cancel
Showing results for 
Search instead for 
Did you mean: 

Fabric Engine and NAC for Per-User-ACL

Fabric Engine and NAC for Per-User-ACL

Antonio_Opromol
Contributor II

Hi,

I've a XIQ-SE latest version ( 22.9.13.5) and a Fabric Engine switch also latest version (8.9).

I've problem with the Radius Attribute Extreme VOSS - Per-User-ACL and auto-sense feature on the access ports.

My configuration follow.

Antonio_Opromol_0-1675084187574.png

 

Antonio_Opromol_1-1675084187581.png

 

 

Client is connected to port 1/24 of this switch that is in auto-sense enable mode:

Antonio_Opromol_2-1675084187581.png

 

 

 The switch has auto-sense parameters configured:

Antonio_Opromol_3-1675084187584.png

 

And radius is configured:

Antonio_Opromol_4-1675084187586.png

 

EAPOL is enabled at global level

Antonio_Opromol_5-1675084187587.png

 

 

When client is connected to this port, the host is correctly authenticated by Radius

Antonio_Opromol_6-1675084187589.png

 

And policy seems to be applied

Antonio_Opromol_7-1675084187590.png

 

Antonio_Opromol_8-1675084187596.png

 

Antonio_Opromol_9-1675084187598.png

 

But I don’t see the VLAN correctly applied to the port but only the auto-sense data vlan.

If now I try to login with a user and dynamically assign vlan id 50 and i-sid 2000050, I see in the switch console:

Antonio_Opromol_10-1675084187600.png

 

So seems that first is correctly authenticated, but immediately un-authenticated and then mac authenticated and in my policy must be assigned in this case vlan id :4 and i-sid: 2000004, as shown in the NAC:

Antonio_Opromol_11-1675084187602.png

 

Antonio_Opromol_12-1675084187604.png

 

But in reality nothing happens on the port of the switch:

Antonio_Opromol_13-1675084187606.png

 

I’ve also tried to enable trace debug of eapol in this port and use a different logon User (Insegnante1) with vlan id: 196 and i-sid: 2000196 (the same as applied from auto-sense data), but also the debug don’t point me in the right direction for solve the problem, I only see authenticated and un-authenticated messages and mac authentication that follow for this client.

 

Instead with Switch engine and proper configurations all works well.

As other test, Iv've tried n VOSS to use flex-uni instead of auo-sense configuration on the port, and in this case the 802.1x authentication works well, the problems are with the FILTER that give the following error when try to change the dynamic-acl-name from the previous one:1.PNG

2.PNG3.PNG4.PNG5.PNG6.PNG7.PNG

So the ACL rules are present on the switch but show me the previous acl name "Unregistered" instead of the ACL name applied to the user that is named "Insegnanti"

Why this happens and how solve?

0 REPLIES 0
GTM-P2G8KFN