<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How I can configurate Radius authentication wtih internal controller Wing in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77523#M7128</link>
    <description>&lt;P&gt;Hi every One&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try to configurate the Radius Authentication But It is not working, I saw the documentation in this link but I am not sure if my configuration it is ok&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is the link:&lt;/P&gt;&lt;P&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000080864" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000080864&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and my configuration is:&amp;nbsp;&lt;/P&gt;&lt;P&gt;aa-policy FabrilPolicy&lt;BR /&gt;&amp;nbsp;authentication server 1 onboard controller&lt;BR /&gt;! &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;wlan VLAN400&lt;BR /&gt;&amp;nbsp;ssid wirelessvlan400&lt;BR /&gt;&amp;nbsp;vlan 400&lt;BR /&gt;&amp;nbsp;bridging-mode tunnel&lt;BR /&gt;&amp;nbsp;encryption-type ccmp&lt;BR /&gt;&amp;nbsp;authentication-type eap&lt;BR /&gt;&amp;nbsp;wpa-wpa2 psk 0 12345678&lt;BR /&gt;&amp;nbsp;wireless-client count-per-radio 200&lt;BR /&gt;&amp;nbsp;use aaa-policy FabrilPolicy&lt;/P&gt;&lt;P&gt;radius-group FabrilTest&lt;BR /&gt;&amp;nbsp;rate-limit from-air 30000&lt;BR /&gt;&amp;nbsp;rate-limit to-air 30000&lt;BR /&gt;&amp;nbsp;policy inactivity-timeout 1800&lt;BR /&gt;! &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;radius-user-pool-policy UserRadius&lt;BR /&gt;&amp;nbsp;user User2 password 0 1234567qwe group FabrilTest&lt;BR /&gt;&amp;nbsp;user Mario password 0 12345678 group FabrilTest&lt;BR /&gt;&amp;nbsp;user User1 password 0 87654321 group FabrilTest&lt;BR /&gt;! &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;radius-server-policy FabrilPolicy&lt;BR /&gt;&amp;nbsp;use radius-user-pool-policy UserRadius&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you help me, what is the problem for my configuration&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Mar 2020 07:33:18 GMT</pubDate>
    <dc:creator>mario123na</dc:creator>
    <dc:date>2020-03-06T07:33:18Z</dc:date>
    <item>
      <title>How I can configurate Radius authentication wtih internal controller Wing</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77523#M7128</link>
      <description>&lt;P&gt;Hi every One&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try to configurate the Radius Authentication But It is not working, I saw the documentation in this link but I am not sure if my configuration it is ok&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is the link:&lt;/P&gt;&lt;P&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000080864" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000080864&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and my configuration is:&amp;nbsp;&lt;/P&gt;&lt;P&gt;aa-policy FabrilPolicy&lt;BR /&gt;&amp;nbsp;authentication server 1 onboard controller&lt;BR /&gt;! &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;wlan VLAN400&lt;BR /&gt;&amp;nbsp;ssid wirelessvlan400&lt;BR /&gt;&amp;nbsp;vlan 400&lt;BR /&gt;&amp;nbsp;bridging-mode tunnel&lt;BR /&gt;&amp;nbsp;encryption-type ccmp&lt;BR /&gt;&amp;nbsp;authentication-type eap&lt;BR /&gt;&amp;nbsp;wpa-wpa2 psk 0 12345678&lt;BR /&gt;&amp;nbsp;wireless-client count-per-radio 200&lt;BR /&gt;&amp;nbsp;use aaa-policy FabrilPolicy&lt;/P&gt;&lt;P&gt;radius-group FabrilTest&lt;BR /&gt;&amp;nbsp;rate-limit from-air 30000&lt;BR /&gt;&amp;nbsp;rate-limit to-air 30000&lt;BR /&gt;&amp;nbsp;policy inactivity-timeout 1800&lt;BR /&gt;! &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;radius-user-pool-policy UserRadius&lt;BR /&gt;&amp;nbsp;user User2 password 0 1234567qwe group FabrilTest&lt;BR /&gt;&amp;nbsp;user Mario password 0 12345678 group FabrilTest&lt;BR /&gt;&amp;nbsp;user User1 password 0 87654321 group FabrilTest&lt;BR /&gt;! &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;radius-server-policy FabrilPolicy&lt;BR /&gt;&amp;nbsp;use radius-user-pool-policy UserRadius&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you help me, what is the problem for my configuration&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 07:33:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77523#M7128</guid>
      <dc:creator>mario123na</dc:creator>
      <dc:date>2020-03-06T07:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: How I can configurate Radius authentication wtih internal controller Wing</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77524#M7129</link>
      <description>&lt;P&gt;Did you map the radius-server policy to the wireless controller at the device level?&amp;nbsp;&lt;/P&gt; &lt;P&gt;From CLI:&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;enable&lt;/STRONG&gt; [enter]&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;self&lt;/STRONG&gt; [enter]&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;use radius-server-policy FabrilPolic&lt;/STRONG&gt;y [enter]&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;end&lt;/STRONG&gt; [enter]&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;commit write&lt;/STRONG&gt; [enter]&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 07:36:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77524#M7129</guid>
      <dc:creator>Christopher_Fra</dc:creator>
      <dc:date>2020-03-06T07:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: How I can configurate Radius authentication wtih internal controller Wing</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77525#M7130</link>
      <description>&lt;P&gt;I try your comment, this is the controller configuration&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;rfs4000 B4-C7-99-FB-82-ED&lt;BR /&gt; &amp;nbsp;use profile default-rfs4000&lt;BR /&gt; &amp;nbsp;use rf-domain TEST&lt;BR /&gt; &amp;nbsp;hostname rfs4000-FB82ED&lt;BR /&gt; &amp;nbsp;license AP DEFAULT-6AP-LICENSE&lt;BR /&gt; &amp;nbsp;license ADSEC DEFAULT-ADV-SEC-LICENSE&lt;BR /&gt; &amp;nbsp;ip domain-name 8.8.4.4&lt;BR /&gt; &amp;nbsp;ip default-gateway 192.168.200.1&lt;BR /&gt; &amp;nbsp;use radius-server-policy FabrilPolicy&lt;BR /&gt; &amp;nbsp;interface up1&lt;BR /&gt; &amp;nbsp; switchport mode trunk&lt;BR /&gt; &amp;nbsp; switchport trunk allowed vlan 1,200,400&lt;BR /&gt; &amp;nbsp; switchport trunk native vlan 1&lt;BR /&gt; &amp;nbsp;interface ge3&lt;BR /&gt; &amp;nbsp; switchport mode access&lt;BR /&gt; &amp;nbsp; switchport access vlan 200&lt;BR /&gt; &amp;nbsp;interface vlan1&lt;BR /&gt; &amp;nbsp; ip address dhcp&lt;BR /&gt; &amp;nbsp; ip address 192.168.0.1/24 secondary&lt;BR /&gt; &amp;nbsp; no ip dhcp client request options all&lt;BR /&gt; &amp;nbsp;interface vlan200&lt;BR /&gt; &amp;nbsp; ip address 192.168.200.50/24&lt;BR /&gt; &amp;nbsp; ip dhcp client request options all&lt;BR /&gt; &amp;nbsp;interface vlan400&lt;BR /&gt; &amp;nbsp; ip address 192.168.4.50/24&lt;BR /&gt; &amp;nbsp;use dhcp-server-policy TEST-DHCP&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;This message send me when I try to connect the wireless vlan400&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="1bb3f4ea7d0743618e5e22af4a8a2cd2_c24497ef-2af0-45de-b030-d3684dba62be.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5706i6B9C7B8C18E9A9B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="1bb3f4ea7d0743618e5e22af4a8a2cd2_c24497ef-2af0-45de-b030-d3684dba62be.png" alt="1bb3f4ea7d0743618e5e22af4a8a2cd2_c24497ef-2af0-45de-b030-d3684dba62be.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 08:32:22 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77525#M7130</guid>
      <dc:creator>mario123na</dc:creator>
      <dc:date>2020-03-06T08:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: How I can configurate Radius authentication wtih internal controller Wing</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77526#M7131</link>
      <description>&lt;P&gt;Have you configured the wireless client supplicant correctly?&lt;/P&gt; &lt;P&gt;What EAP method is the wireless client using?&lt;/P&gt; &lt;P&gt;I assume PEAP/MSCHAPv2 based on user/password.&amp;nbsp;If using certificate, the RFS would need to be staged as such.&amp;nbsp; If no certificate is being used, ensure that “&lt;STRONG&gt;no validate server cert&lt;/STRONG&gt;” on wireless client supplicant is checked.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 00:36:34 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77526#M7131</guid>
      <dc:creator>Christopher_Fra</dc:creator>
      <dc:date>2020-03-07T00:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: How I can configurate Radius authentication wtih internal controller Wing</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77527#M7132</link>
      <description>&lt;P&gt;Hi I try a new configuration&amp;nbsp;&lt;/P&gt; &lt;P&gt;and I see my bad configuration in wireless client but I have a one problem and I do not why&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;my recently configuration is&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;aaa-policy PolicyAAARadius&lt;BR /&gt; &amp;nbsp;authentication server 1 onboard controller&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;wlan VLAN200&lt;BR /&gt; &amp;nbsp;ssid VLAN200&lt;BR /&gt; &amp;nbsp;vlan 200&lt;BR /&gt; &amp;nbsp;bridging-mode tunnel&lt;BR /&gt; &amp;nbsp;encryption-type ccmp&lt;BR /&gt; &amp;nbsp;authentication-type eap&lt;BR /&gt; &amp;nbsp;wpa-wpa2 psk 0 12345678&lt;BR /&gt; &amp;nbsp;wireless-client count-per-radio 80&lt;BR /&gt; &amp;nbsp;use wlan-qos-policy VLAN200QoS&lt;BR /&gt; &amp;nbsp;use aaa-policy PolicyAAARadius&lt;BR /&gt; &amp;nbsp;&lt;/P&gt; &lt;P&gt;radius-group RadiusGroup&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;radius-server-policy ServerpolicyRa&lt;BR /&gt; &amp;nbsp;authentication data-source ldap&amp;nbsp;&lt;BR /&gt; &amp;nbsp;authentication eap-auth-type peap-gtc&lt;BR /&gt; &amp;nbsp;ldap-server primary host 192.168.200.20 port 389 login "(sAMAccountName=%{Stripped-User-Name:-%{User-Name}})" bind-dn "CN=Mario Martinez,CN=Users,DC=abstergo,DC=com" base-dn "CN=Users,DC=abstergo,DC=com" passwd 0 Banco2018 passwd-attr UserPassword group-attr cn group-filter "(|(&amp;amp;(objectClass=group)(member=%{Ldap-UserDn}))(&amp;amp;(objectClass=GroupOfUniqueNames)(uniquemember=%{Ldap-userDn})))" group-membership radiusGroupName net-timeout 10&lt;BR /&gt; &amp;nbsp;use radius-group RadiusGroup&lt;BR /&gt; &amp;nbsp;&lt;/P&gt; &lt;P&gt;profile rfs4000 RFS4000-TEST&lt;BR /&gt; &amp;nbsp;no autoinstall configuration&lt;BR /&gt; &amp;nbsp;no autoinstall firmware&lt;BR /&gt; &amp;nbsp;use radius-server-policy ServerpolicyRa&lt;BR /&gt; …&lt;/P&gt; &lt;P&gt;but always show me this message&lt;/P&gt; &lt;P&gt;Mar 31 16:05:22 2019: %DAEMON-6-INFO: radiusd[2490]: rlm_ldap (ldap_primary): Closing connection (10): Hit idle_timeout, was idle for 303 seconds&lt;BR /&gt; Mar 31 16:05:22 2019: %DAEMON-6-INFO: radiusd[2490]: rlm_ldap (ldap_primary): Closing connection (7): Hit idle_timeout, was idle for 303 seconds&lt;BR /&gt; Mar 31 16:05:22 2019: %DAEMON-6-INFO: radiusd[2490]: rlm_ldap (ldap_primary): Closing connection (9): Hit idle_timeout, was idle for 291 seconds&lt;BR /&gt; Mar 31 16:05:22 2019: %DAEMON-6-INFO: radiusd[2490]: rlm_ldap (ldap_primary): Closing connection (11): Hit idle_timeout, was idle for 291 seconds&lt;BR /&gt; Mar 31 16:05:22 2019: %DAEMON-6-INFO: radiusd[2490]: rlm_ldap (ldap_primary): Closing connection (8): Hit idle_timeout, was idle for 291 seconds&lt;BR /&gt; Mar 31 16:05:22 2019: %DAEMON-6-INFO: radiusd[2490]: rlm_ldap (ldap_primary): Opening additional connection (12), 1 of 32 pending slots used&lt;BR /&gt; Mar 31 16:05:22 2019: %DAEMON-6-INFO: radiusd[2490]: Need 2 more connections to reach min connections (3)&lt;BR /&gt; Mar 31 16:05:22 2019: %DAEMON-6-INFO: radiusd[2490]: rlm_ldap (ldap_primary): Opening additional connection (13), 1 of 31 pending slots used&lt;BR /&gt; Mar 31 16:05:22 2019: %DAEMON-5-NOTICE: radiusd[2490]: (10) auth: found User-Policy = Reject, rejecting user: [nescobar] (from client localhost port 1 cli B4-29-3D-19-1A-B1)&lt;BR /&gt; Mar 31 16:05:22 2019: %DAEMON-5-NOTICE: radiusd[2490]: (10) Login incorrect: [nescobar] (from client localhost port 1 cli B4-29-3D-19-1A-B1)&lt;BR /&gt; Mar 31 16:05:22 2019: ap7632-14E2D5 : %DOT11-5-EAP_FAILED: Client 'B4-29-3D-19-1A-B1' failed 802.1x/EAP authentication on wlan 'VLAN200' radio 'ap7632-14E2D5:R2'&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;I understand that it is due to bad EAP configuration in the wireless client but I already defined it to be PEAP-GTC and it is not working for me&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;this is my wireles client configuration&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="0fe054a8d50c4236b81952afa75153e8_b43dda53-6f0f-4e44-84dc-26b7c11e2961.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1201i8F1130B19B7EA1BD/image-size/large?v=v2&amp;amp;px=999" role="button" title="0fe054a8d50c4236b81952afa75153e8_b43dda53-6f0f-4e44-84dc-26b7c11e2961.png" alt="0fe054a8d50c4236b81952afa75153e8_b43dda53-6f0f-4e44-84dc-26b7c11e2961.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 05:03:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77527#M7132</guid>
      <dc:creator>mario123na</dc:creator>
      <dc:date>2020-03-31T05:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: How I can configurate Radius authentication wtih internal controller Wing</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77528#M7133</link>
      <description>&lt;P&gt;Hello Mario,&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Your configuration shows internal radius to external LDAP user database. I have attached a document that covers LDAP integration using Wing internal radius.&amp;nbsp;&lt;/P&gt; &lt;P&gt;Please ensure that the RFS4 is successfully binded to LDAP (all covered in the attached).&amp;nbsp;&lt;/P&gt; &lt;P&gt;If issues are still persistent and if you have a current/valid support contract, please open a support case for further troubleshooting.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 06:34:15 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-i-can-configurate-radius-authentication-wtih-internal/m-p/77528#M7133</guid>
      <dc:creator>Christopher_Fra</dc:creator>
      <dc:date>2020-03-31T06:34:15Z</dc:date>
    </item>
  </channel>
</rss>

