<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to configure NAC to send outbound radius attributes for dhcp snooping, bpdu filtering, slpp guard in Network Architecture &amp; Design</title>
    <link>https://community.extremenetworks.com/t5/network-architecture-design/how-to-configure-nac-to-send-outbound-radius-attributes-for-dhcp/m-p/77017#M2606</link>
    <description>&lt;P&gt;What configuratoin is required to setup NAC to send outbound radius attributes for configuring ERS4900 with FA radius attributes like:&lt;/P&gt; &lt;P&gt;dhcp snooping&lt;/P&gt; &lt;P&gt;bpdu filtering&lt;/P&gt; &lt;P&gt;slpp guard&lt;/P&gt; &lt;P&gt;IP-Source Guard&lt;/P&gt; &lt;P&gt;All this should be possible in combination with NAC and ERS 4900.&lt;/P&gt; &lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Tue, 19 May 2020 15:30:43 GMT</pubDate>
    <dc:creator>Sacha_Brys</dc:creator>
    <dc:date>2020-05-19T15:30:43Z</dc:date>
    <item>
      <title>How to configure NAC to send outbound radius attributes for dhcp snooping, bpdu filtering, slpp guard</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/how-to-configure-nac-to-send-outbound-radius-attributes-for-dhcp/m-p/77017#M2606</link>
      <description>&lt;P&gt;What configuratoin is required to setup NAC to send outbound radius attributes for configuring ERS4900 with FA radius attributes like:&lt;/P&gt; &lt;P&gt;dhcp snooping&lt;/P&gt; &lt;P&gt;bpdu filtering&lt;/P&gt; &lt;P&gt;slpp guard&lt;/P&gt; &lt;P&gt;IP-Source Guard&lt;/P&gt; &lt;P&gt;All this should be possible in combination with NAC and ERS 4900.&lt;/P&gt; &lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 15:30:43 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/how-to-configure-nac-to-send-outbound-radius-attributes-for-dhcp/m-p/77017#M2606</guid>
      <dc:creator>Sacha_Brys</dc:creator>
      <dc:date>2020-05-19T15:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure NAC to send outbound radius attributes for dhcp snooping, bpdu filtering, slpp guard</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/how-to-configure-nac-to-send-outbound-radius-attributes-for-dhcp/m-p/77018#M2607</link>
      <description>&lt;P&gt;Hi Sacha,&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Whatever is supported on ERS 4900 as RADIUS attributes (see here: &lt;A href="https://documentation.extremenetworks.com/ERS_Series/ERS49005900/SW/78x/9036215-00_ConfigSecERS49005900_7.8_CG.pdf" target="_blank" rel="nofollow noreferrer noopener"&gt;https://documentation.extremenetworks.com/ERS_Series/ERS49005900/SW/78x/9036215-00_ConfigSecERS49005900_7.8_CG.pdf&lt;/A&gt; and &lt;A href="https://documentation.extremenetworks.com/ERS_Series/ERS49005900/SW/78x/9036216-00_ConfigFabConERS49005900_7.8_CG.pdf" target="_blank" rel="nofollow noreferrer noopener"&gt;https://documentation.extremenetworks.com/ERS_Series/ERS49005900/SW/78x/9036216-00_ConfigFabConERS49005900_7.8_CG.pdf)&lt;/A&gt;, they can be configured under selected Policy Mapping in EAC configuration:&lt;/P&gt;  &lt;P&gt;&lt;A href="https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/l_ov_ia_ht_setup_access_policies.html" target="_blank" rel="nofollow noreferrer noopener"&gt;https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/l_ov_ia_ht_setup_access_policies.html&lt;/A&gt;&lt;/P&gt;  &lt;P&gt;&lt;A href="https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/l_ov_ia_at_man_policy_mapping.html" target="_blank" rel="nofollow noreferrer noopener"&gt;https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/l_ov_ia_at_man_policy_mapping.html&lt;/A&gt;&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;On the other hand, when adding ERS to EAC engine Switches list (authenticators), you have to specify what RADIUS attributes are to be send back if an authenticating end-system is connected to this particular switch:&lt;/P&gt;  &lt;P&gt;&lt;A href="https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/c_ov_ia_at_add_switch_window.html#top" target="_blank" rel="nofollow noreferrer noopener"&gt;https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/c_ov_ia_at_add_switch_window.html#top&lt;/A&gt;&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;For BOSS I see ready sets of RADIUS Attributes, e.g. “Extreme BOSS Fabric Attach”. It looks lke that:&lt;/P&gt;  &lt;BLOCKQUOTE&gt; &lt;P&gt;FA-VLAN-Create=1&lt;BR /&gt; FA-VLAN-ISID=%VLAN_ID%:%CUSTOM1%&lt;BR /&gt; FA-VLAN-PVID=%VLAN_ID%&lt;/P&gt; &lt;/BLOCKQUOTE&gt;  &lt;P&gt;So in the Policy Mapping, VLAN ID should be set and ‘Custom 1’ field shall contain I-SID number.&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;It will work the same for other switches and vendors. If some attribute sets are not there (like you would like to mix few attributes from different sets), you can create a new set on your own. If particular proprietary attributes are not defined (like I saw for WiNG), you can define just %CUSTOM1% and inside a Policy Mapping put entire attribute and value pair.&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;If you need more guidance let us know.&lt;/P&gt;  &lt;P&gt;&amp;nbsp;&lt;/P&gt;  &lt;P&gt;Hope that helps,&lt;/P&gt;  &lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 02:28:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/how-to-configure-nac-to-send-outbound-radius-attributes-for-dhcp/m-p/77018#M2607</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2020-05-21T02:28:23Z</dc:date>
    </item>
  </channel>
</rss>

