Please make Password for MAC-Base Auth optional or remove it entirely
None of the modern NAC solutions are receiving the password for MAB therefore causing authentication failure for devices which do not support 802.1x.
Here is the payload that is received from switch to the NAC and as you can see, the password is not passed down.
The only solution that I know of is FreeRadius and it's not really feasible to pidgehole Zyxel users to a single NAC vendor.
[{"Key":"User-Name","Value":"B4-22-00-5C-97-04"},{"Key":"NAS-IP-Address","Value":"10.x.0.x"},{"Key":"NAS-Identifier","Value":"switch_name"},{"Key":"P-Error-Code","Value":"60035"},{"Key":"P-Error-Msg","Value":"Auth via BE failed with curl err: '22' http code: '400'"},{"Key":"CONTEXT_ID","Value":"cab081ae-3e84-34b3-9b38-462edb8fcb97"},{"Key":"PORT","Value":"10432"},{"Key":"RADIUS_REGION","Value":"2"},{"Key":"RADIUS_TYPE","Value":"1"}]
Comments
-
Hi @vladbekker_jp01 ,
A device, such as a printer, is connected to a network switch. This device doesn't have the capability to perform 802.1X authentication, MAB is often used as a fallback method. If the MAC address of the printer is found in the list of the authentication server, the switch grants network access to the printer.
Regarding MAC-based Authentication with Nebula cloud authentication (or using My RADIUS), you don't need to add any passwords. All you have to do is add the MAC address of the client to the list found at Configure > Cloud Authentication > MAC.
If you have any ideas or suggestions that differ from my previous response, please provide us with more details, such as your specific scenario, network topology, and any other information that you believe would be helpful for us to understand and verify your situation accurately.
Be a Community MVP: Win a VIP Deal Dash on Your Next Zyxel Purchase!
0
Categories
- All Categories
- 393 Beta Program
- 2.1K Nebula
- 116 Nebula Ideas
- 78 Nebula Status and Incidents
- 5.1K Security
- 51 USG FLEX H Series
- 247 Security Ideas
- 1.3K Switch
- 70 Switch Ideas
- 906 WirelessLAN
- 34 WLAN Ideas
- 5.9K Consumer Product
- 210 Service & License
- 332 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.9K FAQ
- 880 Nebula FAQ
- 415 Security FAQ
- 220 Switch FAQ
- 195 WirelessLAN FAQ
- 46 Consumer Product FAQ
- 137 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 72 About Community
- 63 Security Highlight