<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Authentication types on Radius Service Policy in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79318#M7314</link>
    <description>&lt;P&gt;Hello Claudio,&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; I have attached a document that covers Wing and LDAP integration with MS Active Directory. This covers what you are trying to accomplish.&lt;/P&gt;</description>
    <pubDate>Sat, 25 Apr 2020 06:07:48 GMT</pubDate>
    <dc:creator>Christopher_Fra</dc:creator>
    <dc:date>2020-04-25T06:07:48Z</dc:date>
    <item>
      <title>Multiple Authentication types on Radius Service Policy</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79312#M7308</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; I’m new here and I’m preparing to deploy my first network with Extreme Wing wireless.&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; In my enviroment I will have an SSID with 802.1x for corp users and other SSID for guest witch captive portal.&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; I managed to make it work one at&amp;nbsp;a time. I was not able to do both work same time because use of “Radius Service Policy”.&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; I saw that need to configure the Radius Service Policy inside Device Controller or Profile, but only one Radius Service Policy is allowed per profile.&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;The doubt is;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Is it possible configure 802.1x and internal radius for guest user using the same “Radius Service Policy”?&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; What is the best way for this configuration?&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Regards,&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; Claudio Rezende&lt;/P&gt; &lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 05:02:33 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79312#M7308</guid>
      <dc:creator>CRS</dc:creator>
      <dc:date>2020-04-25T05:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Authentication types on Radius Service Policy</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79313#M7309</link>
      <description>&lt;P&gt;Hello Claudio,&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; You are correct, only one radius server policy can be mapped to Wing device via self and/or profile (depending on deployment and usage). That being said, if both Corp and Guest will be using internal radius on Wing for authentication, you can map different user pools, which are mapped to groups, to the one radius policy. The radius server policy “&lt;STRONG&gt;Authentication Type&lt;/STRONG&gt;” should be ALL.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 05:09:24 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79313#M7309</guid>
      <dc:creator>Christopher_Fra</dc:creator>
      <dc:date>2020-04-25T05:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Authentication types on Radius Service Policy</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79314#M7310</link>
      <description>&lt;P&gt;Hi Christopher,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; Both SSID&amp;nbsp;will use internal Radius, Guest with user pools,&amp;nbsp;but Corp will authenticate against Active Directory using LDAP.&amp;nbsp;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; Is it sound ok for you?&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Regards,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 05:14:47 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79314#M7310</guid>
      <dc:creator>CRS</dc:creator>
      <dc:date>2020-04-25T05:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Authentication types on Radius Service Policy</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79315#M7311</link>
      <description>&lt;P&gt;Hello Claudio,&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Absolutely, but you will need to configure the Radius Server Policy/Authentication “Default Source” by adding both SSID’s and source (guest using local and corp using&amp;nbsp;LDAP).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 05:18:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79315#M7311</guid>
      <dc:creator>Christopher_Fra</dc:creator>
      <dc:date>2020-04-25T05:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Authentication types on Radius Service Policy</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79316#M7312</link>
      <description>&lt;P&gt;Hi Christopher, thanks a lot for your help…&amp;nbsp;&amp;nbsp;&lt;/P&gt; &lt;P&gt;I believe that I’m almost there but still not working…&amp;nbsp; look below, where I’m mistaking?&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="30380d10adf74859aa89448bea501cc2_8c8c215b-1241-4b66-a744-75ab0b8ec36b.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5499iEE914F2E0F3B860B/image-size/large?v=v2&amp;amp;px=999" role="button" title="30380d10adf74859aa89448bea501cc2_8c8c215b-1241-4b66-a744-75ab0b8ec36b.jpg" alt="30380d10adf74859aa89448bea501cc2_8c8c215b-1241-4b66-a744-75ab0b8ec36b.jpg" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 05:31:27 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79316#M7312</guid>
      <dc:creator>CRS</dc:creator>
      <dc:date>2020-04-25T05:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Authentication types on Radius Service Policy</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79317#M7313</link>
      <description>&lt;P&gt;Hello Claudio,&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Looks correct. Did you configure the LDAP section (on the radius policy tabs above)? You need to configure LDAP accordingly and ensure that the Wing device is binded with LDAP server.&amp;nbsp;&lt;/P&gt; &lt;P&gt;Once LDAP is configured, from Wing CLI (Command Line Interface), you can verify that Wing is binded with LDAP server using the following commands;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;enable &lt;/STRONG&gt;[enter]&lt;/P&gt; &lt;P&gt;&lt;STRONG&gt;show ldap-agent join-status&lt;/STRONG&gt; [enter]&lt;/P&gt; &lt;P&gt;If running the above and LDAP is not configured and/or not configured properly, you will see the following:&lt;/P&gt; &lt;P&gt;Wing#&lt;STRONG&gt;show ldap-agent join-status&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;Primary LDAP Server's agent join-status : &lt;STRONG&gt;Not Configured or Unused&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;If successful, you should something like the following, then you would need to verify your wireless client for 802.1x:&lt;/P&gt; &lt;P&gt;Wing#&lt;STRONG&gt;show ldap-agent join-status&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;Primary LDAP Server's agent join-status : &lt;STRONG&gt;Joined domain SONIC.&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 05:45:50 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79317#M7313</guid>
      <dc:creator>Christopher_Fra</dc:creator>
      <dc:date>2020-04-25T05:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Authentication types on Radius Service Policy</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79318#M7314</link>
      <description>&lt;P&gt;Hello Claudio,&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; I have attached a document that covers Wing and LDAP integration with MS Active Directory. This covers what you are trying to accomplish.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 06:07:48 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79318#M7314</guid>
      <dc:creator>Christopher_Fra</dc:creator>
      <dc:date>2020-04-25T06:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Authentication types on Radius Service Policy</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79319#M7315</link>
      <description>&lt;P&gt;Hi Christopher,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Thanks a lot again, it is working now.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Windows machine authenticating with AD credentials.&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Mobiles autenticating with guest users.&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;The only think that is still not working, is some Mobile Corporative that need to authenticate in SSID CORP. After change the “Authentication type from MSCHAPv2 to ALL” they stop work.&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Any ideia about it?&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt; &lt;P&gt;Regars,&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt; &lt;P&gt;vx9000-600CCE#show ldap-agent join-status&lt;/P&gt; &lt;P&gt;Primary LDAP Server's agent join-status : Joined domain LAB.&lt;/P&gt; &lt;P&gt;&lt;BR /&gt; Secondary LDAP Server's agent join-status : Not Configured or Unused&lt;BR /&gt; vx9000-600CCE#&lt;BR /&gt; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 06:16:29 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79319#M7315</guid>
      <dc:creator>CRS</dc:creator>
      <dc:date>2020-04-25T06:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Authentication types on Radius Service Policy</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79320#M7316</link>
      <description>&lt;P&gt;Hi Christopher,&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Now all is working fine. Thank you for you time.&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Regards,&lt;/P&gt; &lt;P&gt;Claudio Rezende&lt;/P&gt; &lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 09:31:13 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/multiple-authentication-types-on-radius-service-policy/m-p/79320#M7316</guid>
      <dc:creator>CRS</dc:creator>
      <dc:date>2020-04-25T09:31:13Z</dc:date>
    </item>
  </channel>
</rss>

