09-29-2020 02:52 PM
Hi All,
I am trying to create Extreme Control rule sets for MAC and .1x authentication.
Is there not a way I can add a group condition to query a LDAP/AD Domain group?
I can see there is an option for LDAP user groups.
Also, do Extreme offer some sort of downloadable config for updating DHCP fingerprints.
Its really tedious to have to go in and add lines of code to add custom fingerprints, not to mention having to hunt through a log file to get them in the first place.
One other thing, any ideas/thoughts on being able to add if/or conditions into the same rule?
Thanks
Ian
Solved! Go to Solution.
10-13-2020 08:53 AM
Stefan,
With a script from
"Add MAC to Domain Computers" is executed when the computer authenticates. The MAC address is added to End-System and the timestamp is created (updated). Consequent User authentication can be combined with the condition of the End-System group. "Clear old End-Systems in the group" checks if the timestamp is older than X hours and old End-Systems are deleted from the group.
Mig
02-04-2021 07:02 PM
Hi Miguel,
we are not onsite anymore + have no Remote Access. Will be onsite tomorrow morning again.
We made several test, also with the Eval-Tool.
I´m not 100% sure, but almost, that there is NO issue shown with this configuration using the Eval Tool.
I tend to an existing client/windows issue, but i have no idea why + where.
I will check eval-tool tomorrow again.
BR
02-04-2021 06:59 PM
Did you join the AD with the control engine / nac gateway?
I think so - We followed the guides + all test-Scenarios (search within AD) were successfull.
However the Test with Client failed.
What we are wondereing about, too, is the fact, that Control shows the machine-name “host/whatever.domain.de” NOT under “Hostname” but under “Username”.
02-04-2021 06:01 PM
Hi SDR,
Could you share some screenshots from the config evaluation tool?
Usually you can get a lot of answers from there.
Mig
02-04-2021 05:13 PM
Did you join the AD with the control engine / nac gateway?
02-04-2021 04:57 PM
Hi Peter,
thank you.
We started with Host-authentication, which fails with
Auth-Type 802.1x (PEAP)
Reason: Rejected NTLM authentication
Can you assist with this, too? NAC issue or windows/nic configuration issue (however, we followed all available guides) 😞