cancel
Showing results for 
Search instead for 
Did you mean: 

NAC mappings does not distribute tagged vlans

NAC mappings does not distribute tagged vlans

Bernd_Gruetzke
New Contributor III
Environment:
Extreme Management Center 8.1.5.22
Switches D2, B5, S-Serie, X-440, EOX-Stack
Switches configured with RFC3850, "set policy maptable response both and policy"
"RFC3850 vlan authorization enabled" and "Filter ID With VLAN Tunnel Attribute".

Symtoms:
no tagged vlan will distributed to the required port .

For instance D2:

show port egress
Port Vlan Egress Registration
Number Id Status Status
------------------------------------------------------------
ge.1.1 1 untagged static
ge.1.1 123 untagged etsysPolicyProfile
ge.1.7 1 untagged static
ge.1.7 250 untagged etsysPolicyProfile
ge.1.12 123 tagged static
ge.1.12 196 tagged static
ge.1.12 250 tagged static
8 REPLIES 8

Hi Tomasz and Zdenek,

thanks for your tips. I will check all that again. I only have one question left, is the vlan egress a radius attribute or is it provided by the policy mapping?

Best Bernd

Ronald_Dvorak
Honored Contributor
Is the role set to VLAN egress tagged ?!

Result:
B5(su)->show port egress ge.1.1
Port Vlan Egress Registration
Number Id Status Status
------------------------------------------------------------
ge.1.1 1 untagged static
ge.1.1 100 tagged etsysPolicyProfile
B5(su)->


82b7005ccbac431ea2a43bafbea65b5d_7753d7b8-aac0-4c9f-90f4-c705a3d5ab4a.png

Hello Zdenek,

thanks for your prompt answer. First I set the policy mapping as vlan tagged, only at access control, not at policy.....

057e69de80cc42a3b274189db61dc855_dad8f02d-1092-4724-9f27-9611b454352c.png




Second I create the profile...

057e69de80cc42a3b274189db61dc855_001eb255-621b-4068-bb60-f1f9760bbc53.png



And third I create the rule....

057e69de80cc42a3b274189db61dc855_81e9afa8-1e74-474b-a7f1-cbda2aa74063.png



At this moment I won´t use any Policy Roles, I will use it later if it is necessary. I this the wrong way or should I use already Policy Roles at this point too?

Best Bernd

Zdeněk_Pala
Extreme Employee
I suggest to use policy to define if you want untagged or tagged vlan to be assigned to egress.
set policy profile....
Regards Zdeněk Pala
GTM-P2G8KFN