Sometimes, you want your devices to purely based on their MAC address be able to authenticate. This can be the case if your employees are always using the same devices to log in, and you do not want to hassle around with static DHCP assignments, etc. In this case, Nebula got you covered with our MAC-based authentication! The tutorial below will show you all the necessary configuration steps to achieve this.
MAC-based Authentication allows you to protect your network from unauthorized users without requiring your end devices to input or apply any security settings.
-
Connecting the MAC-based authentication to the Nebula Cloud Authentication
-
Connecting the MAC-based authentication to your own RADIUS Server
Setting up the MAC-based authentication in the SSID
1. Go to
Site-wide > Configure > Access point > SSID advanced settings
and select the SSID.
2. In the Network Access section, select
"Open"
or
"WPA2 Pre-shared Key".
*You cannot use "WPA2-Enterprise" together with MAC-based Authentication.
3. Turn-On MAC-based Authentication.
*Select "My RADIUS server" if your network has a local RADIUS server for authentication.
4. Save your settings.
Connecting the MAC-based authentication to the Nebula Cloud Authentication
1. Go to
SITE-WIDE > Configure > Cloud Authentication > MAC
2. Select [+ Add] and create your trusted device's MAC address.
3. Save your settings.
Connecting the MAC-based authentication to your own RADIUS Server
1. Click [+ Add a server] and configure your RADIUS server.
2. Add RADIUS client in your RADIUS server. Make sure client IP and the secret are correct.
*Example is taken from FreeRADIUS.
3. Add MAC address in the RADIUS user account. Follow the Account Format used in your Nebula AP's RADIUS server settings.
Example:
Preparing the Client
- Press Windows + R and type services.msc
- Search for Wired AutoConfig and set it to Automatic Start
- Click on Start and wait until the Service has started
- Control Panel Home > Network and Internet > Network and Sharing Centre > Change Adapter Settings
- Click Right on the correct Ethernet Connection and choose "Properties"
- Go to the Tab "Network"
- Disable I/O Driver for Link-Layer Topology Detection
- Disable Response for Link-Layer Topology Detection
- Go to the Tab "Authentication"
- Activate "Enable IEEE 802.1X authentication"
- Put "Method for network authentication" on "Microsoft: Protected EAP (PEAP)"
- In the Advanced Settings dialogue, activate Specify Authentication Mode and select Computer Authentication
- Confirm the Advanced Settings dialogue with OK
- Confirm the Wireless Network Properties dialogue with OK
Comments
0 comments
Please sign in to leave a comment.