cancel
Showing results for 
Search instead for 
Did you mean: 

How to configure NAC to send outbound radius attributes for dhcp snooping, bpdu filtering, slpp guard

How to configure NAC to send outbound radius attributes for dhcp snooping, bpdu filtering, slpp guard

Sacha_Brys
Contributor

What configuratoin is required to setup NAC to send outbound radius attributes for configuring ERS4900 with FA radius attributes like:

dhcp snooping

bpdu filtering

slpp guard

IP-Source Guard

All this should be possible in combination with NAC and ERS 4900.

Thanks in advance

1 ACCEPTED SOLUTION

Tomasz
Valued Contributor II

Hi Sacha,

 

Whatever is supported on ERS 4900 as RADIUS attributes (see here: https://documentation.extremenetworks.com/ERS_Series/ERS49005900/SW/78x/9036215-00_ConfigSecERS49005... and https://documentation.extremenetworks.com/ERS_Series/ERS49005900/SW/78x/9036216-00_ConfigFabConERS49..., they can be configured under selected Policy Mapping in EAC configuration:

https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/l_ov_ia_ht_setup_ac...

https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/l_ov_ia_at_man_poli...

 

On the other hand, when adding ERS to EAC engine Switches list (authenticators), you have to specify what RADIUS attributes are to be send back if an authenticating end-system is connected to this particular switch:

https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/c_ov_ia_at_add_swit...

 

For BOSS I see ready sets of RADIUS Attributes, e.g. “Extreme BOSS Fabric Attach”. It looks lke that:

FA-VLAN-Create=1
FA-VLAN-ISID=%VLAN_ID%:%CUSTOM1%
FA-VLAN-PVID=%VLAN_ID%

So in the Policy Mapping, VLAN ID should be set and ‘Custom 1’ field shall contain I-SID number.

 

It will work the same for other switches and vendors. If some attribute sets are not there (like you would like to mix few attributes from different sets), you can create a new set on your own. If particular proprietary attributes are not defined (like I saw for WiNG), you can define just %CUSTOM1% and inside a Policy Mapping put entire attribute and value pair.

 

If you need more guidance let us know.

 

Hope that helps,

Tomasz

View solution in original post

1 REPLY 1

Tomasz
Valued Contributor II

Hi Sacha,

 

Whatever is supported on ERS 4900 as RADIUS attributes (see here: https://documentation.extremenetworks.com/ERS_Series/ERS49005900/SW/78x/9036215-00_ConfigSecERS49005... and https://documentation.extremenetworks.com/ERS_Series/ERS49005900/SW/78x/9036216-00_ConfigFabConERS49..., they can be configured under selected Policy Mapping in EAC configuration:

https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/l_ov_ia_ht_setup_ac...

https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/l_ov_ia_at_man_poli...

 

On the other hand, when adding ERS to EAC engine Switches list (authenticators), you have to specify what RADIUS attributes are to be send back if an authenticating end-system is connected to this particular switch:

https://emc.extremenetworks.com/content/oneview/docs/control/access_control/docs/c_ov_ia_at_add_swit...

 

For BOSS I see ready sets of RADIUS Attributes, e.g. “Extreme BOSS Fabric Attach”. It looks lke that:

FA-VLAN-Create=1
FA-VLAN-ISID=%VLAN_ID%:%CUSTOM1%
FA-VLAN-PVID=%VLAN_ID%

So in the Policy Mapping, VLAN ID should be set and ‘Custom 1’ field shall contain I-SID number.

 

It will work the same for other switches and vendors. If some attribute sets are not there (like you would like to mix few attributes from different sets), you can create a new set on your own. If particular proprietary attributes are not defined (like I saw for WiNG), you can define just %CUSTOM1% and inside a Policy Mapping put entire attribute and value pair.

 

If you need more guidance let us know.

 

Hope that helps,

Tomasz

GTM-P2G8KFN