cancel
Showing results for 
Search instead for 
Did you mean: 

XIQ - How can I enable wired 802.1x port authentication

XIQ - How can I enable wired 802.1x port authentication

StephanH
Valued Contributor III

Hello,

how can I enable wired 802.1x authentication for an XIQ AP so that the AP authenticate on a switch port?

Regards Stephan
1 ACCEPTED SOLUTION

reinhardg
Contributor II

Hello Stephan,

yes, with the GUI of XIQ it is not possible to configure 802.1x.

With the CLI PEAP is the default. MD5, TLS and TTLS is also possible, i.e.: supplicant name_of_supplicant eap-type md5 (https://docs.aerohive.com/330000/docs/help/english/ng/Content/reference/docs/cli-reference-guides.ht...)

I’ve requested an according FR at my sales engineer some months ago, but didn’t get an answer, yet.

Our production env is still under HM Classic. We are testing XIQ so that we can decide whether to migrate or replace all that stuff with HW of a vendor that has better support (or should I say: Support at all?)

View solution in original post

18 REPLIES 18

StephanH
Valued Contributor III

Hello  Sam,

I will open a request. 

I think @CWurm has the same need maybe he can open a feature request, too.

 

 

 

 

Regards Stephan

SamPirok
Community Manager Community Manager
Community Manager

Thank you for jumping in here Reinhard, I can confirm that we are limited to MAC authentication in this scenario. 

@reinhardg, could you please forward me the email chain where you brought up your feature request? I’ll find you a different contact so we can get you a response, it’s unacceptable that you didn’t hear anything back. 

@StephanH , in addition to Reinhard’s feature request, the more requests we get for a certain feature, the more of a priority we can make it. I would encourage you to also submit a feature request for this so our engineers can see the demand for that functionality. 

reinhardg
Contributor II

Hello Stephan,

yes, with the GUI of XIQ it is not possible to configure 802.1x.

With the CLI PEAP is the default. MD5, TLS and TTLS is also possible, i.e.: supplicant name_of_supplicant eap-type md5 (https://docs.aerohive.com/330000/docs/help/english/ng/Content/reference/docs/cli-reference-guides.ht...)

I’ve requested an according FR at my sales engineer some months ago, but didn’t get an answer, yet.

Our production env is still under HM Classic. We are testing XIQ so that we can decide whether to migrate or replace all that stuff with HW of a vendor that has better support (or should I say: Support at all?)

StephanH
Valued Contributor III

Reinhard,

are you still using 802.1x with PEAP and XIQ APs?

Regards Stephan

StephanH
Valued Contributor III

Hello Reinhard,

thank you for the hint. There is lot of text in the mentioned topic.

What I can read is:

  1. There is no possibility to confige the authentication in the GUI
  2. It is (was) possible to configure 802.1x via CLI but it seems only PEAP (but not supported because of CLI)
  3. Maybe there is a FR but I can’t see if there is really one

NAC (Extreme Control) is the key differentiator between Extreme and other vendors.  And MAC authentication is not really secure. I can't believe that this feature (802.1x) is not supported.

Regards Stephan
GTM-P2G8KFN