Plain Mac-Auth - server accepts but client does not connect

Alan DeKok aland at deployingradius.com
Wed Jan 13 00:38:11 CET 2016


On Jan 12, 2016, at 4:47 PM, Munroe Sollog <mus3 at lehigh.edu> wrote:
> I see what you're saying. I've been reading this thread from last year:
> 
> http://lists.freeradius.org/pipermail/freeradius-users/2015-January/075146.html
> 
> And this seems to be what people do, or at least how vendors are implementing radius-backed
> mac-auth in their hardware.

  They do MAC auth only when there's no EAP, and no Macsec.

> TL;DR, the NAS generates an EAP-MD5 packet with the MAC address as the username and password.

  That's still Mac auth.  It does NOT work for wireless.

  Alan DeKok.




More information about the Freeradius-Users mailing list