Cisco AIR-LAP1252AG-A-K9 Software Configuration Guide - Page 153

Enabling MAC-Based Authentication in Cisco Secure ACS

Page 153 highlights

Chapter 4 Security Setup Setting Up MAC-Based Authentication Step 3 Step 4 Step 5 Follow this link path to reach the Address Filters page: a. On the Summary Status page, click Setup. b. On the Setup page, click Address Filters under Associations. Select yes for the option called Is MAC Authentication alone sufficient for a client to be fully authenticated? Click Apply. When you enable this feature, the access point follows these steps to authenticate all clients that associate using open authentication: a. When a client device sends an authentication request to the access point, the access point sends a MAC authentication request in the RADIUS Access Request Packet to the RADIUS server using the client's user ID and password as the MAC address of the client. b. If the authentication succeeds, the client joins the network. If the client is also using EAP authentication, it attempts to authenticate using EAP. c. If MAC authentication fails for the client, the access point allows the client to attempt to authenticate using EAP authentication. The client cannot join the network until EAP authentication succeeds. Enabling MAC-Based Authentication in Cisco Secure ACS Cisco Secure Access Control Server for Windows NT/2000 Servers (Cisco Secure ACS) can authenticate MAC addresses sent from the access point. The access point works with ACS to authenticate MAC addresses using Secure Password Authentication Protocol (Secure PAP). You enter a list of approved MAC addresses into the ACS as users, using the client devices' MAC addresses as both the username and password. The authentication server's list of allowed MAC addresses can reside on the authentication server or at any network location to which the server has access. Follow these steps to create a list of allowed MAC addresses in Cisco Secure ACS: Step 1 Step 2 On the ACS main menu, click User Setup. When the User text box appears, enter the MAC address you want to add to the list. OL-2159-03 Cisco Aironet 1200 Series Access Point Software Configuration Guide 4-35

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284

4-35
Cisco Aironet 1200 Series Access Point Software Configuration Guide
OL-2159-03
Chapter 4
Security Setup
Setting Up MAC-Based Authentication
Step 3
Follow this link path to reach the Address Filters page:
a.
On the Summary Status page, click
Setup
.
b.
On the Setup page, click
Address Filters
under Associations.
Step 4
Select
yes
for the option called
Is MAC Authentication alone sufficient for a client
to be fully authenticated?
Step 5
Click
Apply
. When you enable this feature, the access point follows these steps
to authenticate all clients that associate using open authentication:
a.
When a client device sends an authentication request to the access point, the
access point sends a MAC authentication request in the RADIUS Access
Request Packet to the RADIUS server using the client
s user ID and password
as the MAC address of the client.
b.
If the authentication succeeds, the client joins the network. If the client is also
using EAP authentication, it attempts to authenticate using EAP.
c.
If MAC authentication fails for the client, the access point allows the client
to attempt to authenticate using EAP authentication. The client cannot join
the network until EAP authentication succeeds.
Enabling MAC-Based Authentication in Cisco Secure ACS
Cisco Secure Access Control Server for Windows NT/2000 Servers (Cisco Secure
ACS) can authenticate MAC addresses sent from the access point. The access
point works with ACS to authenticate MAC addresses using Secure Password
Authentication Protocol (Secure PAP). You enter a list of approved MAC
addresses into the ACS as users, using the client devices
MAC addresses as both
the username and password. The authentication server
s list of allowed MAC
addresses can reside on the authentication server or at any network location to
which the server has access.
Follow these steps to create a list of allowed MAC addresses in Cisco Secure
ACS:
Step 1
On the ACS main menu, click
User Setup
.
Step 2
When the User text box appears, enter the MAC address you want to add to the
list.