<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: RADIUS / AAA question in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59872#M5021</link>
    <description>Hello Vedra,&lt;BR /&gt;
&lt;BR /&gt;
when you use AAA policy configuration "onboard controller" or "onboar centralized-controller" the RADIUS is encapsulated within MINT(UDP 24576) so you do not have to enable any other port.&lt;BR /&gt;
&lt;BR /&gt;
Regarding the voucher size - this is supposed to be printed using mobile printers. There is unfortunately not much you can change on WiNG side. &lt;BR /&gt;
More options are under &lt;I&gt;Printer preferences&lt;/I&gt;&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Ondrej</description>
    <pubDate>Mon, 20 Nov 2017 16:50:00 GMT</pubDate>
    <dc:creator>Ondrej_Lepa</dc:creator>
    <dc:date>2017-11-20T16:50:00Z</dc:date>
    <item>
      <title>RADIUS / AAA question</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59871#M5020</link>
      <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
A site has 24 AP7522s, they are adopted to a NOC VX9000 over WAN. The VX9000 has UDP 24576 and TCP 443 opened. I'd like to create a CP with internal RADIUS / AAA and then create bulk vouchers for guests. The CP will be hosted on the APs.&lt;BR /&gt;
&lt;BR /&gt;
Option A - Use internal RADIUS on the VX9000&lt;BR /&gt;
A1 - Under AAA policy -&amp;gt; Server Type do I use onboard-controller or onboard-centralized-controller?&lt;BR /&gt;
Is onboard-controller used when there is a site controller?&lt;BR /&gt;
A2 - Do I need to open up UDP 1812 and 1813 on the VX?&lt;BR /&gt;
&lt;BR /&gt;
Option B - Use internal RADIUS on the APs&lt;BR /&gt;
B1 - Do I enable RADIUS policy for only one AP or can I enable it in the profile for all APs? If enabled on all APs, do they synchronize data between them? How does it work?&lt;BR /&gt;
B2 - Am I limited to 256 RADIUS users in this scenario?&lt;BR /&gt;
&lt;BR /&gt;
Regarding vouchers, if printing to A4 paper, it seems to print one voucher per page. This seems like a waste. How to change this?&lt;BR /&gt;
&lt;BR /&gt;
Thanks.&lt;BR /&gt;
&lt;BR /&gt;
Best regards.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 20 Nov 2017 03:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59871#M5020</guid>
      <dc:creator>Vedran_Jurak</dc:creator>
      <dc:date>2017-11-20T03:36:00Z</dc:date>
    </item>
    <item>
      <title>RE: RADIUS / AAA question</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59872#M5021</link>
      <description>Hello Vedra,&lt;BR /&gt;
&lt;BR /&gt;
when you use AAA policy configuration "onboard controller" or "onboar centralized-controller" the RADIUS is encapsulated within MINT(UDP 24576) so you do not have to enable any other port.&lt;BR /&gt;
&lt;BR /&gt;
Regarding the voucher size - this is supposed to be printed using mobile printers. There is unfortunately not much you can change on WiNG side. &lt;BR /&gt;
More options are under &lt;I&gt;Printer preferences&lt;/I&gt;&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Ondrej</description>
      <pubDate>Mon, 20 Nov 2017 16:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59872#M5021</guid>
      <dc:creator>Ondrej_Lepa</dc:creator>
      <dc:date>2017-11-20T16:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: RADIUS / AAA question</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59873#M5022</link>
      <description>Hello Ondrej,&lt;BR /&gt;
&lt;BR /&gt;
Thanks for replying. I will check with the end user if they have some mobile / label printer.&lt;BR /&gt;
&lt;BR /&gt;
What about option B? I will probably not use it, but I would like to know. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
According to the centralized deployment guide: &lt;BR /&gt;
&lt;BR /&gt;
"When backup RADIUS services are provided locally on the Independent Access Points at a site, a RADIUS Server Policy will need to be defined and assigned to the Access Point Profile. The RADIUS Server Policy includes the RADIUS Server configuration along with specific User Pools. During a WAN outage, each Independent Access Point will be fully capable of authenticating EAP or Hotspot users locally providing no interruption to Wireless services at the remote site."&lt;BR /&gt;
&lt;BR /&gt;
This implies to just enable the RADIUS server policy in the AP profile and forget about it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Best regards.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 20 Nov 2017 17:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59873#M5022</guid>
      <dc:creator>Vedran_Jurak</dc:creator>
      <dc:date>2017-11-20T17:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: RADIUS / AAA question</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59874#M5023</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
for option B shall use:&lt;BR /&gt;
&lt;UL&gt; use &lt;I&gt;onboard self &lt;/I&gt;RADIUS authentication server map RADIUS server policy to affected devices profile these &lt;B&gt;won't &lt;/B&gt;synchronize data - &lt;B&gt;NO ROAMING&lt;/B&gt;  &lt;/UL&gt;Using the bulk user creating on web admin I was able to create ~8200 users (didn't test more) and I am able to print up to 4 vouchers per page (WiNG 5.9)&lt;BR /&gt;
See below:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="f3a6c643463a49ce8028ad02b9073b3b_RackMultipart20171120-84246-mo4o3s-voucher1_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3089i1683D4F05D4ECA94/image-size/large?v=v2&amp;amp;px=999" role="button" title="f3a6c643463a49ce8028ad02b9073b3b_RackMultipart20171120-84246-mo4o3s-voucher1_inline.png" alt="f3a6c643463a49ce8028ad02b9073b3b_RackMultipart20171120-84246-mo4o3s-voucher1_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Ondrej</description>
      <pubDate>Mon, 20 Nov 2017 17:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59874#M5023</guid>
      <dc:creator>Ondrej_Lepa</dc:creator>
      <dc:date>2017-11-20T17:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: RADIUS / AAA question</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59875#M5024</link>
      <description>Ondrej, what do you mean with no roaming? If we use internal AAA on a AP, we can't roam seamless? Each AP change need to reauthenticate?&lt;BR /&gt;
&lt;BR /&gt;
Vedran, for the printing, you can get user and password in cleartext from the config. Just copy and paste it. With this data you can create your own "voucher".</description>
      <pubDate>Mon, 20 Nov 2017 17:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59875#M5024</guid>
      <dc:creator>Timo1</dc:creator>
      <dc:date>2017-11-20T17:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: RADIUS / AAA question</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59876#M5025</link>
      <description>Well, let's tear it down&lt;BR /&gt;
&lt;UL&gt; RADIUS runs locally on every AP = unique RADIUS user pool per AP roaming presumes presence of known authentication = not possible due different RADIUS databases &lt;/UL&gt;If we talk about scenario where the RADIUS user pool is shared (or static) then "roaming" obviously works, but &lt;B&gt;this is not seamless roaming&lt;/B&gt; at all.&lt;BR /&gt;
&lt;BR /&gt;
From RADIUS perspective the MAC address associated with the user account is not known - with RADIUS onboard-self every AP runs own database of account / MAC combinations with accounting on its own. When you roam, you go for re-association based on WNMP but then you hit the edge of EAP authentication and RADIUS server will start to send challenges instead of recognizing the client MAC.&lt;BR /&gt;
&lt;BR /&gt;
In my opinion this is unnecessary mess you can easily avoid by mapping the RADIUS to either RFDM or centralized controller. Moreover, if Vendran wants to use Captive portal, that would bring extra layer of complexity. &lt;BR /&gt;
&lt;BR /&gt;
I'd definitely go for elegant option A and rather use multiple (per-site) user group / user pool.&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
Ondrej</description>
      <pubDate>Mon, 20 Nov 2017 17:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59876#M5025</guid>
      <dc:creator>Ondrej_Lepa</dc:creator>
      <dc:date>2017-11-20T17:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: RADIUS / AAA question</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59877#M5026</link>
      <description>Thanks for the replies. We used onboard-centralized-controller.&lt;BR /&gt;
&lt;BR /&gt;
Regarding vouchers, an A4 paper can easily fit 6, maybe even 8 vouchers per page but the maximum available setting is 4, unfortunately.&lt;BR /&gt;
&lt;BR /&gt;
After creating bulk vouchers, if you did not print them, you won't be able to do it later on... only one by one, which is not very nice when there's thousands of users.&lt;BR /&gt;
&lt;BR /&gt;
In the end, we created a spreadsheet of users and uploaded it in the configured user pool. For printing we used an online label design and print tool which can import the spreadsheet.&lt;BR /&gt;
&lt;BR /&gt;
Best regards.</description>
      <pubDate>Tue, 05 Dec 2017 19:02:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/radius-aaa-question/m-p/59877#M5026</guid>
      <dc:creator>Vedran_Jurak</dc:creator>
      <dc:date>2017-12-05T19:02:00Z</dc:date>
    </item>
  </channel>
</rss>

