09-29-2020 02:52 PM
Hi All,
I am trying to create Extreme Control rule sets for MAC and .1x authentication.
Is there not a way I can add a group condition to query a LDAP/AD Domain group?
I can see there is an option for LDAP user groups.
Also, do Extreme offer some sort of downloadable config for updating DHCP fingerprints.
Its really tedious to have to go in and add lines of code to add custom fingerprints, not to mention having to hunt through a log file to get them in the first place.
One other thing, any ideas/thoughts on being able to add if/or conditions into the same rule?
Thanks
Ian
Solved! Go to Solution.
10-13-2020 08:53 AM
Stefan,
With a script from
"Add MAC to Domain Computers" is executed when the computer authenticates. The MAC address is added to End-System and the timestamp is created (updated). Consequent User authentication can be combined with the condition of the End-System group. "Clear old End-Systems in the group" checks if the timestamp is older than X hours and old End-Systems are deleted from the group.
Mig
10-12-2020 01:51 PM
10-12-2020 01:49 PM
The LDAP config you use for the host
10-12-2020 01:41 PM
Yep using the test function, what config do you want to see?
10-12-2020 01:33 PM
Ian,
Do you test with the test button on the LDAP config screen?
Could you share your config with a screen shot?
Mig
10-12-2020 01:29 PM
ok, so back on topic, as a test, the account used to join the EAC appliances to the domain/used in the ldap configuration was given full domain admin rights.
When testing it still couldnt see the host device return the memberof attribute for the “domain computers” group. it worked for all other member groups as mentioned in an earlier host.
any ideas?