Network Policy and Access Services using MAC address authentication

mavx

Well-Known Member
Joined
Apr 20, 2005
Messages
338
Reaction score
3
Location
Kzn
Hi Guys,

We are busy implementing a wireless solution in conjunction with a IPS device. We have a wireless network setup that we would like to secure using MAC address authentication. I understand that this is possible using RADIUS in Network Policy and Access Services in Server 2008 (Formerly Routing and Remote Access).

At the moment we have got the wireless running, it is handing out IP addresses from the wireless management device using DHCP and we have full internet access, happiness.

So.... I'm hoping that the below makes sense and that anybody can actually come up with some form of tutorials or guidelines they previously used as this seems to be something that isn't often setup.

What we now need to do is lock down that network to only allow specified MAC addresses onto the wireless network. To do this we are going to use the RADIUS authentication on the wireless controller and point that to the Network Access Server (NAS). We will then create a policy that will specify PAP authentication. The NAS needs to be configured to allow a group from Active Directory access using AD users that we specify the username as the MAC address of the NIC's.

If anybody has done this before or has some experience with RADIUS in 2008 please let me know where we are going wrong if we are?
 
Wouldn't it be easier to set the allowed MAC addresses on the AP itself? It looks like you're doing 4 steps to achieve something that could be in 1. Unless you're trying to do something that I am not understanding..
 
Last edited:
Hi hungrbeaver, the wireless AP's (22 of them) are all integrated into one WIFI network with two separate SSID's and the management device caters for a blacklist only as there is no local password repository.
 
Hi hungrbeaver, the wireless AP's (22 of them) are all integrated into one WIFI network with two separate SSID's and the management device caters for a blacklist only as there is no local password repository.

Gee I had a suspicion that there might be more than 1 AP involved here... not 22!! :eek:

I'm out of my league, sorry. You might find some useful info in these links:

http://blog.eddiedelgado.com/?p=28
http://technet.microsoft.com/en-us/network/bb629414.aspx
http://araihan.wordpress.com/2010/0...00-cisco-1142-ap-and-microsoft-radius-server/

Good luck!
 
Thanks Beaver, having a look now. Seems as though MAC authentication is something of a mystery when using NAS...
 
Just an update. It looks like the MAC address authentication will be secondary just to getting RADIUS authentication actually working. From what I can see it looks as though we need to set up 802.1X and use certificates on the client PC's. Once we have it setup, I'll post steps we followed.
 
Top
Sign up to the MyBroadband newsletter
X