NAC filter-id: null when doing switch management access
Anonymous
Not applicable
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎12-02-2015 02:31 PM
Currently have NAC configured to proxy network access for computer authentication using eap-tls and also switch management access to FreeRadius.
Computer authorisation is being done by querying host name to a valid entry in LDAP.
Switch authorisation is being done by querying username and password to kerberos.
Each works in the that a radius Accept is being returned to the switch in each case. The problem I have is that NAC is reporting the filter-id as null when doing switch management login.
So my question is, can NAC, just as you can do with a typical profile, change / add the filter id radius attribute to include "Enterasys:mgmt=su" instead of having to configure it somehow in FreeRadius.
Many thanks in advance.
Note: In NAC when editing the switch I have the "Gateway RADIUS Attributes to send = Extreme Policy"
Computer authorisation is being done by querying host name to a valid entry in LDAP.
Switch authorisation is being done by querying username and password to kerberos.
Each works in the that a radius Accept is being returned to the switch in each case. The problem I have is that NAC is reporting the filter-id as null when doing switch management login.
So my question is, can NAC, just as you can do with a typical profile, change / add the filter id radius attribute to include "Enterasys:mgmt=su" instead of having to configure it somehow in FreeRadius.
Many thanks in advance.
Note: In NAC when editing the switch I have the "Gateway RADIUS Attributes to send = Extreme Policy"
2 REPLIES 2
Anonymous
Not applicable
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎12-02-2015 02:47 PM
Excellent, worked a treat. Thanks!
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎12-02-2015 02:41 PM
Yes it can. Please review the following article. In the policy mappings applied for specific users you can add this in. Note the bottom of the last pic (current today) under management attributes.
https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-NAC-for-custom-radius-att...
Below is the default administrator profile that may be able to be used, or for a reference.
https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-configure-NAC-for-custom-radius-att...
Below is the default administrator profile that may be able to be used, or for a reference.
