Security

 View Only
Expand all | Collapse all

Can MAB (Mac-Auth) using WIFI

This thread has been viewed 134 times
  • 1.  Can MAB (Mac-Auth) using WIFI

    Posted May 16, 2025 12:08 PM

    Can MAB in Clearpass can be done if the endpoint using WIFI connectivity? 
    I don't see any document from Aruba for this.

    I have tried configured new services that use MAC_AUTH but it won't work as expected. 



  • 2.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 17, 2025 10:05 AM

    If you mean, using MAC Authentication for Wireless Infrastructure, you need to setup your SSID to do MAC-Auth and then configure the service on Clearpass to perform MAC-AUTH (for Authentication under Authentication Methods, use Allow All MAC AUTH option). 
    However, with the current Random MAC on most mobile devices, are you sure you want to use MAB for WIFI connectivity?



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 3.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 17, 2025 11:02 AM

    Yes, we want to setup for TV display, Camera & Printer via WIFI. 
    So technically it can be done, not only via LAN (network cable)

    I did configure the MAC_AUTH services but this error hit me and REJECT.

    Alerts for this Request :
    RADIUS Cannot select appropriate authentication method




  • 4.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 17, 2025 11:56 AM

    What is the authentication source you're using? 



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 5.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 17, 2025 12:02 PM
    Edited by airhead_tem May 17, 2025 12:04 PM

    Service Type : MAC Authentication

    Authentication Method : MAC_AUTH
    Authentication Source : Static Host List 

    I have register inside static host list my test laptop MAC Address using this format XX-XX-XX-XX-XX-XX




  • 6.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 17, 2025 12:25 PM

    can you check on the Access Tracker, on the Event and then post the Input of that request?



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 7.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 18, 2025 04:42 AM

    Here is a quick write up on this topic 

    Using Static Host List with ClearPass



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 8.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 18, 2025 10:37 PM
    Edited by airhead_tem May 18, 2025 10:38 PM

    This is what my services, and it won't work and pickup the services. 

    Alert




  • 9.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 12:03 AM

    Can you send the Input from the Request Details so we can compare your Service triggering requirements with the Input and check what is missing?



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 10.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 12:17 AM
    Edited by airhead_tem May 19, 2025 12:17 AM

    Is this you're referring




  • 11.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 12:21 AM

    I think the service-type is not matching your service,



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 12.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 12:25 AM
    Edited by shpat May 19, 2025 12:26 AM

    So, from your print screens:

    NAD-IP-Address - Belongs_to_Group_ PLI-LVL26

    Request is Coming from PLI-LVL23

    So your access tracker request shows that is coming with AP-Group is PLI-LVL23 and your service says Belongs to Group PLI-LVL26 (That is one which i noticed) 



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 13.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 12:34 AM

    Also, after you solve service Triggering, this can be an issue.

    Your static host list has MAC Address in the format of XX-XX-XX-XX-XX-XX 

    If you make Rule Mapping and Enforcement policies based on the User-names, the username you are receiving is in format xxxxxxxxxxxx based on your Access Tracker input



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 14.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 02:08 AM

    Urmm...that interesting, I don't have any PLI-LVL23 in the Device Group.

    However, I check access tracker, on my working EAP-TLS connection, the Radius Request come from the same PLI-LVL23. 





  • 15.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 02:27 AM

    Check the RADIUS configuration on controller. Do you send service type of FRAMED-USER instead of LOGIN-USER? If so, then you need to change service definition to use FRAMED-USER (2) instead of LOGIN-USER(1) or reconfigure RADIUS server on controller.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 16.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 03:00 AM

    I'm using Aruba Central as a controller.
    I've checked the place where the SSID profile was created, there is no such option for frame.




  • 17.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 03:04 AM

    The your best bet is to change the service type in Clearpass from LOGIN-USER to FRAMED-USER and it should.work.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 18.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 03:05 AM

    Ok i got already where the PLI-LVL23 come from. It was from the VC of the Access Point. 




  • 19.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 03:23 AM

    So modify your service Trigger parameters to Match precisely the name (keep in mind it is Case Sensitive).
    Then the service should be triggered correctly.



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 20.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 04:18 AM
    Edited by airhead_tem May 19, 2025 04:24 AM

    I have changes this following the recommendation.





  • 21.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 04:43 AM

    You didnt match radius request. NAD-IP-ADDRESS nedd to be address or group. Add PLI-LVL23 ip address into ap group in clearpass and use belongs-to-group condition.



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 22.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 10:00 AM

    For Aruba Instant You will find these settings in RADIUS server setting.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 23.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 04:44 AM

    Also you need to use ALL MAC AUTH instead of MAC AUTH.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 24.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 04:55 AM

    You should leave service type 10 and just change 1 to 2. 

    You can very easily check why your service didnt match. Just compare access tracker radius request with service definition. Also mac auth amethod will only authenticate mac known mac addresses.Status Known in endpoint database. To authenticate all mac addresses use all mac auth.



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 25.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 05:01 AM
    Edited by airhead_tem May 19, 2025 05:01 AM

    Ok promising, now it detected the services but got reject. 

    It prompt username /password - I key in both version of MAC add 




  • 26.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 05:27 AM

    I can't find which service didn't match. 

    NAS-port-type = 19

    service type = 2

    SSID = Tower3-MAC
    AP Group = PLI-LVL23





  • 27.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 08:38 AM

    Confirm AP Device is in the Device Groups in ClearPass. 




  • 28.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 07:49 AM

    For this, you need to go to Authentication Methods and choose All MAC AUTH . From your previous print Screens it was just [MAC AUTH]



    ------------------------------
    Shpat | ACEP | ACMP | ACCP | ACDP
    Just an Aruba enthusiast and contributor by cases
    If you find my comment helpful, KUDOS are appreciated.
    ------------------------------



  • 29.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 08:59 AM

    Authentication Method = [Allow All MAC Auth]

    The AP Group was in the Device Group = PLILVL23




  • 30.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 09:59 AM

    You will need to check your WiFi configuration as it seems it is not configured for MAC auth. 

    Also check other settings for MAC Auth.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 31.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 10:11 AM
    Edited by airhead_tem May 19, 2025 10:12 AM

    Here is the option on my end.
    There is no specific MAC authentication but here as below

    I need to test this tomorrow. 




  • 32.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 10:16 AM

    If you want to have mac authentication, you need to enable it. It won't work in your current setup.

    Also using static mac list is very unflexible. It's better to use Guest Device Repository as you can manage it from Guest module and also assign specific role to each device.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 33.  RE: Can MAB (Mac-Auth) using WIFI

    Posted May 19, 2025 10:20 AM

    This option you highlighted is a specific MAC authentication option when you have 802.1x SSID. In my case I just show option for PSK type (personal) SSID. You need to enable it for MAC Auth to work.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 34.  RE: Can MAB (Mac-Auth) using WIFI
    Best Answer

    Posted Jun 05, 2025 01:15 AM

    Ok thanks you all for the contribution.

    I manage to resolve this.
    In the Aruba Central, I need to make sure the SSID profile security is NOT set as Enterprise, it can be Personal or Open. 
    On this option, MAC Auth is visible.