<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Mac address based authentication with TACACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383871#M418888</link>
    <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there is a change in RADIUS to authenticate a user using his mac-address. Is it possible with TACACS?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 23:50:45 GMT</pubDate>
    <dc:creator>fgasimzade</dc:creator>
    <dc:date>2019-03-10T23:50:45Z</dc:date>
    <item>
      <title>Mac address based authentication with TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383871#M418888</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there is a change in RADIUS to authenticate a user using his mac-address. Is it possible with TACACS?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383871#M418888</guid>
      <dc:creator>fgasimzade</dc:creator>
      <dc:date>2019-03-10T23:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Mac address based authentication with TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383872#M418890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="text"&gt;The &lt;SPAN class="b0"&gt;MAC Address&lt;/SPAN&gt; &lt;SPAN class="b0"&gt;authentication&lt;/SPAN&gt; works only in an EAP Protocol environment, TACACS does not support EAP. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an old discussion about the above statement:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://learningnetwork.cisco.com/message/8820"&gt;https://learningnetwork.cisco.com/message/8820&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 16:39:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383872#M418890</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-12-14T16:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: Mac address based authentication with TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383873#M418893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your answer and the link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everyone says EAP is not supported in TACACS, but there is EAP configuration in TACACS, especially PEAP, LEAP and etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 18:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383873#M418893</guid>
      <dc:creator>fgasimzade</dc:creator>
      <dc:date>2009-12-14T18:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Mac address based authentication with TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383874#M418895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;EAP for TACACS? Do you see it in ACS? Could you instruct us where that is?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 18:46:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383874#M418895</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-12-14T18:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Mac address based authentication with TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383875#M418897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure. Go to System Configuration, and then to Global Authentication Setup, you will find PEAP, LEAP and other EAP settings&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 18:51:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383875#M418897</guid>
      <dc:creator>fgasimzade</dc:creator>
      <dc:date>2009-12-14T18:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Mac address based authentication with TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383876#M418902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this section we are not really looking at the TACACS options. We are actually looking at what the ACS Server supports for EAP authentication types:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/SCAuth.html#wp349274"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/SCAuth.html#wp349274&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS supports both protocols Radius and TACACS, but TACACS does not support the EAP methods...so if we have a Radius Client (Switch, AP...) then we can setup MAC authentication, please look at this example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/standalone_mab_ps6441_TSD_Products_Configuration_Guide_Chapter.html#wp1056526"&gt;http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/standalone_mab_ps6441_TSD_Products_Configuration_Guide_Chapter.html#wp1056526&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 19:05:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383876#M418902</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-12-14T19:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Mac address based authentication with TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383877#M418905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how can I configure MAC address based authentication with ACS to grand wireless access only to specific users?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 19:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383877#M418905</guid>
      <dc:creator>fgasimzade</dc:creator>
      <dc:date>2009-12-14T19:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Mac address based authentication with TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383878#M418907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is an example on how to setup an AP against ACS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H4&gt;&lt;A name="ap-acs"&gt;Set Up the AP on the ACS&lt;/A&gt;&lt;/H4&gt;&lt;P&gt;Complete these steps to set up the AP on the ACS:&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;&lt;P&gt;On the ACS server, click &lt;STRONG&gt;Network Configuration&lt;/STRONG&gt; on &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the left.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;To add a AAA client, click &lt;STRONG&gt;Add &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Entry&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Enter these values in the boxes:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;AAA Client IP Address—IP_of_your_AP&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Key—Make up a key (make sure the key matches the AP shared secret &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; key)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Authenticate Using—RADIUS (Cisco Aironet)&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click &lt;STRONG&gt;Submit&lt;/STRONG&gt; &amp;amp; Restart.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt; &lt;SPAN class="content"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3&gt;&lt;A name="mac"&gt;MAC Authentication&lt;/A&gt;&lt;/H3&gt;&lt;H4&gt;&lt;A name="mac-add"&gt;Add a MAC Address to ACS&lt;/A&gt;&lt;/H4&gt;&lt;P&gt;Complete these steps:&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;&lt;P&gt;From the ACS main menu, click on the &lt;STRONG&gt;User Setup&lt;/STRONG&gt; button.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;In the User text box, enter the MAC address to add to the user &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; database.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt; The MAC address must be exactly as it is sent by the AP for both &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the username and the password. If authentication fails, check the failed &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; attempts log to see how the MAC is being reported by the AP. Do not cut and &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; paste the MAC address, as this can introduce phantom characters.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;On the User Setup screen, enter the MAC address in the Secure-PAP &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; password text box.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt; The MAC address must be exactly as it is sent by the AP for both &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the username and the password. If authentication fails, check the failed &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; attempts log to see how the MAC is being reported by the AP. Do not cut and &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; paste the MAC address, as this can introduce phantom characters.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Check the &lt;STRONG&gt;Separate&lt;/STRONG&gt; (CHAP/MS-CHAP) box.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Enter a password for CHAP/MS-CHAP (this password should be &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; different from the MAC address).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click &lt;STRONG&gt;Submit&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H4&gt;&lt;A name="mac-ios-ap"&gt;IOS AP Web Interface&lt;/A&gt;&lt;/H4&gt;&lt;P&gt;Complete these steps:&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;&lt;P&gt;Choose &lt;STRONG&gt;Security &amp;gt; Server &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Manager&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;From the Current Server List drop-down list, choose &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RADIUS.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Enter the ACS IP address.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Enter the shared secret (must match the key in &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click &lt;STRONG&gt;Apply&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;From the EAP Authentication drop-down list, choose the RADIUS &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server's IP address.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click &lt;STRONG&gt;Apply&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;H4&gt;&lt;A name="mac-ssid"&gt;SSID Manager (WEP Encryption Only)&lt;/A&gt;&lt;/H4&gt;&lt;P&gt;Complete these steps for WEP encryption only:&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;&lt;P&gt;Choose the SSID from the Current SSID List, or enter a new SSID in &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the SSID field.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Check the &lt;STRONG&gt;Open Authentication&lt;/STRONG&gt; box.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;From the drop-down list, choose with EAP.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Check the &lt;STRONG&gt;Network EAP&lt;/STRONG&gt; box.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click &lt;STRONG&gt;Apply&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;H4&gt;&lt;A name="mac-encryption"&gt;Encryption Manager (WEP Encryption Only)&lt;/A&gt;&lt;/H4&gt;&lt;P&gt;Complete these steps for WEP encryption only:&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;&lt;P&gt;Choose &lt;STRONG&gt;Security &amp;gt; Encryption &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Manager&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click the &lt;STRONG&gt;WEP Encryption&lt;/STRONG&gt; radio button.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;From the drop-down list, choose Mandatory.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click the &lt;STRONG&gt;Encryption Key 1&lt;/STRONG&gt; radio button.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Enter the key.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;From the Key Size drop-down list, choose 128.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Click &lt;STRONG&gt;Apply&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00805e7a13.shtml#mac"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00805e7a13.shtml#mac&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 19:22:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383878#M418907</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-12-14T19:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: Mac address based authentication with TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383879#M418909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Dec 2009 19:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mac-address-based-authentication-with-tacacs/m-p/1383879#M418909</guid>
      <dc:creator>fgasimzade</dc:creator>
      <dc:date>2009-12-14T19:34:56Z</dc:date>
    </item>
  </channel>
</rss>

