03-19-2025 06:10 AM
Hi all.
i have configured ldap domain checking in extreme control following this article https://extreme-networks.my.site.com/ExtrArticleDetail?an=000080814 . my goal is to let the domain-joined laptop and quarantine the non-domain-joined laptop.
My problem is when i plug a laptop that is non-domain joined the host name is showing in extreme control, but when i plug the domain joined laptop the host name is not showing.
With this problem, NAC can't check LDAP for the hostname.
Any help will be appreciated.
05-04-2025 09:07 PM
It seems your Extreme Control setup isn't detecting hostnames for domain-joined laptops, preventing LDAP checks. Ensure proper DNS and DHCP registration, verify Kerberos snooping, and consider using dNSHostName as the LDAP search attribute. Checking Extreme Control logs may also reveal insights.
03-20-2025 05:10 AM
Hostname resolution depends on IP resolution or information gleamed from DHCP. After IP resolution would be reliance on DNS, DHCP and/or Kerberos snooping to be able to resolve/acquire the hostname. Those would be the starting points. There are articles in our KB repository on how to troubleshoot IP Resolution / Hostname resolution concerns.