Jump to content

Recommended Posts

Posted

Hello all,

I have been reading about the pros and cons of Cisco ACS vs Microsoft NPS, and have a question for those of you using NPS.

Will NPS allow for end station filters based on mac address, not mac authentication bypass?

A bit of background and my scenario.

I currently have a Cisco ACS setup as my radius server, and it failed on Friday and I had to reload it from backup. This got me thinking what to replace it with when it completely dies and is unrecoverable.

I have a number of policies for dynamic vlan assignment for staff / student etc.

 

All of my windows PC’s authenticate as the machine and not the user, then put in a vlan with full network access.

If a user authenticate they are placed in a guest vlan with limited access to the internal network, because it could be their own device for byod.

 

Finally I have a few Macintosh computers that need to be in the trusted staff vlan but cannot authenticate as a domain machine. What I did to accomplish this was create an end station filter in ACS with the mac addresses of these machines.

Then if the user is part of this group and has one of these mac addresses use this vlan.

Cisco ACS calls them end station filters. I see a condition in NPS called calling station ID I have got mixed information on this from around the web.

Also how are multiple conditions handled in NPS, ANDed ORed

If calling station ID is the client MAC I want

Group is Staff AND MAC is abc OR def etc

 

Does NPS have a similar function or have I made this more complicated than it needs to be.

 

If I get the time I will setup a test ssid and nps server. If I can replicate the functionality of ACS I’ll have a backup.

 

 

Thank you,

 

maccompspolicy.PNG

Posted

OK after some testing today it looks like ALL conditions must match. I tried adding in two mac addresses for the calling station ID and it failed where one worked and did what I wanted.

 

I've replicated my entire ACS config to NPS and had clients authenticating to it today.

My ruckus wireless has a place to configure a backup radius server. I configured it and shutdown the ACS.

The NPS log was filled with event ID 18 invalid attribute.

 

If I configure ruckus to authenticate against NPS directly it works but will not fail over to it. Any ideas on this?

Also there are no students in today and very few staff so I'm not disrupting the entire network today.

Posted

We knew if we ignored you that that was the push you needed to work it out ;)

 

But seriously well done sometimes you have a scenario that no-one else has implemented or has experience of which is why replies were non existant.

 

Ben

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...