10-28-2002 02:03 PM - edited 07-04-2021 11:29 PM
I tried to implement a solution to authenticate both MAC address and LEAP for wireless client using Cisco ACS. However, it seems that as long as LEAP authentication passed, no matter the MAC authentication was configured properly or not, the user could always be associated and connect to the network. Is there a way to enforce both MAC and LEAP using ACS, so that either authentication fails, the client could not connect to the network.
Thanks,
Daniel
10-30-2002 02:20 AM
Daniel,
The MAC authentication is done first, and then the LEAP authentication. You can select if MAC authen is enought or not.
Please have a look at : http://www.cisco.com/univercd/cc/td/doc/product/wireless/airo1200/accsspts/ap120scg/bkscgch4.htm#xtocid20
If this configuration is not working, you might need to open a TAC CASE.
Regards,
Vincent
10-30-2002 08:54 AM
I have been able to get this to work ...
Ensure that the ACS has the MAC defined as a user.
Ensure that the AP has "default unicast address filter" set to off and that the AP will check ACS for MACs
Configure LEAP as normal ... as the other replier indicated MAC is done first then LEAP
Good Luck ...
11-02-2002 01:30 PM
I got that setup to work by following the instructions on this link:
http://www.cisco.com/warp/public/cc/pd/witc/ao1200ap/prodlit/wrsec_an.htm
The above link is a briliant cook book for wireless security.
I guess your problem could be that the default MAC-filter is "allowed"
go to
setup -> AP radio -> advanced
on your AP and look for "default unicast address filter". Set these to "disallowed"
Best regards,
Mikkel
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide