<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: NAC mappings does not distribute tagged vlans in Network Architecture &amp; Design</title>
    <link>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12671#M75</link>
    <description>I suggest to use policy to define if you want untagged or tagged vlan to be assigned to egress.&lt;BR /&gt;
set policy profile....</description>
    <pubDate>Mon, 10 Dec 2018 01:11:00 GMT</pubDate>
    <dc:creator>Zdeněk_Pala</dc:creator>
    <dc:date>2018-12-10T01:11:00Z</dc:date>
    <item>
      <title>NAC mappings does not distribute tagged vlans</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12670#M74</link>
      <description>Environment:&lt;BR /&gt;
Extreme Management Center 8.1.5.22&lt;BR /&gt;
Switches D2, B5, S-Serie, X-440, EOX-Stack&lt;BR /&gt;
Switches configured with RFC3850, "set policy maptable response both and policy" &lt;BR /&gt;
"RFC3850 vlan authorization enabled" and "Filter ID With VLAN Tunnel Attribute".&lt;BR /&gt;
&lt;BR /&gt;
Symtoms:&lt;BR /&gt;
no tagged vlan will distributed to the required port .&lt;BR /&gt;
&lt;BR /&gt;
For instance D2:&lt;BR /&gt;
&lt;BR /&gt;
show port egress&lt;BR /&gt;
 Port    Vlan   Egress     Registration&lt;BR /&gt;
 Number   Id    Status      Status&lt;BR /&gt;
 ------------------------------------------------------------&lt;BR /&gt;
ge.1.1   1     untagged    static&lt;BR /&gt;
ge.1.1   123    untagged    etsysPolicyProfile&lt;BR /&gt;
ge.1.7   1     untagged    static&lt;BR /&gt;
ge.1.7   250    untagged    etsysPolicyProfile&lt;BR /&gt;
ge.1.12   123    tagged     static&lt;BR /&gt;
ge.1.12   196    tagged     static&lt;BR /&gt;
ge.1.12   250    tagged     static</description>
      <pubDate>Mon, 10 Dec 2018 00:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12670#M74</guid>
      <dc:creator>Bernd_Gruetzke</dc:creator>
      <dc:date>2018-12-10T00:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC mappings does not distribute tagged vlans</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12671#M75</link>
      <description>I suggest to use policy to define if you want untagged or tagged vlan to be assigned to egress.&lt;BR /&gt;
set policy profile....</description>
      <pubDate>Mon, 10 Dec 2018 01:11:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12671#M75</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2018-12-10T01:11:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC mappings does not distribute tagged vlans</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12672#M76</link>
      <description>Is the role set to VLAN egress tagged ?!&lt;BR /&gt;
&lt;BR /&gt;
Result:&lt;BR /&gt;
B5(su)-&amp;gt;show port egress ge.1.1&lt;BR /&gt;
 Port    Vlan   Egress     Registration&lt;BR /&gt;
 Number   Id    Status      Status&lt;BR /&gt;
 ------------------------------------------------------------&lt;BR /&gt;
ge.1.1   1     untagged    static&lt;BR /&gt;
ge.1.1   100    tagged     etsysPolicyProfile&lt;BR /&gt;
B5(su)-&amp;gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="82b7005ccbac431ea2a43bafbea65b5d_7753d7b8-aac0-4c9f-90f4-c705a3d5ab4a.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2708iAD45E2D0E2E038B4/image-size/large?v=v2&amp;amp;px=999" role="button" title="82b7005ccbac431ea2a43bafbea65b5d_7753d7b8-aac0-4c9f-90f4-c705a3d5ab4a.png" alt="82b7005ccbac431ea2a43bafbea65b5d_7753d7b8-aac0-4c9f-90f4-c705a3d5ab4a.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 03:25:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12672#M76</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-12-10T03:25:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC mappings does not distribute tagged vlans</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12673#M77</link>
      <description>Hello Zdenek,&lt;BR /&gt;
&lt;BR /&gt;
thanks for your prompt answer. First I set the policy mapping as vlan tagged, only at access control, not at policy.....&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="057e69de80cc42a3b274189db61dc855_dad8f02d-1092-4724-9f27-9611b454352c.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5233iA478D42C7B8D8644/image-size/large?v=v2&amp;amp;px=999" role="button" title="057e69de80cc42a3b274189db61dc855_dad8f02d-1092-4724-9f27-9611b454352c.png" alt="057e69de80cc42a3b274189db61dc855_dad8f02d-1092-4724-9f27-9611b454352c.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
Second I create the profile...&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="057e69de80cc42a3b274189db61dc855_001eb255-621b-4068-bb60-f1f9760bbc53.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3782iF8CF8AFDE2E9B9A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="057e69de80cc42a3b274189db61dc855_001eb255-621b-4068-bb60-f1f9760bbc53.png" alt="057e69de80cc42a3b274189db61dc855_001eb255-621b-4068-bb60-f1f9760bbc53.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
And third I create the rule....&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="057e69de80cc42a3b274189db61dc855_81e9afa8-1e74-474b-a7f1-cbda2aa74063.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3913i0D1EDB8FB37C756F/image-size/large?v=v2&amp;amp;px=999" role="button" title="057e69de80cc42a3b274189db61dc855_81e9afa8-1e74-474b-a7f1-cbda2aa74063.png" alt="057e69de80cc42a3b274189db61dc855_81e9afa8-1e74-474b-a7f1-cbda2aa74063.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
At this moment I won´t use any &lt;B&gt;Policy Roles,&lt;/B&gt; I will use it later if it is  necessary. I this the wrong way or should I use already Policy Roles at this point too?&lt;BR /&gt;
&lt;BR /&gt;
Best Bernd</description>
      <pubDate>Mon, 10 Dec 2018 15:11:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12673#M77</guid>
      <dc:creator>Bernd_Gruetzke</dc:creator>
      <dc:date>2018-12-10T15:11:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC mappings does not distribute tagged vlans</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12674#M78</link>
      <description>Hi Bernd,&lt;BR /&gt;
&lt;BR /&gt;
There are two approaches how to get along with VLANs upon authentication. One is to configure default role VLAN or entire VLAN Egress list for a role, second is to use RFC 3580. The former needs just policy (role) name within policy mappings, the latter needs just VLAN ID within policy mappings (yes, you can combine both depending on switch vendor/capabilities you have).&lt;BR /&gt;
&lt;BR /&gt;
If you plan to use RFC 3580 apart from Policy feature, policy mapping approach should also be alright (but just for a single VLAN, not an entire list if you want e.g. to prepare authenticated AP to serve its clients - this is feasible with role's VLAN Egress list). However, make sure that your switch is added to NAC Appliance with correct "RADIUS attributes to send" option (legacy GUI here but take a look: https://emc.extremenetworks.com/content/nachelp/docs/nac_at_edit_switch.html).&lt;BR /&gt;
If it is set to RFC 3850 or some combination of RFC 3580 and else, you can easily confirm with tcpdump on NAC appliance that relevant RADIUS attributes are sent to the switch and if there are those three Tunnel attributes but it's still not working, I would go back to look at the switch config.&lt;BR /&gt;
&lt;BR /&gt;
Hope that helps,&lt;BR /&gt;
Tomasz</description>
      <pubDate>Tue, 11 Dec 2018 05:20:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12674#M78</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2018-12-11T05:20:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC mappings does not distribute tagged vlans</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12675#M79</link>
      <description>Hi Bernd.&lt;BR /&gt;
For D2 I would go with policy approach = more flexible.</description>
      <pubDate>Fri, 14 Dec 2018 16:13:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12675#M79</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2018-12-14T16:13:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC mappings does not distribute tagged vlans</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12676#M80</link>
      <description>Hi Tomasz and Zdenek,&lt;BR /&gt;
&lt;BR /&gt;
thanks for your tips. I will check all that again. I only have one question left, is the vlan egress a radius attribute or is it provided by the policy mapping?&lt;BR /&gt;
&lt;BR /&gt;
Best Bernd</description>
      <pubDate>Fri, 14 Dec 2018 21:07:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12676#M80</guid>
      <dc:creator>Bernd_Gruetzke</dc:creator>
      <dc:date>2018-12-14T21:07:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC mappings does not distribute tagged vlans</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12677#M81</link>
      <description>the screenshot from Roland = it is policy configuration = you need to enforce and you have it in the switch config. in radius you just reply with policy assignment.&lt;BR /&gt;
&lt;BR /&gt;
The screenshot from you (Bernd) with vlan 123 mdcvoip is radius attribute.</description>
      <pubDate>Fri, 14 Dec 2018 22:02:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12677#M81</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2018-12-14T22:02:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC mappings does not distribute tagged vlans</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12678#M82</link>
      <description>Hi Zdenek, Ronald and Tomasz,&lt;BR /&gt;
&lt;BR /&gt;
I have now tried everything, without result and have now rolled out the policy planned for later and everything goes well.&lt;BR /&gt;
Thanks again for your help and I wish you a merry christmas.&lt;BR /&gt;
&lt;BR /&gt;
Best Bernd</description>
      <pubDate>Wed, 19 Dec 2018 18:47:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/nac-mappings-does-not-distribute-tagged-vlans/m-p/12678#M82</guid>
      <dc:creator>Bernd_Gruetzke</dc:creator>
      <dc:date>2018-12-19T18:47:00Z</dc:date>
    </item>
  </channel>
</rss>

