[AP Controller]Setting Up MAC Authentication on Wireless Network

Zyxel_Kay
Zyxel_Kay Posts: 1,210  Zyxel Employee
Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security

This example demonstrates how to configure MAC authentication, allowing wireless clients to authenticate using their MAC addresses instead of usernames and passwords.

In a classroom setting, teachers' devices are pre-registered and trusted on the controller. These devices can bypass standard authentication protocols and are treated as MAC user roles.

In this topology:

  • The NXC acts as the authentication server, storing the devices' MAC addresses.
  • The USG gateway functions as the DHCP server.

Note:
All IP addresses and subnet masks mentioned in this example are placeholders. Replace them with your actual network details. This configuration was tested on:

  • USG20v2 (Firmware Version: V4.15)
  • NXC2500 (Firmware Version: 5.30)
  • GS2210-8HP (Firmware Version: V4.30)

6.1.1 Configure AP Profile

  1. Navigate to CONFIGURATION > Object > AP Profile > SSID > Security.
    • Click Add to create a new security profile.
    • Set the option you prefer for security mode and enable MAC Authentication. In this example, I set the security mode as None.
  2. Go to CONFIGURATION > Object > AP Profile > SSID > SSID List.
    • Create an SSID profile and assign the previously created security profile.

6.1.2 Configure User/Group Profile

  1. Go to CONFIGURATION > Object > User/Group > MAC Address.
    • Select MAC Authentication.
    • Add the teachers' MAC addresses to the NXC local server.

6.1.3 Configure Authentication Method Setting

  1. Go to CONFIGURATION > Object > Auth. Method.
    • Click Add to create a new authentication method.
    • Enter a Name and select Local from the Method List.

6.1.4 Configure AP Group Profile

  1. Navigate to CONFIGURATION > Wireless > AP Management > AP Group > Group Summary > Radio Setting.
    • Set the SSID profile to the AP radio.

6.1.5 Test the Configuration

  1. Use a trusted teacher's device to connect to the SSID: MAC_auth.
    • Verify that the device successfully passes MAC authentication and gains Internet access.
  2. Go to MONITOR > Wireless > Station Info.
    • Check the station information on the NXC.
  3. Navigate to MONITOR > System Status > Login Users > Login Users.
    • Verify that the teacher's device appears in the list of logged-in users.

This completes the MAC authentication setup for trusted wireless devices in a classroom environment.

Kay

See how you've made an impact in Zyxel Community this year! https://bit.ly/Your2024Moments_Community