Wireless Access

last person joined: 19 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Open SSID with MAC Based Authentication & Radius Authentication

This thread has been viewed 15 times
  • 1.  Open SSID with MAC Based Authentication & Radius Authentication

    Posted Mar 26, 2018 05:18 AM

    Aruba 7010 (software 6.5)

    Open SSID

     

    hi we are trying to configure MAC based authentication and Radius Authentication (with Domain controller) for using active directory username and password. once successfully passed these MAC & AD user authentication only able to get the network /internet access.

     

    Our Query.

     

    1. How can we configure MAC authentication (do we need to add MAC address manually to contoller or is it possible to check from Active directory).

    2. once complete the MAC authenticaation user browser automatically redirect to captive portal, there user need to put active directory username and password for network /internet access.



  • 2.  RE: Open SSID with MAC Based Authentication & Radius Authentication

    EMPLOYEE
    Posted Apr 02, 2018 09:40 AM

    Are you using NPS? If so, I believe the functionality required will be limited. This can be easily accomplished using ClearPass.

     

    Otherwise, you will need to have some backend system with the MAC and/or do some other type of authorization. The flow is definitely possible but will be limited by the backend auth system being used.



  • 3.  RE: Open SSID with MAC Based Authentication & Radius Authentication

    Posted Apr 03, 2018 12:41 PM

    1. you can utilize internal database or use NPS for this (or both :D)

     

    2. You can try these:

    - Create MAC based auth wifi, "initial role" and "802.1x role" set to denyall

    - mac role set to "logon" (or new profile.. )

    - edit logon profile, set to use captive portal (L3) profile.

    - on L3, enable user login (username / password), set user role to "allow-internet-role", set  authentication server to NPS

     

     

    -Yopianus Linga-