cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
520
Views
0
Helpful
7
Replies
Muhammed Adnan
Enthusiast

MAB equivalent for the wireless clients

Hello Experts,

 

MAB  ==> For Wired Client only ==> If dot1x authentication fails, then Mac authentication is tried.

 

MAC Authentication Failover to 802.1X  ==> If mac authentication fails, then try dot1x authentication.

 

1. Is there not any MAB equivalent in wireless, wherein if dot1x authentication fails for wireless clients than MAB is tried?

 

2. If we enable mac authentication on a WLAN, will it consume any end point license from ISE?

 

MAC authentication.PNG

 

7 REPLIES 7
patoberli
VIP Advisor

1. I don't think that is possible on wireless.
2. No idea.

Thanks Patoberli for the response.

 

Is MAC authentication with Radius for WPA2-PSK SSID even supported?

Not that I know of, not without supplying a correct PSK.

You can use iPSK to have a custom PSK per MAC address, but that needs creating a policy per client(group).


MAB and dot1.x can't be configure on the same SSID.

 

Please check the doc for IPSK Deployment Cisco WLC and ISE

 

 

Regards,
Sathiyanarayanan Ravindran

Please rate the post and accept as solution, if my response satisfied your question:)

Hi Ravindran,

 

Thanks for the response and the link.

 

I am not looking for dot1x and MAB on the same SSID.

 

The combination that I am looking out for is wpa2-psk + mac authentication via Radius.

It's either PSK or 802.1x. Now with iPSK you have the possibility to have a different PSK per Mac address, this wasn't possible before.

What you could do, you can block / permit the specific mac addresses directly on the WLC, but that is usually a very bad idea (Mac addresses don't offer any security and can be cloned by everybody!!!).


Yes, That can be done.

 

You have to configure the SSID with WPA2+PSK and MAC filtering , In the AAA server you have to map the radius server which you want to use for MAB.

Regards,
Sathiyanarayanan Ravindran

Please rate the post and accept as solution, if my response satisfied your question:)
Create
Recognize Your Peers
Content for Community-Ad