Netlogin MAC-based auth problems
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
05-26-2017 04:16 PM
Hello, everybody,
I've got a recommendation from Extreme's empoloyee (he is really expert!) to configure netlogin mac-based auth. (I need it to bring more data like Device Type and Operationg System from identity-management on Summits to Netsight. NAC is also involved).
He said:
"For MAC-auth your users does not need to enter anything at all – they just connecting to the network as usual and NAC automatically does the mac-auth (for visibility purpose only) . When you add “switch” into the NAC switch database , you can select “no attribute to send back” , in this case MAC-auth happens but no policy will be applied to the port , so clients connected as usual but NAC knows everything about the client and provide this details in NMS screens/reports."
How can I configure that "MAC-auth for visibility purpose only"? I've tried to do so many times and every time switch just blocks a port when I attach any device...
Please, help! Does somebody understand how exactly should I do configure mac-based netlogin auth on summit taking into the consideration the recommendation above?
Many thanks in advance,
Ilya
I've got a recommendation from Extreme's empoloyee (he is really expert!) to configure netlogin mac-based auth. (I need it to bring more data like Device Type and Operationg System from identity-management on Summits to Netsight. NAC is also involved).
He said:
"For MAC-auth your users does not need to enter anything at all – they just connecting to the network as usual and NAC automatically does the mac-auth (for visibility purpose only) . When you add “switch” into the NAC switch database , you can select “no attribute to send back” , in this case MAC-auth happens but no policy will be applied to the port , so clients connected as usual but NAC knows everything about the client and provide this details in NMS screens/reports."
How can I configure that "MAC-auth for visibility purpose only"? I've tried to do so many times and every time switch just blocks a port when I attach any device...
Please, help! Does somebody understand how exactly should I do configure mac-based netlogin auth on summit taking into the consideration the recommendation above?
Many thanks in advance,
Ilya
16 REPLIES 16
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
05-26-2017 06:46 PM
Hello, Jeremy,
I have not such commands in 16.1.2.14 on X430:
X430-48t.10 # configure netlogin port 17 ?
allow Allow traffic, even when not authenticated
mode Configure port operation mode
no-restart Do not restart the port when all clients unauthenticate
restart Restart the port when all clients unauthenticate
* X430-48t.10 # configure netlogin port 17
Is this an equal - configure netlogin port 17 allow egress-traffic all_cast ?
I have not such commands in 16.1.2.14 on X430:
X430-48t.10 # configure netlogin port 17 ?
allow Allow traffic, even when not authenticated
mode Configure port operation mode
no-restart Do not restart the port when all clients unauthenticate
restart Restart the port when all clients unauthenticate
* X430-48t.10 # configure netlogin port 17
Is this an equal - configure netlogin port 17 allow egress-traffic all_cast ?
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
05-26-2017 06:46 PM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
05-26-2017 06:46 PM
can you run show netlogin session port... The command is similar to that but will show the status of the device.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
05-26-2017 06:46 PM
Thanks, Jeremy...
I think "configure netlogin port 1:36 authentication mode optional" isn't enough... Should it be some more configuration strings? I think, it must.
I think "configure netlogin port 1:36 authentication mode optional" isn't enough... Should it be some more configuration strings? I think, it must.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
05-26-2017 05:21 PM
Please post your current switch configuration.
