cancel
Showing results for 
Search instead for 
Did you mean: 

Remove the MAC address restriction list.

Remove the MAC address restriction list.

peter_stephens
New Contributor

We currently use HiveManager 8.2r2 with MAC address restriction and use this in conjunction with a RADIUS rule that require domain account authentication on the SSID. Ideally we would like to be able to restrict via a method for both domain user and something related to the hardware.

 

Any help gratefully received

1 ACCEPTED SOLUTION

GeorgiaMason
Contributor II

I just tried to set up a Radius auth SSID with MAC auth on the same SSID (using NG) but it only allows me to use one Radius server. Changing the server in once place also changes the server in the second part of the configuration. You could theoretically use Radius auth with a MAC filter. But you might want to use a firewall or content filter for any large amount of MAC filtering so you aren't putting extra work on the APs.

View solution in original post

3 REPLIES 3

GeorgiaMason
Contributor II

I just tried to set up a Radius auth SSID with MAC auth on the same SSID (using NG) but it only allows me to use one Radius server. Changing the server in once place also changes the server in the second part of the configuration. You could theoretically use Radius auth with a MAC filter. But you might want to use a firewall or content filter for any large amount of MAC filtering so you aren't putting extra work on the APs.

peter_stephens
New Contributor

We use it with both at the moment, so the devices MAC has to be in the MAC list, and then the RADIUS rule prompts the user for credentials to authenticate as well

 

So, we would remove any authentication on the Aerohive side, and just configure RADIUS to use a cert and a username and password, right?

samantha_lynn
Esteemed Contributor III

We can do Radius authentication with certificate authentication, so the client device would have to submit Radius credentials and their machine would need the proper certification installed on it in order for clients to connect. I'm not sure we can have a set up that requires Radius credentials and MAC Auth, as MAC auth uses the MAC address of the device in place of a username and password rather than in tandem with a username and password.

GTM-P2G8KFN