ā05-31-2019 12:39 PM
Solved! Go to Solution.
ā08-11-2021 08:31 AM
Hi Tomasz,
Thank you for your reply. I was talking about the EAP-TEAP with a vendor of our Extreme solutions. They contacted Extreme directly and found out that Extreme NAC does not support EAP-TEAP yet. However, itās in their road map so hopefully somedayā¦
Nevertheless, there should be basically two workarounds. The first one is the one youāre describing in your previous post. I can be done either manually or using the workflow you provided.
The second one is to create two rules. First for machine certificate authentication and second one for identity authentication (credentials in AD). For this option you need to set your Windows supplicant for EAP-TEAP authentication, but I was told, that it does not work very well. However, I havenāt tried it myself, so who knows, it may be the way.
Iām not an expert in AD/GPO myself, but I donāt believe that there is a āuser-friendlyā solution. And even if it was, I would like to assign different VLANs to different groups of users, which wouldnāt be possible, right? The NAC would just let the machine to the network, but Iād have to have a user certificate (which I donāt have) to assign a specific VLAN. With machine certificate only, the NAC would know that the machine is from our company, therefore let it in, but wouldnāt know which user uses it, so I canāt create any user group.
Regards,
Jakub
ā06-07-2019 07:50 AM
ā06-03-2019 09:50 AM
ā06-01-2019 05:53 PM