cancel
Showing results for 
Search instead for 
Did you mean: 

Extreme Control Rule and AD

Extreme Control Rule and AD

Ian_Broadway
New Contributor III

Hi All,

 

I am trying to create Extreme Control rule sets for MAC and .1x authentication.

Is there not a way I can add a group condition to query a LDAP/AD Domain group?

I can see there is an option for LDAP user groups.

 

Also, do Extreme offer some sort of downloadable config for updating DHCP fingerprints.

Its really tedious to have to go in and add lines of code to add custom fingerprints, not to mention having to hunt through a log file to get them in the first place.

 

One other thing, any ideas/thoughts on being able to add if/or conditions into the same rule?

Thanks

Ian

1 ACCEPTED SOLUTION

Miguel-Angel_RO
Valued Contributor II

Stefan,

 

With a script from @Zdenek Pala (https://github.com/extremenetworks/ExtremeScripting/blob/master/Netsight/oneview_workflows/combo/Use... you can mix both authentications to ensure that the user authentication is done on a computer from the domain:

"Add MAC to Domain Computers" is executed when the computer authenticates. The MAC address is added to End-System and the timestamp is created (updated). Consequent User authentication can be combined with the condition of the End-System group. "Clear old End-Systems in the group" checks if the timestamp is older than X hours and old End-Systems are deleted from the group.

 

Mig

View solution in original post

47 REPLIES 47

Stefan_K_
Valued Contributor

Hi Ian,

of course there is! 🙂

3f1449db7f7c46e9b32ac302d0447323_1f4fd0ec-39e6-4e55-8f54-51daff91464c.png

This user group is used in a NAC-Rule to allow the CLI-Access to network switches for the configured AD-Group (which is censored in the screen).

Can of course also used in combination with MAC and Dot1x Auth.

Edit: Dang, much too slow.

Miguel-Angel_RO
Valued Contributor II

Ian,

 

  1. Yes you can create a condition to trigger a rule based on an LDAP group
    1. https://gtacknowledge.extremenetworks.com/articles/How_To/How-To-Match-NAC-LDAP-Lookup-To-Active-Dir...
    2. https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-authorise-Windows-domain-user-compu...
    3. an others articles
  2. I don’t know for the DHCP fingerprint tool
  3. You can add if/or at different levels
    1. In the group definition
      1. bfd4bf0d04b44cc99956f9ac0b8bf186_6b431037-8ac9-4132-a46c-8bf4314bedef.png
      2. in the policy mappings (a Location Group lookup will trigger the return values)

Regards

 

Mig

 

Ian_Broadway
New Contributor III

ok, just read 8.5 release notes, alot more functionality for DHCP fingerprinting.

other concerns still stand though if anyone has any thoughts please.

GTM-P2G8KFN