Creating a NAC VNS Using the VNS Wizard

The ExtremeWireless controller integrates with an Extreme Networks NAC controller to provide authentication, assessment, remediation and access control for mobile users. For more information, see NAC Integration with the Wireless WLAN.

Use the VNS wizard to configure a NAC gateway-compatible VNS by defining the following essential parameters:

  • VNS Name — The name that will be assigned to the VNS and SSID.
  • IP Address — The IP address of the ExtremeWireless controller's interface on the VLAN.
  • Mask — The subnet mask for the IP address to separate the network portion from the host portion of the address.
  • VLAN ID — ID number of the VLAN to which the ExtremeWireless controller is bridged for the VNS.
  • Port — Physical L2 port to which the configured VLAN is attached.
  • RADIUS server — IP address of the NAC controller.
  • Redirection URL — The URL that points to the NAC controller‘s web server.

The VNS wizard creates a Bridge Traffic Locally at EWC VNS. This VNS has the crucial attributes — SSID Network Assignment Type, MAC-based external captive portal authentication and WPA-PSK encryption — that makes it compatible with the NAC controller. The remaining VNS parameters are defined automatically according to best practice standards.

To configure a NAC VNS using the VNS wizard:

  1. From the top menu, click VNS.
  2. In the left pane, click New > START VNS WIZARD.
    Click to expand in new window
    Graphics/VNS_creation_wizard_screen.jpg
  3. In the Name box, type a name for the NAC SSID-based VNS.
  4. In the Category drop-down list, click NAC VNS, and then click Next.
    Click to expand in new window
    Graphics/VNS_wizard_NAC_basic.jpg
    Click to expand in new window

    NAC-compatible VNS Page - Fields and Buttons

    Field/Button Description
    IP Address Type the IP address of the ExtremeWireless Appliance's interface on the VLAN.
    Mask Type the appropriate subnet mask for this IP address to separate the network portion from the host portion of the address (typically 255.255.255.0).
    Interface From the drop-down list, select the physical port that provides the access to the VLAN.
    VLAN ID Type the VLAN tag to which the ExtremeWireless Appliance will be bridged for the VNS.
    NAS From the drop-down list, click the interface/port through which the NAC gateway will communicate with the ExtremeWireless Appliance. The IP address in this field will be used as the NAS IP RADIUS attribute when communicating with the NAC gateway.
    NAC Server
    Server Alias Type the name or IP address of the NAC server.
    Hostname/IP Type the NAC server‘s FQDN (fully qualified domain name) or IP address.
    Shared Secret Type the password that will be used to validate the connection between the ExtremeWireless Appliance and the NAC server.

    To proofread your shared secret key, click Unmask. The password is displayed.

    Note: You should always proofread your Shared Secret key to avoid any problems later when the wireless appliance attempts to communicate with the NAC controller.
    NAC web server IP Type the NAC web server IP address.
  5. To save your changes, click Finish.
    The VNS wizard creates a SSID-based NAC controller-compatible VNS, and displays the configuration summary.
  6. To close the VNS wizard, click Close.
If applicable, you can continue to configure or edit the new VNS by clicking the individual VNS configuration tabs.