Wireless Access

 View Only
  • 1.  MAB authentication with cert authenication

    Posted Jan 17, 2024 03:31 PM

    Is there a way to enable MAB authentication for the wireless clients in a parallel to 802.1x. For example I would want the devices to attempt 802.1x authentication first and once a timer times out or it fails the request I would want the controller to attempt MAB? I still want to use our external NPS (RADIUS) Servers to pass the MAB authentication. I set up a group on the test controllers for MAB authentication using the external servers (same as our dot1x radius servers) and when enabled it killed authentication for the test 802.1x client and did not pass MAB authentication for the Wireless Client that was setup for MAB on the back end.



  • 2.  RE: MAB authentication with cert authenication

    Posted Jan 18, 2024 09:42 AM

    No.  Failure of the EAP exchange means failure of the session.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: MAB authentication with cert authenication

    Posted Jan 19, 2024 10:38 AM

    We were able to get the Radius server to authenticate the client.  I can see it on the wireless LAN, we just don't get an IP address for that client.  Any ideas?




  • 4.  RE: MAB authentication with cert authenication

    Posted Jan 19, 2024 10:40 AM
    Hi,
    What role is user getting and does it allow dhcp? Correct vlan?






  • 5.  RE: MAB authentication with cert authenication

    Posted Jan 19, 2024 11:44 AM

    Yes, sir all that is correct.  We even created a test policy for username and password and mapped the same vlan to the SSID and both clients connected with no problem.