Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Server 2008 (R2) and MAC Authentification

This thread has been viewed 0 times
  • 1.  Server 2008 (R2) and MAC Authentification

    Posted Jul 11, 2012 01:54 AM

    Hi again,

     

    I try to configure my server 2008 to do MAC authentification ... I also use this server as logon server with mschap, this works great.

    My question is: can i use my radius server to do mac authentification and logon?

     

    I want to get the MAC-adresses out of my active directory...  is this possible?

     

    Thanks!



  • 2.  RE: Server 2008 (R2) and MAC Authentification

    EMPLOYEE
    Posted Jul 11, 2012 02:27 AM

    Please try this technet article here:  

     

    http://blogs.technet.com/nap/archive/2006/09/08/454705.aspx

     

     

     



  • 3.  RE: Server 2008 (R2) and MAC Authentification

    Posted Jul 11, 2012 02:43 AM

    @cjoseph wrote:

    Please try this technet article here:  

    http://blogs.technet.com/nap/archive/2006/09/08/454705.aspx


    If i klick on this link i get an Outlook Web App- Page ....is that correct?

    I found that link before but i always get this...



  • 4.  RE: Server 2008 (R2) and MAC Authentification

    EMPLOYEE
    Posted Jul 11, 2012 03:12 AM

    I fixed the link.  Not sure why it was doing that...

     



  • 5.  RE: Server 2008 (R2) and MAC Authentification

    Posted Jul 11, 2012 03:16 AM

    @cjoseph wrote:

    I fixed the link.  Not sure why it was doing that...

     


    Sorry but is this the right link? Title is "Certificate Autoenrollment in Windows XP"?!



  • 6.  RE: Server 2008 (R2) and MAC Authentification

    EMPLOYEE
    Posted Jul 11, 2012 03:36 AM

    No.  lets try this one more time:

     

    http://blogs.technet.com/nap/archive/2006/09/08/454705.aspx

     



  • 7.  RE: Server 2008 (R2) and MAC Authentification

    Posted Jul 11, 2012 03:51 AM

    Thanks!

     

    This solution is not the best for our constellation... Is it possible to let the aruba controller check if a mac-adress is in the active-directory and then do the MSCHAP-Logon?

     

    Sorry for the bad english.

     

     



  • 8.  RE: Server 2008 (R2) and MAC Authentification

    EMPLOYEE
    Posted Jul 11, 2012 04:03 AM

    The general answer is yes.  You can create  mac authentication profile and mac authentication server group in the same AAA profile that you do 802.1x

     

    The big question is: do you already have all of these mac addresses stored somewhere?  The issue is adding/deleting and maintaining the mac addresses either as users in Active Directory or Users in the local database on the controller.

     



  • 9.  RE: Server 2008 (R2) and MAC Authentification

    Posted Jul 11, 2012 06:58 AM

    @cjoseph wrote:

     

    The big question is: do you already have all of these mac addresses stored somewhere?  

     


    No.



  • 10.  RE: Server 2008 (R2) and MAC Authentification

    EMPLOYEE
    Posted Jul 11, 2012 07:05 AM

    Okay.  The instructions to configure mac-based authentication is here:  How do I configure MAC-based authentication on Aruba? https://kb.arubanetworks.com/app/answers/detail/a_id/1126

     



  • 11.  RE: Server 2008 (R2) and MAC Authentification

    Posted Jul 11, 2012 07:16 AM

    Thanks for your reply.

     

    This works... i have tested it before ... but now i dont want to save the mac adresses in the internal database but in the active directory.

    Is this possible?



  • 12.  RE: Server 2008 (R2) and MAC Authentification

    EMPLOYEE
    Posted Jul 11, 2012 07:17 AM

    You can configure a user in AD with the username and password being the mac address.  in your AAA profile, the MAC authentication server group will then be your AD radius server.

     



  • 13.  RE: Server 2008 (R2) and MAC Authentification

    Posted Jul 11, 2012 07:20 AM

    I tested that yesterday... reason was:

    the user "00-1C-AB-XX-XX-XX@domain.local" tried to logon at the radius server...is that correct?



  • 14.  RE: Server 2008 (R2) and MAC Authentification
    Best Answer

    EMPLOYEE
    Posted Jul 11, 2012 07:28 AM

    Yes.

     



  • 15.  RE: Server 2008 (R2) and MAC Authentification

    Posted Jul 11, 2012 08:40 AM

    Thanks! It works!

     

    But I have got a problem... if i want to connect to my network i can also do this while typing in the mac-adress as username and password -  not using the correct username.

     

    I hope this is comprehensible for you.



  • 16.  RE: Server 2008 (R2) and MAC Authentification

    Posted Jul 12, 2012 05:50 AM

    ....okay I fixed this by creating a second rule on my radius-server.

     



  • 17.  RE: Server 2008 (R2) and MAC Authentification

    EMPLOYEE
    Posted Jul 12, 2012 06:10 AM

    Very good.  Please mark the thread solved..