[ACS 5.4] PEAPv1 authentication with MAC filtering

Hello

Our WiFi use the PEAPv1 authentication.

It works very well with different devices (computer, tablets, smartphones).

Now, I want to filter the devices of the company. We have all the MAC addresses of these devices.

Is it possible to activate authentication PEAPv1 combined with MAC filtering in Cisco ACS?

I don't want to filter addresses MAC on WLC...

Thank you

Patrick

Hi Patrick,

See if this helps:

http://www.Cisco.com/en/us/Tech/tk722/tk809/technologies_configuration_example09186a008084f13b.shtml

https://supportforums.Cisco.com/thread/2163123

Agentless network access:

http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/common_scenarios.html#wp1053005

Ed

Tags: Cisco Security

Similar Questions

  • MAC filtering with guest network

    Hello, I have E4200v2 of Cisco, and after someone hacked password of my router, I was forced to activate a white list of MAC filtering. Problem is that I also like to activate a network of comments so my small business clients could still connect to the wifi, without acceding to out to home PC (and drink our bandwidth).

    Is this possible? Thank you.

    1. make sure that disable WPS.

    2 change the router password on the Administration page to guarantee something.

    3 make sure to disable remote management.

    4. set WPA2 Personal with a new strong password.

    5 disable the feedback network.

    That will protect your network. Piracy is not possible unless someone passes the WPA2 password or have access to the router and ethernet ports.

    The MAC filter won't help you. MAC addresses are transferred, are easily picked up and not cloned.

    If you want to activate the guest network you must accept the fact that other computers connect to your guest network and try to access the internet from there. They manage unless they know the password, but still, they can connect to the guest network because it is not protected. Only access from the network invited to the internet is protected.

    He must also accept the fact that you can "drink your bandwidth. If you do not like who don't offer guest access.

  • ACS authentication with Active Directory based on ad groups

    Hello

    I'm trying to integrate Cisco ACS 5.4.0.46 with AD and I connected successfully GBA to AD and I used as a successful AD authentication for network devices but my problem now is that anyone with an AD account can connect to network devices that compromises security. I created a group in AD that I would use and I added the group under users and identity stores > external identity stores > Active Directory > groups directory. I also chose source of identity for Default Device Admin as AD1 and under the authorization, an authorization policy that uses a compound condition that uses AD1 and the custom group. However after you have set all that I am still able to connect to the switch with a user not in the custom group. Based on what I have explained to you can someone tell me if Miss me a step?

    Thank you

    Derek Velez

    Thanks for the update and the fence wire. Set default default rules to deny access when user legimitate if does not match a rule set by the administration of the CSA he should get denied access. In your case, it has been updated a permit so that both type of users access (members and non-members of ad groups).

    The best way to resolve these issues is to look at the monitoring and troubleshooting > attempt user > magnifying glass. You will see how this user has been allowed access.

    ~ BR
    Jatin kone

    * Does the rate of useful messages *.

  • WAP54g does not recognize the IP address of my laptop with active Mac filtering

    I have reset my factory default WAP54g v3.05 to allow access to the older computer to my network.

    Now, I reinstalled for better security using my new laptop: no SSID broadcast and WPA2-Personal encryption. However, when I activate the Mac filtering and allow my laptop more recent, the WAP54g does not recognize.

    Disable Mac filtering and my laptop is back on the network.

    Any suggestions to solve this problem would be appreciated.

    Make sure that the MAC address of the wireless network adapter in the MAC address filtering tab. To get the MAC address of the wireless network card. Click on start-> Go to run-> type-> CMD-> Hit Enter type ipconfig/all

    This will give a show you the MAC address for adapter ethernet and a wireless adapter. You must select one for the wireless network adapter.

  • ISE 1.4 WLAN MAC filtering comments

    Hello

    I just installed 1.4 ISE and features of the company work. However, I have problems with the installation of comments.

    The WLC (5508), I have a guest and foreign controller setup, the client being in the demilitarized zone. I am Setup ISE as radius server and when I select the MAC filtering option, it won't let me connect to the WLAN comments. Keeps trying to connect and fails authentication.

    I have the installation RADIUS, defined by the WLC in ISE, checked the overide AAA and RADIUS selected as the NAC agent according to the instructions online. But I think that MAC authentications keeps failing.

    Any ideas anyone

    Thank you

    Good work on the resolution of your problem! (+ 5) to me!

    If your problem is solved, please mark the thread as "answered" :)

  • Auto unlock with Mac OS and Apple Watch

    I know that you need a Mac 2013 or later with Mac OS, a Apple Watch with watch OS 3 and two factor authentication (not two authentication step) to activate this feature, but for some reason, it does not appear in my system preferences.

    Any ideas?

    Greetings MetallicAsh,

    Thank you for using communities of Apple Support. It seems you want to unlock your Mac with your Apple Watch. Looks like you are already assured of a large number of parameters.
    I recommend reading this article, it explains what the parameters are still needed.

    Make sure that your devices are configured as follows:

    • Your Mac has Bluetooth and Wi - Fi enabled.
    • Your Mac and Apple Watch are connected to iCloud with the same Apple ID.
      On your Mac, choose Apple () menu > System Preferences, and then click iCloud.
      On your iPhone, open the Apple Watch app, then go to general > Apple ID.
    • Your Apple Watch uses a password.
      On your iPhone, open the Apple Watch app, then type the access code.
    • Your Mac has "allow your Apple Watch unlock your Mac" selected in Security & Privacy preferences.
      Choose the Apple menu > System Preferences, click on Privacy & Security, then select the general tab.

    Automatically unlock your Mac with your Apple Watch - Apple Support

    Take care.

  • iPad Air2, Wi - Fi and MAC filtering

    Two other iPads in the House and my iPad Air2 keep disconnecting my wireless router when I turn MAC filtering AND broadcast THAT SSID is disabled. I can't even manually connect to the router, but when I turn one of these functions, or both, the device will automatically reconnect.  I have a router Linksys WRT of Dual-band 1900AC. I have not had this problem with my previous NetGear router. Does anyone know of a solution?

    Before ask you, yes the MAC addresses of my devices are entered into the router. Also, I realize that MAC filtering is not a security measure. It is not my purpose for its use.

    Thank you!

    Can you give us more details?

    What happens when you try to manually connect?

    I'm afraid to say "cannot connect manually" isn't much for us to go. You have "ask to join networks" enabled?

    Have you tried to install the app from Linksys? I know this is to configure the router, but maybe it will help you to establish a compatible connection.

  • Address MAC WUMC710 problems when using MAC filtering

    I recently bought the point WUMC710-HQ AC wireless to connect to my router EA6500.  Generally, the WUMC710 seems to work.  I was able to connect to the router wirelessly on the 5 GHz band and flow EA6500 a NetFlix video with no problems.

    However, there is a major problem that comes makes no logical sense for me:

    When I turn on the wireless MAC address filtering of the EA6500, the WUMC710 does not connect to the EA6500router.

    Yet, I 8 eight other wireless devices on my network which connect very well to the EA6500 when the MAC address filtering is enabled.  Thus, the question seems to outright to WUMC710.

    The address printed on the product shipment to the ends of the box with numbers XX:1 d.

    This address matches the address printed at the bottom of the WUMC710 MAC. (normal)

    My EA6500 router recognizes this MAC address as the correct MAC associated with the WUMC710 (when MAC filtering is enabled).  But as soon as the MAC filtering is turned on, the WUMC710 does not recover to the router. (I checked the MAC address, that I walked into the filter at least a dozen times, and she entered correct - but all my other wireless devices connect OK).

    This is a point that seems strange on the MAC address associated to the WUMC710:

    When I am able to connect to the WUMC710, State--> tab Device illustrated the right address MAC I use to filter.  But when I check the status--> network wireless tab, it displays the MAC address wireless like: XX:1E.

    So, now, I try to get into this 'new' MAC address in the MAC of the router EA6500 filter just to see if it will work with this MAC address "without papers" of the wireless device.  At first, it seems to work.  The WUMC710 of blue light will come on indicating that a wireless connection has been established with the router.  BUT nowhere in the web interface of EA6500 says that the WUMC710 has a DHCP connection with the router.  And, if I connect my laptop directly to one of the WUMC710 Ethernet ports, there is no connection to the Internet via the router (as long as the MAC filtering is enabled).

    I did Factory Reset a few times now and no difference.

    Firmware is the factory default - it is there no update of the firmware available, yet.

    I spent several hours trying to understand what is happening with this device and go round and round in circles in trying different things.  I can only conclude WUMC710-AC is defective, or requires a firmware fix - but none are available.

    Am I missing something here?  Or Cisco does suggest a fix for the firmware for the WUMC710-AC?

    (I don't really like to run my network wireless MAC address filtering active wireless.)

    Kind regards

    Jeff

    Cisco-Linksys 2 support with me today confirmed what I thought it was a possible firmware bug, is actually undocumented features of the WUMC710, by design.  And they agreed that they will update the documentation for WUMC710 to take account of these features and system requirements.

    Just like a reference to new users of the WUMC710 AC wireless bridge, I will summarize here the requirements for WUMC710 wireless bridge to work properly with the router, Cisco-Linksys AC6500 Wireless, when MAC filtering is enabled.  If all goes well, this information will save some other people the many hours I spent to dig through the documentation and the FAQ to try to understand what it takes to connect successfully devices behind the bridge of WUMC710 to the AC6500 router - when the MAC address filtering is enabled:

    The following MAC address must be entered in the AC6500 router table filtering of MAC addresses to connect devices behind the bridge WUMC710 wireless to the Internet:

    1. The MAC address of the bridge wireless WUMC710 wireless.
    2. The address MAC LAN of the WUMC710 bridge.
    3. Addresses MAC LAN of each LAN device connected to the LAN Ports of the WUMC710 bridge.

    That in a few words.

    With this information, devices behind the WUMC710 of Internet connection (with the active MAC filtering) is a breeze.

  • E4200: comments of networking and MAC filtering

    Hello

    I have my e4200 with active network guest and also MAC filtering installation. Somehow, I've been epxecting MAC filtering to do not apply to the network without comment thread, but it seems to be the case.

    Can someone confirm please if this is the case and if there is a work around?

    beautifulbeatrice wrote:

    It depends on which option you select. There is an option to prevent certain MAC address to connect to the network and an option to allow certain MAC addresses to connect. It depends on what you choose. Please see the link below for more information.

    Furthermore, network comments shouldn't be assigned to Wireless Mac Filter restrictions.

    Setting up wireless MAC filtering to prevent users to connect to the network wirelessly on your L...

    Setting up wireless MAC filtering to permit users to connect to the network on your Linksys Wireless...

    ^ ^ ^ Too bad the guest network is affected by the MAC filter.

  • WRT610N - MAC filtering does not list the names of machine

    I replaced a DLink 624 with a Linksys WRT610N and am surprised to see that it doesn't seem to be a way to write the name of the machine with the MAC that I had with the Dlink router.

    Please tell me there is a way to do it.  There is no way I can follow machines.  If I want to delete a machine, and I don't have access to it to check the MAC address, how do I remove the right machine?

    With a little luck I suffer just a brain lock and there is a simple way to do this, but I can't.

    See you soon,.

    Rob

    There is no such feature to enter the name of the Mac filtering on the router linksys devices.

  • How to make MAC filtering

    How can I use MAC filtering to computers that I want to use my wirelsee network? I'm trying to do, I put in the address ip and everything, but after doing this I am not able to connect to the internet until I have reset my router. I have wireless B.

    Thanks to a bouquet.

    1. the MAC filtering does not offer security. If you want to do this for security reasons, forget it. It is not worth. Using WPA2 with a good password. It is safe.

    2. for filtering by MAC address, you must enter the no the IP address of the computers MAC address.

    3 post the exact model and the version of the router as shown on the label under the rotuer.

    4. Please post exactly how you want to put in place filtering. Make sure that you configure MAC wireless filtering on the part wireless to the web interface and access restrictions and not generals?

  • HOWTO to Setup wpa2 + aes + psk with mac-filter WLC 4402 (RADIUS)

    Hello

    I'm trying to Setup wpa2 + aes + psk with mac-filter (RADIUS) on WLC 4402 (6.0.182), with Lap - 1142

    on security, the value L2 security wpa + wpa2 and make sure MAC filtering

    Uncheck the WPA

    check the WPA2, AES, TKIP to unckeck

    Mgmt PSK auth key

    PSK ASCII marker

    L3 no

    Uncheck the political web

    AAA servers

    Select enable accounting radius server server

    It's work fine, when I use WEP with mac-filter (radius)

    but when I select WPA2 is it fail and no newspaper both WLC server and RADIUS

    Is this limitation or bug...

    Thanks in advance for your help

    This sounds like it should work.  Maybe your client likes not wpa2/aes or does not match the PSK.  I would try to associate with this same configuration, but without enabled mac filtering to try to identify the problem.

    -John

  • C410a - wireless not connect to the Verizon FIOS router - fails MAC filtering

    I just bought an all-in-one HP Photosmart Premium C410a printer.  It does not connect to the Verizon FIOS Actiontek MI424WR router, failed the test of MAC filtering.  Spent half an hour on the phone with Verizon (no resolution as they checked the filtering MAC is turned off in the router) and 3 hours with HP (no resolution).  Sharing the printer on a home network defeated the purpose wireless and is not acceptable because I don't want to have another PC switched on just to get to the printer.  Someone was able to resolve the failure "MAC filtering" wireless?

    Without the MAC address filtering test indicates the problem is inconsistent with other available error messages.

    There may not be a real problem of filtering.  I saw this message associated with WEP key mismatches secutiry and a host of other issues.

    To what extent do you have on the installation.  We can work from there.

    Host family

    P.S. I saw messages asking people to try to disconnect the router from the internet while doing the configuration of the printer.  Have you tried?  Sometimes the router check with the service provider before it will allow a device to join the network.  It bypasses this audit.

  • Problems with proportions filtering metadata, am I do bad things?

    Hello

    I've tried to filter all my photos in a collection that has a general portrait of the proportions, but LR is all wrong.

    Picture1.png

    As you can see, there is a mixture of landscapes and portraits even if the portrait is filtered.

    I tried to look at some of my other collections and see if it was an isolated issue, but think that I have the problem here and there.

    Found this example:

    Picture2.png

    Even if the dimensions in the EXIF info on the right indicates 3456 x 2304, LR think that the image is square.

    Could I do something wrong here or could I help LR somewhere along the way, or is this a bug any? I use LR 3.3 on a Mac with Mac OS 10.5.8

    Thanks in advance,

    -Jimmy

    I have a problem (I just checked).

    One thing: portrait vs landscape assessment should be based on the cropped size, IE if you re - crop it should re-classified - what do you see?

  • Is compatible with Mac OS 10.12 (Sierra) with Logic Pro 10.2.4 and the iMac (21.5 inch mid 2011)

    Is compatible with Mac OS 10.12 (Sierra) with Logic Pro 10.2.4 and the iMac (21.5 inch mid 2011)?  I contemplate moving to Sierra, but not if it comes into conflict with Logic Pro.  Can someone advise?

    Thank you!

    Matt

    It was reported a number of not being able to save or to new projects with the title of the Sierra.

    I would conclude some time if I were you, especially if everything is working well at the moment.

Maybe you are looking for