ADMaster Posted October 12, 2014 Posted October 12, 2014 Hello all, I have been reading about the pros and cons of Cisco ACS vs Microsoft NPS, and have a question for those of you using NPS. Will NPS allow for end station filters based on mac address, not mac authentication bypass? A bit of background and my scenario. I currently have a Cisco ACS setup as my radius server, and it failed on Friday and I had to reload it from backup. This got me thinking what to replace it with when it completely dies and is unrecoverable. I have a number of policies for dynamic vlan assignment for staff / student etc. All of my windows PC’s authenticate as the machine and not the user, then put in a vlan with full network access. If a user authenticate they are placed in a guest vlan with limited access to the internal network, because it could be their own device for byod. Finally I have a few Macintosh computers that need to be in the trusted staff vlan but cannot authenticate as a domain machine. What I did to accomplish this was create an end station filter in ACS with the mac addresses of these machines. Then if the user is part of this group and has one of these mac addresses use this vlan. Cisco ACS calls them end station filters. I see a condition in NPS called calling station ID I have got mixed information on this from around the web. Also how are multiple conditions handled in NPS, ANDed ORed If calling station ID is the client MAC I want Group is Staff AND MAC is abc OR def etc Does NPS have a similar function or have I made this more complicated than it needs to be. If I get the time I will setup a test ssid and nps server. If I can replicate the functionality of ACS I’ll have a backup. Thank you,
ADMaster Posted October 13, 2014 Author Posted October 13, 2014 OK after some testing today it looks like ALL conditions must match. I tried adding in two mac addresses for the calling station ID and it failed where one worked and did what I wanted. I've replicated my entire ACS config to NPS and had clients authenticating to it today. My ruckus wireless has a place to configure a backup radius server. I configured it and shutdown the ACS. The NPS log was filled with event ID 18 invalid attribute. If I configure ruckus to authenticate against NPS directly it works but will not fail over to it. Any ideas on this? Also there are no students in today and very few staff so I'm not disrupting the entire network today.
ADMaster Posted October 15, 2014 Author Posted October 15, 2014 I think the problem was with the cert used for peap. I now have Ruckus seamlessly failing over from ACS to NPS. 1
plexer Posted October 15, 2014 Posted October 15, 2014 We knew if we ignored you that that was the push you needed to work it out But seriously well done sometimes you have a scenario that no-one else has implemented or has experience of which is why replies were non existant. Ben
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now