt;
Any idea please?&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
FrÉdÉric.&lt;BR /&gt;
&lt;BR /&gt;
  (from fredftp)&lt;/NOT&gt;&lt;/NOT&gt;&lt;/NOT&gt;&lt;/NOT&gt;&lt;/NOT&gt;&lt;/NOT&gt;</description>
      <pubDate>Wed, 08 Jan 2014 05:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-configure-guest-vlan/m-p/21608#M1582</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:58:00Z</dc:date>
    </item>
    <item>
      <title>RE: How to configure guest vlan</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-configure-guest-vlan/m-p/21609#M1583</link>
      <description>Create Date: Jan 18 2013  5:41PM&lt;BR /&gt;
&lt;BR /&gt;
Solved&lt;BR /&gt;
&lt;BR /&gt;
Unconfigured all related netlogin configuration.&lt;BR /&gt;
started a new netlogin dotx mode from scratch&lt;BR /&gt;
Enabling guest vlan with no problems now on any netlogin port  (from fredftp)</description>
      <pubDate>Wed, 08 Jan 2014 05:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-configure-guest-vlan/m-p/21609#M1583</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:58:00Z</dc:date>
    </item>
  </channel>
</rss>

