MAC Authentication without RADIUS Server/Only with Controller
I was getting these request from couple of customers where in MAC Auth without RADIUS/only with controller. I have tested below config and found out working. I am posting here for more tweaks and suggestions.
Controller : V2110
OS : 9.15.03.005
1. Create Role for MAC Authentication with access control option as Default deny.
data:image/s3,"s3://crabby-images/3b974/3b97422972a32a2dde93bb52e0bafddee1f2dff6" alt="685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-20752-3lsl01-1_inline.png 685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-20752-3lsl01-1_inline.png"
2. Add rules under the role by clicking ADD button.
data:image/s3,"s3://crabby-images/4df12/4df12d4c7b76fce12902a90cf5570bd3ab67f32c" alt="685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-1172-9sj9ur-2_inline.png 685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-1172-9sj9ur-2_inline.png"
3. For both In and Out Filters, allow specified MAC Address
data:image/s3,"s3://crabby-images/d6556/d655668573d47a5ff5484e530bb9ff1ff2b92461" alt="685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-32436-urihw2-3_inline.png 685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-32436-urihw2-3_inline.png"
4. Similarly Create individual entries for each allowed MAC Address.
data:image/s3,"s3://crabby-images/6ef5d/6ef5d78929d8b47f4e88f7f25384d2aec6fc9afe" alt="685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-21123-1961tnw-4_inline.png 685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-21123-1961tnw-4_inline.png"
5. Now Role has been created. Create WLAN for MAC auth
data:image/s3,"s3://crabby-images/3b3c2/3b3c2db72415f4765a23291a723fe4f5b67dcc46" alt="685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-12208-tjgy9l-5_inline.png 685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-12208-tjgy9l-5_inline.png"
6. Let the privacy be none and Authentication as disabled. Create new VNS to map WLAN services and Role.
data:image/s3,"s3://crabby-images/3da6e/3da6ef469afd9614fb57e1eb4aebe4f657ac1a67" alt="685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-11043-ij58y5-6_inline.png 685c0d135af54f3db80002a2eb6c27ed_RackMultipart20150430-11043-ij58y5-6_inline.png"
What to do if you have hundreds of MAC address to be added?
Get all MAC address in and excel sheet and use concatenate functon to create the create command [Syntax given below]. Login to controller through putty and navigate to
role and
macauth and issue
create commands copied from excel sheet. Sample given below
role
macauth
create 1 proto any eth any mac AB:CD:EF:12:34:56/48 0.0.0.0/0 in both out both allow priority none tos-dscp none cos none
applyOne Question I have in mind is "How many MAC address can be used to put in a single ruleset?"