Security

 View Only
Expand all | Collapse all

Can MAB (Mac-Auth) using WIFI

This thread has been viewed 134 times
  • 1.  Can MAB (Mac-Auth) using WIFI

    Posted May 16, 2025 12:08 PM

    Can MAB in Clearpass can be done if the endpoint using WIFI connectivity? 
    I don't see any document from Aruba for this.

    I have tried configured new services that use MAC_AUTH but it won't work as expected. 



  • 2.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 30 days ago

    If you mean, using MAC Authentication for Wireless Infrastructure, you need to setup your SSID to do MAC-Auth and then configure the service on Clearpass to perform MAC-AUTH (for Authentication under Authentication Methods, use Allow All MAC AUTH option). 
    However, with the current Random MAC on most mobile devices, are you sure you want to use MAB for WIFI connectivity?



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 3.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 30 days ago

    Yes, we want to setup for TV display, Camera & Printer via WIFI. 
    So technically it can be done, not only via LAN (network cable)

    I did configure the MAC_AUTH services but this error hit me and REJECT.

    Alerts for this Request :
    RADIUS Cannot select appropriate authentication method




  • 4.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 30 days ago

    What is the authentication source you're using? 



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 5.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 30 days ago
    Edited by airhead_tem 30 days ago

    Service Type : MAC Authentication

    Authentication Method : MAC_AUTH
    Authentication Source : Static Host List 

    I have register inside static host list my test laptop MAC Address using this format XX-XX-XX-XX-XX-XX




  • 6.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 30 days ago

    can you check on the Access Tracker, on the Event and then post the Input of that request?



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 7.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 29 days ago

    Here is a quick write up on this topic 

    Using Static Host List with ClearPass



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 8.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 29 days ago
    Edited by airhead_tem 29 days ago

    This is what my services, and it won't work and pickup the services. 

    Alert




  • 9.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 29 days ago

    Can you send the Input from the Request Details so we can compare your Service triggering requirements with the Input and check what is missing?



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 10.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 29 days ago
    Edited by airhead_tem 29 days ago

    Is this you're referring




  • 11.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 29 days ago

    I think the service-type is not matching your service,



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 12.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 29 days ago
    Edited by shpat 29 days ago

    So, from your print screens:

    NAD-IP-Address - Belongs_to_Group_ PLI-LVL26

    Request is Coming from PLI-LVL23

    So your access tracker request shows that is coming with AP-Group is PLI-LVL23 and your service says Belongs to Group PLI-LVL26 (That is one which i noticed) 



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 13.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 29 days ago

    Also, after you solve service Triggering, this can be an issue.

    Your static host list has MAC Address in the format of XX-XX-XX-XX-XX-XX 

    If you make Rule Mapping and Enforcement policies based on the User-names, the username you are receiving is in format xxxxxxxxxxxx based on your Access Tracker input



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 14.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    Urmm...that interesting, I don't have any PLI-LVL23 in the Device Group.

    However, I check access tracker, on my working EAP-TLS connection, the Radius Request come from the same PLI-LVL23. 





  • 15.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    Check the RADIUS configuration on controller. Do you send service type of FRAMED-USER instead of LOGIN-USER? If so, then you need to change service definition to use FRAMED-USER (2) instead of LOGIN-USER(1) or reconfigure RADIUS server on controller.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 16.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    I'm using Aruba Central as a controller.
    I've checked the place where the SSID profile was created, there is no such option for frame.




  • 17.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    The your best bet is to change the service type in Clearpass from LOGIN-USER to FRAMED-USER and it should.work.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 18.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    Ok i got already where the PLI-LVL23 come from. It was from the VC of the Access Point. 




  • 19.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    So modify your service Trigger parameters to Match precisely the name (keep in mind it is Case Sensitive).
    Then the service should be triggered correctly.



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 20.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago
    Edited by airhead_tem 28 days ago

    I have changes this following the recommendation.





  • 21.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    You didnt match radius request. NAD-IP-ADDRESS nedd to be address or group. Add PLI-LVL23 ip address into ap group in clearpass and use belongs-to-group condition.



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 22.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    For Aruba Instant You will find these settings in RADIUS server setting.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 23.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    Also you need to use ALL MAC AUTH instead of MAC AUTH.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 24.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    You should leave service type 10 and just change 1 to 2. 

    You can very easily check why your service didnt match. Just compare access tracker radius request with service definition. Also mac auth amethod will only authenticate mac known mac addresses.Status Known in endpoint database. To authenticate all mac addresses use all mac auth.



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 25.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago
    Edited by airhead_tem 28 days ago

    Ok promising, now it detected the services but got reject. 

    It prompt username /password - I key in both version of MAC add 




  • 26.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    I can't find which service didn't match. 

    NAS-port-type = 19

    service type = 2

    SSID = Tower3-MAC
    AP Group = PLI-LVL23





  • 27.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    Confirm AP Device is in the Device Groups in ClearPass. 




  • 28.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    For this, you need to go to Authentication Methods and choose All MAC AUTH . From your previous print Screens it was just [MAC AUTH]



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 29.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    Authentication Method = [Allow All MAC Auth]

    The AP Group was in the Device Group = PLILVL23




  • 30.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    You will need to check your WiFi configuration as it seems it is not configured for MAC auth. 

    Also check other settings for MAC Auth.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 31.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago
    Edited by airhead_tem 28 days ago

    Here is the option on my end.
    There is no specific MAC authentication but here as below

    I need to test this tomorrow. 




  • 32.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    If you want to have mac authentication, you need to enable it. It won't work in your current setup.

    Also using static mac list is very unflexible. It's better to use Guest Device Repository as you can manage it from Guest module and also assign specific role to each device.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 33.  RE: Can MAB (Mac-Auth) using WIFI

    Posted 28 days ago

    This option you highlighted is a specific MAC authentication option when you have 802.1x SSID. In my case I just show option for PSK type (personal) SSID. You need to enable it for MAC Auth to work.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 34.  RE: Can MAB (Mac-Auth) using WIFI
    Best Answer

    Posted 11 days ago

    Ok thanks you all for the contribution.

    I manage to resolve this.
    In the Aruba Central, I need to make sure the SSID profile security is NOT set as Enterprise, it can be Personal or Open. 
    On this option, MAC Auth is visible.