MAC based authentication
i've been reading forum after forum on , have not been able find direct answer. ias possible setup mac based authentication, nps solutions work arounds. i'm using hp switches , want able use these 2 lines:
aaa authentication port-access eap-radius
aaa authentication mac-based chap-radius
the first line use nap , 802.1x enforcment. second use mac based enforcment. if fail both of hosed. design here if nap client go through nap, if aren't, , printer/unix/whatever go second. need simple mac solution , windows 2008 r2 dhcp mac filter not enough. want port disabled if not authenticate, nap authenticates using nt credentials of sort, freeradius allow me autheniticate using mac address, love if 1 nap server.
aaa authentication port-access eap-radius
aaa authentication mac-based chap-radius
the first line use nap , 802.1x enforcment. second use mac based enforcment. if fail both of hosed. design here if nap client go through nap, if aren't, , printer/unix/whatever go second. need simple mac solution , windows 2008 r2 dhcp mac filter not enough. want port disabled if not authenticate, nap authenticates using nt credentials of sort, freeradius allow me autheniticate using mac address, love if 1 nap server.
i figured out. asked question didn't follow own rules. had setup mac , 802.1x @ same time state in first question. these articles helpful.
mac:
http://h40060.www4.hp.com/procurve/uk/en/pdfs/application-notes/an-s2_mac-authentication-final-080708.pdf
802.1x:
http://h40060.www4.hp.com/procurve/uk/en/pdfs/application-notes/an-s9_procurve-802.1x-configuration-final-091608.pdf
i forgetting program switch , kept troubleshooting problem nap side. man feel dumb. can see requests hitting nap server , see mac address in requests need setup ad accounts. work me time being.
mac:
http://h40060.www4.hp.com/procurve/uk/en/pdfs/application-notes/an-s2_mac-authentication-final-080708.pdf
802.1x:
http://h40060.www4.hp.com/procurve/uk/en/pdfs/application-notes/an-s9_procurve-802.1x-configuration-final-091608.pdf
i forgetting program switch , kept troubleshooting problem nap side. man feel dumb. can see requests hitting nap server , see mac address in requests need setup ad accounts. work me time being.
Windows Server > Network Access Protection
Comments
Post a Comment