cancel
Showing results for 
Search instead for 
Did you mean: 

NAC&V2110: unable to change from Admin port to esa0 IP

NAC&V2110: unable to change from Admin port to esa0 IP

Ilya_Semenov
Contributor

Hello, team,

I try to follow this article:

https://extremeportal.force.com/ExtrArticleDetail?an=000090139

...and I can't do this:

  • EWC Connection: Change from Admin port IP (192.168.10.1) to esa0 IP

IP-address on esa0 was assigned, but I can't select it here - it's absent and only Admin IP is available. Why?

Many thanks in advance,

Ilya
 

23 REPLIES 23

- For Policy Acceptance - do you mean to read AUP? YOu can disable that.
- the message "you have been denied" - I believe you can go to "look&feel' and "Launch Message string editor" where you can modify/remove all possible messages
- For the auto-login , on wireless controller - VNS - global setting - "client auto-login" , set to "Redirect detection messages to Captive Portal " (the dafault is "Hide" I think). Most of the clients (iOS , Android , MAC , Win10) will show you the pop-up .On some old clients like Win7 and XP you might still need to open the browser
- If the client is "stack" upon authentication , it means something is no working right. As I mentioned earlier - check what role client get - should be "Guest access" or something else (if you configure your rule engine) , but not Unregistered.
For the http:/nac/main - I believe starting from 8.0 (or 8.1?) you don't need to define the full path , just keep the IP address of the appliance itself , it will detect where need to be redirected.

Hello, Yury!

First of all, thank you very much for such detailed response. Unfortunately, at the moment I can't give you all answers cause I am far away from my demo installation and have remote access only.

So, what I can say right now?

My primary task is to change autorization portal from Fortigate's to Extreme NAC's and it's almost done. There are a few interface things which still unclear, but I hope we'll solve them=)

Then, I want to make NAC to make lookups to my LDAP (Active Directory). And it's done.

I can say that two things above work in connection, but not 100% correct.

Details:

After connection to SSID is established, I try to open any website in browser and get to NAC's portal page.

There is a question: https://nac/main - is it correct URL for redirection? Cause I've set exactly this page...

Regardless correct it or not, on a client side I see this (everything below demostrated for wired client, but from a wireless client I see the same):

d494060d2c944e19a51af9737cc39fd9_RackMultipart20180427-94923-1893upl-NacStartPage_inline.jpg



(Black text on foreground is a disgusting thing - I don't know now to remove that)

So, If I input wrong password I get:

d494060d2c944e19a51af9737cc39fd9_RackMultipart20180427-27947-1a0u5nn-wrong_inline.jpg



If I enter correct login/password I get:

d494060d2c944e19a51af9737cc39fd9_RackMultipart20180427-128945-92rpcb-Success_inline.jpg



After I tick "Agree" and click "Complete registration" I get endless "Network Registration in Progress..."

d494060d2c944e19a51af9737cc39fd9_RackMultipart20180427-48970-7bo37q-NetRegProg_inline.jpg



There are my questions:

1) Actually, I want just to give users Internet access after successful login without any "Policy Acceptance" - let they get a page they have requested. How can I get that?

2) How can I remove black text in foreground "You have been denied network access because your device is not currently registered to the network. bla-bla-bla..."?

3) Are there any ways to make NAC's portal page appear automatically without manual browser opening by user? Like in 100% airports and hotels are...?

Many thanks to you, Yury...

I am not sure I got it correctly . WHen you say "NAC customization" is that about the web page customization or access control ? If latter , then I need to know few things .
First - as I understand , you are using your Captive portal BYOD (Authenticated Registration) option which will make a lookup back to your LDAP (Windows AD) . So , when the user enters the credentials (which exists in your AD) , the NAC will be changing policy from "Unregistered" to "Guest Access" (by default , unless you changed it) . YOu need to check couple of things : 1. On the End-Systems page , do you see that the Profile of the user changed to Guest Access ? If not , we would need to stop here and figure out why .If yes , then the next step -2. check on the Wireless Controller (Report page , the one with the client) if the customer get corresponded Role (Guest Access) . If not , then it would mean one of the thing - it is either this Role does no exist on WIreless Controller , or you have an issue with time sync. For the latter please check that both - controller and NAC has exactly the same time - the best point it to the same NTP server. If time is not in-sync , controller refuse the CoA change and role will stay the same.

Yury, it's done. After the upgrade I did exactly as you've said. Now, after connection I open browser and trying to access whatever get to NAC page!!! Thanks a lot!

So, do you have an article about further NAC customization. I enter my AD credentials, they are accepted, but there is still no access for me.

Please, look:

955a515f39a54cbca63478ac2930a961_RackMultipart20180426-81988-1w2h8u2-image1_inline.png



How may I make NAC authorize me?

Many thanks to you, Yury!

You are using 10.01 , this is a GA more the two years old I believe . Please upgrade it to 10.41 . Or 10.31 at least .The feature we are talking about (role based redirect , redirect at AP) was introduced in 10.11.
If it's VM , don't forget to change the disk to "para-virtual" as per release notes.
GTM-P2G8KFN