Take the following steps to configure the
External NAC server:
Extreme Management Center Console
-
Navigate to ExtremeCloud IQ - Site
Engine OneView
page or launch the console.
-
Add the external NAC server and the ExtremeCloud IQ
Controller esa0 interface as
devices to be managed by ExtremeCloud IQ - Site
Engine.
- Open NAC Manager using either OneView
or the console.
- Add the external NAC server as an
appliance to be managed.
- Go to .
- Select the ExtremeCloud IQ
Controller esa0
interface
- Configure the following
parameters:
- Primary Engine
- NAC server
- RADIUS Attributes to Send
- Edit RADIUS Attribute
Settings
-
To edit the RADIUS Attribute
settings:
- Select Add and provide the
Attribute Group name.
- In the Attribute field, enter the
following:
- Filter-Id=%FILTER_NAME%
- Filter-Id=Enterasys:version=1:%MANAGEMENT%policy=%POLICY_NAME%
- Login-LAT-Port=%LOGIN_LAT_PORT%
- Service-Type=%MGMT_SERV_TYPE%
Note
The Attribute Group is
configured to ensure that
ExtremeWireless APs function with the
appliance.
-
Save the Attribute Group, then select
this group as the option in the RADIUS Attributes to Send field.
-
Press OK.
NAC Manager
-
Go to
-
Select .
-
Add a new user.
Select
Add and configure the
following parameters:
- Display Name
- Username
- Password
-
Select Save.
-
In the Advanced Configuration window,
navigate to .
-
Add a new End-System
Group.
Add a new MAC entry for each MAC address of each client that should be successfully
authenticated.
-
Select Save.
-
In the Advanced Configuration window,
navigate to .
-
Add a new rule.
From the End-System Group drop-down
list, select the
End-System Group that you previously created.
-
In the Profile drop-down list, select Default NAC
Profile.
Note
Assuming no prior configuration
changes have been made to the Default NAC Profile, it will send an
Enterprise
User Filter-ID.
-
Save the rule and move it up the list,
just after the Assessment
Warning rule.
-
Close the Advanced Configuration window
and Enforce the NAC engine.
-
Once the Enforce is successful, close
the window.