cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
662
Views
0
Helpful
3
Replies

Prevent MAC Addressing Masking

Hi All, 

Hope you are well. 

I've enabled RADIUS authentication using a Kerio NG511 in order to authenticate the users. 

I have an Cisco 9800 series and in between both of them, there is a Cisco 9200 Stack. 

I am attempting to set the user authentication in order to implement QoS and Bandwidth management, as currently the users have unrestricted data. 

My thought was the following:

Kerio NG511: Used to control authentication and Bandwidth Management. 

Cisco WLC: receives the RADIUS auth and allows the device to register to the network. 

I have successfully achieved this, but it seems that the 9200 is masking all the mac addresses to the Kerio. 

Here are my questions:

What do I need to do in order for the WLC to send through the 9200 to the Kerio the Mac addresses?

Will the authentication register the IP to the user on the Kerio or will the information only stay on the WLC?

Thank you for your help in advance. Let me know what you require in order to help.

3 Replies 3

@jonathan.colburn.sastre hi, as per my understanding your kerio device doing NAT for the connecting devices (check if it is). if its doing NAT, all traffic coming through that will use its MAC as source MAC.

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

Hi, As far as I can see, the Kerio is doing NAT from the Kerio to the separate Uplinks. If that was the case, would it show the MAC address of the Kerio or the switch?

The Kerio Firewall is showing on all connected devices the MAC address of the 9200 switch. 

Let me know if there is anything I am not understanding. Thank you. 

That doesn't make any sense.  Like the others said that would likely mean:
- NAT
- Proxy ARP (make sure disabled on all interfaces)
If the Kerio is on the same VLAN and IP subnet as the clients then you should see the client MAC addresses - end of story.  Check your 9800 config with https://cway.cisco.com/wireless-config-analyzer/ using the output of "show tech wireless".  Make sure your IOS is up to date as per TAC recommended below.
Make sure you aren't using any fancy features on the 9200 or trying to do any kind of routing there.
Can the 9200 see the client MAC addresses?
Is the Kerio the default gateway for the clients?
Presume no SVI configured on the client VLAN on the 9800?
Cisco do not recommend using SVI except for specific features which require it - see best practice guide below.

Review Cisco Networking for a $25 gift card