Jump to content

Recommended Posts

Posted

Morning all,

 

Anyone out there running MAC based authentication with Windows NPS/Radius for their WIFI authentication?

I'm at the F it point where i've been going round in circles for 4+ hours now.

 

I have setup 2 test accounts in AD with both the username and password as the MAC address of devices and then added them to a group.

I have a simple NPS connection policy for any connection the is wireless and an NPS network policy stating anyone within the created group can connect using EAP (PEAP) and MS Chap V2.

 

I want this to work on my new Unifi AP's but there is no test functionality other than using a device so i'm lazily using an old Meraki AP as it has a radius test feature in the console.

If I have it setup for WPA2-Enterprise and use user/password authentication it works fine, flip it to device MAC based and it fails.

 

I cant get anything meaningful out of the NPS logs with accounting setup, any pointers would be appreciated.

Posted (edited)

I briefly played with MAC address authentication many months ago at home for WiFi. Not sure if I still have the VM setup, I'll have to have a look.

 

It can be down to the format of the MAC address even.

 

The better way would be to use certificates and have the devices connect using 802.1x policies.

Edited by Davit2005
Posted
Any particular reason why want to use MAC authentication? We use RADIUS and NPS with Computer based authentication so any machines joined to the domain connect automatically. Anything off the domain uses guest wifi access
Posted
Any particular reason why want to use MAC authentication? We use RADIUS and NPS with Computer based authentication so any machines joined to the domain connect automatically. Anything off the domain uses guest wifi access
1:1 iPads [emoji19]
  • 1 year later...
Posted

Did you manage to get this working?

 

I am trying to get one device that doesn't support 802.1x and Certificates to use Mac Authentication. Not ideal, but I also don't want to broadcast a SSID campus wide for one device!

  • 2 weeks later...
Posted
Set up a user in AD using the MAC address for the username and password, I seem to remember that working but have only done it the once years back.

 

This if you haven't already.

 

I now 1300+ ipads using Radius MAC authentication via usernames/passwords as mac addresses of the devices.

Posted
Intrested in how you did this only because we are 1:1 iPad and our PSK key keeps leaking and we have to keep rolling round the network. we have tried 802.1x with a generic user for the iPads pushed via Jamf it does work but never got that working correcly in Lightspeed.
Posted
Intrested in how you did this only because we are 1:1 iPad and our PSK key keeps leaking and we have to keep rolling round the network. we have tried 802.1x with a generic user for the iPads pushed via Jamf it does work but never got that working correcly in Lightspeed.

 

That is the issue with a PSK, especially as some devices make it very easy to either see or share the key. A PSK per device is better but not as good as 802.1x for sure.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...