Deployment Guide

Table Of Contents
Network with Pass-Through External RADIUS
The following procedure outlines how to configure a network and associate it with a Pass-Through
External RADIUS accept policy. The following network types are described:
MBA Network
AAA Network
Related Topics
Configuring an MBA Network on page 83
Configuring a AAA Network on page 84
Configuring an MBA Network
To create the MBA network associated to a Pass-thru External RADIUS accept policy. Take the following
steps:
1. Configure a RADIUS server for AAA authentication.
Log in to Extreme Campus Controller and go to Onboard > AAA > Radius Server and add a new
RADIUS server.
Configure the following parameters:
Radius Server IP Address
Add the NAC IP address
Shared Secret
Provide the NAC Shared Secret.
Note
To find the Shared Secret of the NAC Manager, go to:
Advanced NAC Configuration Settings > Global and Appliance Settings >
Appliance Settings.
2. Create a new network.
Enable MAC-based authentication (MBA) and choose an appropriate MBA Timeout Role.
Clear the Authenticate Locally for MAC check box.
Choose RADIUS as the Authentication Method and select the NAC added in Step 1 as the Primary
RADIUS.
Select a Default VLAN.
Click Save.
3. Add a new rule.
From Extreme Campus Controller, navigate to Onboard > Rules.
Click Add.
In the Location Group drop-down menu, select Network: <name of your network>.
From the Accept Policy field:
To configure a Default Auth Role Policy: select Use Default Auth Role.
Configuring
an External NAC Server for MBA and AAA
Authentication Network with Pass-Through External RADIUS
Extreme Campus Controller Deployment Guide for version 5.46.03 83