<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allowing only one end-system per domain user? in Network Architecture &amp; Design</title>
    <link>https://community.extremenetworks.com/t5/network-architecture-design/allowing-only-one-end-system-per-domain-user/m-p/80775#M2634</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt; &lt;P&gt;Short background info :&lt;/P&gt; &lt;P&gt;On our network, users authenticate for&amp;nbsp;wired and wireless network with&amp;nbsp;802.1X.&lt;BR /&gt; The users and computers&amp;nbsp;are retrieved&amp;nbsp;from our Domain controller.&amp;nbsp;&lt;/P&gt; &lt;P&gt;The AD is the primary radius server linked to&amp;nbsp;2 NAC virtual appliances, which we use&amp;nbsp;for policies/access control.&amp;nbsp;&lt;BR /&gt; Some devices, like copiers, raspberry pies, ..authenticate locally with MAC&lt;/P&gt; &lt;P&gt;Furthermore&lt;/P&gt; &lt;UL&gt;&lt;LI&gt;Mainly X440G2/X450G2&amp;nbsp;switches,&lt;/LI&gt; &lt;LI&gt;Extreme management center appliance,&lt;/LI&gt; &lt;LI&gt;2xC35 wireless controllers an&amp;nbsp;use&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;I have been asked to look into the following :&lt;/P&gt; &lt;P&gt;To reduce&amp;nbsp;the number of devices&amp;nbsp;users can &lt;STRONG&gt;concurrently&lt;/STRONG&gt; use to connect to the network. Ideally, they should get disconnected on their own devices from Wi-Fi when they try to log in on a school owned device..&lt;/P&gt; &lt;P&gt;Is this something that can be done, some way or another..? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt; &lt;P&gt;Thanks&lt;/P&gt; &lt;P&gt;Daniël&lt;/P&gt;</description>
    <pubDate>Thu, 05 Mar 2020 05:43:00 GMT</pubDate>
    <dc:creator>Dani_tH</dc:creator>
    <dc:date>2020-03-05T05:43:00Z</dc:date>
    <item>
      <title>Allowing only one end-system per domain user?</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/allowing-only-one-end-system-per-domain-user/m-p/80775#M2634</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt; &lt;P&gt;Short background info :&lt;/P&gt; &lt;P&gt;On our network, users authenticate for&amp;nbsp;wired and wireless network with&amp;nbsp;802.1X.&lt;BR /&gt; The users and computers&amp;nbsp;are retrieved&amp;nbsp;from our Domain controller.&amp;nbsp;&lt;/P&gt; &lt;P&gt;The AD is the primary radius server linked to&amp;nbsp;2 NAC virtual appliances, which we use&amp;nbsp;for policies/access control.&amp;nbsp;&lt;BR /&gt; Some devices, like copiers, raspberry pies, ..authenticate locally with MAC&lt;/P&gt; &lt;P&gt;Furthermore&lt;/P&gt; &lt;UL&gt;&lt;LI&gt;Mainly X440G2/X450G2&amp;nbsp;switches,&lt;/LI&gt; &lt;LI&gt;Extreme management center appliance,&lt;/LI&gt; &lt;LI&gt;2xC35 wireless controllers an&amp;nbsp;use&lt;/LI&gt; &lt;/UL&gt;&lt;P&gt;I have been asked to look into the following :&lt;/P&gt; &lt;P&gt;To reduce&amp;nbsp;the number of devices&amp;nbsp;users can &lt;STRONG&gt;concurrently&lt;/STRONG&gt; use to connect to the network. Ideally, they should get disconnected on their own devices from Wi-Fi when they try to log in on a school owned device..&lt;/P&gt; &lt;P&gt;Is this something that can be done, some way or another..? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt; &lt;P&gt;Thanks&lt;/P&gt; &lt;P&gt;Daniël&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 05:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/allowing-only-one-end-system-per-domain-user/m-p/80775#M2634</guid>
      <dc:creator>Dani_tH</dc:creator>
      <dc:date>2020-03-05T05:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Allowing only one end-system per domain user?</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/allowing-only-one-end-system-per-domain-user/m-p/80776#M2635</link>
      <description>&lt;P&gt;This is possible and I have POC’d it out at one point some years back, but I needed to use an additional authentication server (FreeRADIUS) and NAC was using proxy-RADIUS to Freeradius and Freeradius authenticated against AD. Freeradius needs some additional configuration to make this work.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2020 13:38:59 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/allowing-only-one-end-system-per-domain-user/m-p/80776#M2635</guid>
      <dc:creator>Matthew_Hum</dc:creator>
      <dc:date>2020-03-21T13:38:59Z</dc:date>
    </item>
  </channel>
</rss>

