cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 

NAC (ExtremeControl) - Don't see End-Systems Connected on my ERS Switch

NAC (ExtremeControl) - Don't see End-Systems Connected on my ERS Switch

kevin_phi
New Contributor

Hello every one, 

I tried to setup Extreme Control on my XMC in order to see whatā€™s connected on our network.

The NAC appliance has been added to my XMC.

My Switch (ERS4900 Series) has been added in ā€œSwitchesā€ on Access Control Tab. 

There are two IP Phones connected on the port 1 and 2 but I donā€™t see these devices in  ā€œend-systemsā€ on Access Control.

Does someone know what I have to do exactly (procedure?), maybe I missed something in my configuration...

I only need to use Access Control in ā€œlistenā€ mode, no authentication or securityā€¦ only be able to see whatā€™s connnected on my network in a first time.

It would be helpful if someone already have experience(s) about this. 

16 REPLIES 16

Miguel-Angel_RO
Valued Contributor II

Indeed, recheck now the NAC config.

Mig

kevin_phi
New Contributor

Hi, 

Many thanks for your time. 

The host 192.168.201.211 is my NAC appliance and is reachable from my switch 192.168.204.62.

I think I will start from scratch, I did a lot of tests and itā€™s not very clean

Miguel-Angel_RO
Valued Contributor II

Clean it a little bit:

no radius server host 192.168.201.211 used-by eapol acct-enable
no radius server host 192.168.201.211 used-by non-eapol acct-enable timeout 20

no radius dynamic-server client 192.168.204.62

Removing the specific entry on eapol and non-eapol will force it to use the global one

 

Can the switch ping the radius?

Mig

kevin_phi
New Contributor

SW_DUDELANGE#show run module radius

******************************************************************************
        Command Execution Time: 2021-02-23 14:07:04 GMT+01:00    UTC time: 2021-02-23 13:07:04
******************************************************************************
! Embedded ASCII Configuration Generator Script
! Model = Ethernet Routing Switch 4926GTS-PWR+
! Software version = v7.8.1.055
!
! Displaying only parameters different to default
!================================================
enable
configure terminal
!
! *** RADIUS ***
!
radius server host 192.168.201.211 acct-enable
radius server host 192.168.201.211 used-by eapol acct-enable
radius server host 192.168.201.211 used-by non-eapol acct-enable timeout 20
radius accounting interim-updates enable
!
! *** RADIUS Dynamic Server ***
!
radius dynamic-server replay-protection

radius dynamic-server client 192.168.201.211
radius dynamic-server client 192.168.201.211 port 3799
! radius dynamic-server client 192.168.201.211 secret ****************
! radius dynamic-server client 192.168.201.211 enable
radius dynamic-server client 192.168.201.211 process-change-of-auth-requests
radius dynamic-server client 192.168.201.211 process-disconnect-requests
radius dynamic-server client 192.168.201.211 process-reauthentication-requests

radius dynamic-server client 192.168.204.62
radius dynamic-server client 192.168.204.62 port 3799
! radius dynamic-server client 192.168.204.62 secret ****************

Miguel-Angel_RO
Valued Contributor II

Please share the output of the following:

ā€œshow run module radiusā€

Mig

GTM-P2G8KFN