Controllerless Networks

last person joined: yesterday 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

Assing vlan on mac auth failure

This thread has been viewed 1 times
  • 1.  Assing vlan on mac auth failure

    Posted Oct 06, 2016 06:33 AM

    Hi. I just want to assing clients to a specific VLAN if MAC auth fails. I have configured an open network with MAC auth to an external radius server, no captive portal configuration.

     

    Assign users with MAC on my radius server to specfic VLAN is working fine, but I don't achieve assign VLAN to unauthenticated clientes.

     

    Thank you in advance



  • 2.  RE: Assing vlan on mac auth failure

    EMPLOYEE
    Posted Oct 06, 2016 01:50 PM

    Unauthenticated clients should end up in the default VLAN.  Authenticated users should end up in the VLAN that you return from radius.



  • 3.  RE: Assing vlan on mac auth failure

    Posted Oct 07, 2016 03:55 AM

    Hi. Unauthenticated clients are not getting IP because they don't pass level2 validation. What I have done is configure my radius server to give an "accept" to clientes who fails mac validation in order to let them pass to the default VLAN.

     

    Regards



  • 4.  RE: Assing vlan on mac auth failure

    EMPLOYEE
    Posted Oct 07, 2016 06:45 AM

    What is your configuration?



  • 5.  RE: Assing vlan on mac auth failure

    Posted Oct 07, 2016 06:47 AM

    Open Network with MAC authentication enabled. No captive portal.

     

    Regards.



  • 6.  RE: Assing vlan on mac auth failure

    EMPLOYEE
    Posted Oct 07, 2016 06:50 AM

    If you are using mac authentication, users should get the role in the initial role parameter of the AAA profile.  If they fail mac auth, they should stay in that initial role.  What is your question?  What are you trying to do exactly?



  • 7.  RE: Assing vlan on mac auth failure

    Posted Oct 07, 2016 06:53 AM

    First of all It seems that I forget to mention that I'm using Instant Access Point :P... With Aruba Access Point and using an open Wireless Network with mac authentication I can't assing pre-authenticated role.

     

    Regards,



  • 8.  RE: Assing vlan on mac auth failure

    EMPLOYEE
    Posted Oct 07, 2016 07:00 AM

    Allright.  I apologize.

     

    You should manage the failed authentication from your radius server.  Which radius server are you using?



  • 9.  RE: Assing vlan on mac auth failure
    Best Answer

    Posted Oct 07, 2016 07:31 AM

    I'm using freeradius. I configured it to respond with an ok if doesn't find MAC in the database. It the MAC is in database I assing a VLAN based on Aruba-Role stored in freeradius database. It appear to be working fine.

     

    Regards,



  • 10.  RE: Assing vlan on mac auth failure

    EMPLOYEE
    Posted Oct 07, 2016 07:38 AM

    If it is working, please mark this topic solved.  If not, your radius server should reply with the Aruba-User-VLAN attribute to set the correct VLAN.