Posted on 05-15-2015 12:47 PM
Has anyone been through the process of integrating a JSS with a Extreme Networks NetSight NAC appliance?
Interested in learning from the experience of others. I'm looking to avoid the "Gotchas", learn more about BYOD device registration options, and gain additional insight into the Mac agent support.
Thanks!
-L
Posted on 05-15-2015 01:29 PM
I haven't used this specific product but I used something pretty close to it.
What we did was install SSH keys into a hidden admin account that was only made by Casper. So once then account was made, a hidden ~/.ssh folder was made and inside that hidden folder were the SSH keys. The SSH keys were generated by the NAC appliance and as long as the client had those keys, they were allowed on the network and everything worked fine.
Not sure if that helps you at all but that was my experience.
Posted on 06-26-2015 01:14 PM
and what about iOS devices?
Posted on 11-05-2015 10:59 PM
@lionelgruenberg were you able to get the NetSight JSS integration to work? We are looking at implementing this and I am curious how well it works.
Posted on 11-06-2015 05:29 AM
we have the Extreme guys in all next week to get ours configured. i should have more info for you after we have it running for a week or so.
Posted on 11-11-2015 03:47 AM
We were the first customers of the NetSight/Casper integration, so I should be able to answer any questions you have.
Posted on 11-11-2015 05:55 AM
the extreme guys should show up in an hour or so. any words of wisdom? questions i should ask? pitfalls i should look out for?
Posted on 11-13-2015 03:26 AM
Oops, didn't have email notification on. Anyway, the biggest thing is your devices will only be in one end-system group in Netsight at a time, based on the casperPriority set in the Netsight group. So you'll need to plan your groups and rules accordingly. We try and use Casper groups (smart or static) as the source of truth, because if you manually move an end-system, Netsight won't override your change and move it again.
We tried the assessment portal, triggering on a last update time of greater than 2 weeks, but it's not great for iOS devices. If we want to have an iPad brought in, we just send out a profile that disables Safari which is pretty effective.
The guest portal is pretty good, we're 1:1 not BYOD so it's only used for actual guests, not staff/students registering their devices with their own username/password.
Posted on 12-22-2015 07:44 PM
well after several back and forths with the vender and the engineers. and one remote session with the actual guy who wrote the casper plugin. yesterday the applied an update to netsight and the NAC appliance. it took all day to chomp down the casper database but now everything is working perfectly. we even took it on step further and have netsight forwarding the casper info along to our web filter so users no longer have to authenticate to the filter.