04-26-2023 06:33 AM
Hi All,
Hope you are well.
I've enabled RADIUS authentication using a Kerio NG511 in order to authenticate the users.
I have an Cisco 9800 series and in between both of them, there is a Cisco 9200 Stack.
I am attempting to set the user authentication in order to implement QoS and Bandwidth management, as currently the users have unrestricted data.
My thought was the following:
Kerio NG511: Used to control authentication and Bandwidth Management.
Cisco WLC: receives the RADIUS auth and allows the device to register to the network.
I have successfully achieved this, but it seems that the 9200 is masking all the mac addresses to the Kerio.
Here are my questions:
What do I need to do in order for the WLC to send through the 9200 to the Kerio the Mac addresses?
Will the authentication register the IP to the user on the Kerio or will the information only stay on the WLC?
Thank you for your help in advance. Let me know what you require in order to help.
04-26-2023 06:37 AM
@jonathan.colburn.sastre hi, as per my understanding your kerio device doing NAT for the connecting devices (check if it is). if its doing NAT, all traffic coming through that will use its MAC as source MAC.
04-26-2023 06:50 AM
Hi, As far as I can see, the Kerio is doing NAT from the Kerio to the separate Uplinks. If that was the case, would it show the MAC address of the Kerio or the switch?
The Kerio Firewall is showing on all connected devices the MAC address of the 9200 switch.
Let me know if there is anything I am not understanding. Thank you.
04-28-2023 07:39 AM
That doesn't make any sense. Like the others said that would likely mean:
- NAT
- Proxy ARP (make sure disabled on all interfaces)
If the Kerio is on the same VLAN and IP subnet as the clients then you should see the client MAC addresses - end of story. Check your 9800 config with https://cway.cisco.com/wireless-config-analyzer/ using the output of "show tech wireless". Make sure your IOS is up to date as per TAC recommended below.
Make sure you aren't using any fancy features on the 9200 or trying to do any kind of routing there.
Can the 9200 see the client MAC addresses?
Is the Kerio the default gateway for the clients?
Presume no SVI configured on the client VLAN on the 9800?
Cisco do not recommend using SVI except for specific features which require it - see best practice guide below.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide