<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Meraki Wireless + Dot1x + Mac address in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466237#M291053</link>
    <description>&lt;P&gt;You won't be able to perform dual MAC+dot1x authentication using NPS (as in, MAC authenticate a machine and then dot1x authenticate a user).&lt;/P&gt;&lt;P&gt;However - that should not be required.  Instead use something like EAP-TLS.  Configure your environment to deploy certificates to machines (and/or users) and authenticate using that.&lt;/P&gt;&lt;P&gt;This is much stronger than stronger than using MAC-based authentication.&lt;/P&gt;&lt;P&gt;If instead you mean you want to be able to support devices doing EITHER MAC-based authentication or username/password authentication (for example), then that can be done with NPS - but it is pretty ugly.  You have to create AD accounts where the username and password are the MAC address of the device.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/MAC-Based_Access_Control_Using_Microsoft_NPS_-_MR_Access_Points" target="_self" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/MAC-Based_Access_Control_Using_Microsoft_NPS_-_MR_Access_Points&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2024 08:09:00 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2024-04-16T08:09:00Z</dc:date>
    <item>
      <title>Meraki Wireless + Dot1x + Mac address</title>
      <link>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466236#M291052</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Require help on how to configure authentication dot1x using user account + mac address. I believe this requires to be done on NPS side. Does anyone have any ideas on this?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 05:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466236#M291052</guid>
      <dc:creator>ShahrulEzwvn</dc:creator>
      <dc:date>2024-04-16T05:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Wireless + Dot1x + Mac address</title>
      <link>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466237#M291053</link>
      <description>&lt;P&gt;You won't be able to perform dual MAC+dot1x authentication using NPS (as in, MAC authenticate a machine and then dot1x authenticate a user).&lt;/P&gt;&lt;P&gt;However - that should not be required.  Instead use something like EAP-TLS.  Configure your environment to deploy certificates to machines (and/or users) and authenticate using that.&lt;/P&gt;&lt;P&gt;This is much stronger than stronger than using MAC-based authentication.&lt;/P&gt;&lt;P&gt;If instead you mean you want to be able to support devices doing EITHER MAC-based authentication or username/password authentication (for example), then that can be done with NPS - but it is pretty ugly.  You have to create AD accounts where the username and password are the MAC address of the device.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/MAC-Based_Access_Control_Using_Microsoft_NPS_-_MR_Access_Points" target="_self" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/MAC-Based_Access_Control_Using_Microsoft_NPS_-_MR_Access_Points&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 08:09:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466237#M291053</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2024-04-16T08:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Wireless + Dot1x + Mac address</title>
      <link>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466238#M291054</link>
      <description>&lt;P&gt;thanks for your explaination. already checked on the MAC as username/password but it cant be done as the AD policy requires special character as the password. &lt;/P&gt;&lt;P&gt;for the first option, the environment includes the scanner as well. so it seems impossible to generate cert.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 08:19:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466238#M291054</guid>
      <dc:creator>ShahrulEzwvn</dc:creator>
      <dc:date>2024-04-16T08:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Wireless + Dot1x + Mac address</title>
      <link>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466239#M291055</link>
      <description>&lt;P&gt;If you go down this path you need to limit yourself to buying hardware that meets your security posture.  There are plenty of scanners and printers out there that support EAP-TLS.&lt;/P&gt;&lt;P&gt;You could also consider not enabling 802.1x on that port and simply using a sticky MAC address.  You can search for the feature on this page:&lt;BR /&gt;&lt;A href="https://documentation.meraki.com/MS/Port_and_VLAN_Configuration/Switch_Ports" target="_self" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/MS/Port_and_VLAN_Configuration/Switch_Ports&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 08:27:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466239#M291055</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2024-04-16T08:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Wireless + Dot1x + Mac address</title>
      <link>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466240#M291056</link>
      <description>&lt;P&gt;I see. Is it possible to bind the user with mac address on the AD side?&lt;/P&gt;&lt;P&gt;Or could we Whitelist all the mac addresses and deny the rest. Could we achieve this using the meraki wireless? &lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 09:53:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466240#M291056</guid>
      <dc:creator>ShahrulEzwvn</dc:creator>
      <dc:date>2024-04-16T09:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Wireless + Dot1x + Mac address</title>
      <link>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466241#M291057</link>
      <description>&lt;P&gt;No with Microsoft NPS.  To be able to do something like this you need to use an authentication protocol called TEAP, and Microsoft NPS does not support this.&lt;/P&gt;&lt;P&gt;But no one does this.  Everyone uses certificate-based authentication instead that needs this kind of security.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 18:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466241#M291057</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2024-04-16T18:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Wireless + Dot1x + Mac address</title>
      <link>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466242#M291058</link>
      <description>&lt;P&gt;Noted. Any documentation on the meraki setup with the dot1x with certificate-based? &lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 09:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466242#M291058</guid>
      <dc:creator>ShahrulEzwvn</dc:creator>
      <dc:date>2024-04-17T09:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Wireless + Dot1x + Mac address</title>
      <link>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466243#M291059</link>
      <description>&lt;P&gt;Not that I am aware of, and it is quite a project.  You might want to consider getting someone in to help you with this.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 19:08:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/meraki-wireless-dot1x-mac-address/m-p/5466243#M291059</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2024-04-17T19:08:24Z</dc:date>
    </item>
  </channel>
</rss>

