cancel
Showing results for 
Search instead for 
Did you mean: 

Add IP Range devices to Access Control

Add IP Range devices to Access Control

EF
Contributor III

Hi Team,

when you add a device  to Access control it must exist in Network tab or be created at this moment, and it´s ok for a few devices, but this is a problem when you got a lot of devices and more big problem if they got IP by DHCP, for example XIQ APs.

Is there any way to create an "IP Range" or use regular expressions to create Access Control clients?

If not, I cant understand why is not implemented yet.

Cheers!!

EF

2 ACCEPTED SOLUTIONS

Robert_Haynes
Extreme Employee

You can also add the switches, APs, other devices as Ping Only devices. No SNMP. This will inhibit IP resolution and other SNMP-based exchanges Control would have with SNMP-capable devices. If you opt for this then IP resolution for example will depend on other means like DHCP relay mirroring / snooping or RADIUS Accounting to gleam IP information from the device/network.

View solution in original post

7 REPLIES 7

EF
Contributor III

Hi Team,

thanks for your responses, but Im still think that sometimes is usefull have a range object because is not needed obtain any other info from the client and only want to allow make RADIUS request.

Thanks a lot for share your knowledge.

EF

 

EF
Contributor III

Hi Team,

thx for your response but I´m still cant undertand why EAC need "to talk" by SNMP with devices, I got 3K APs, 500 switches, some of them from others manufactures, FWs, etc...

I only want enable them like EACs clients and then return the right atributes matching policies.

About the scripts to sync APs, How often does it run? I see a problem if one AP obtain a diferent IP from DHCP server and there is a delay of minutes.

Regards

EF

Robert_Haynes
Extreme Employee

You can also add the switches, APs, other devices as Ping Only devices. No SNMP. This will inhibit IP resolution and other SNMP-based exchanges Control would have with SNMP-capable devices. If you opt for this then IP resolution for example will depend on other means like DHCP relay mirroring / snooping or RADIUS Accounting to gleam IP information from the device/network.

Zdeněk_Pala
Extreme Employee

You can also use discovery to add your devices to NAC... that can be scheduled also.

Regards Zdeněk Pala
GTM-P2G8KFN