43
7
Authentication
7.1 MAC Authentication
MAC Authentication is based on VLAN and MAC address. The administrator can preset
MAC Authentication entries to allow or deny the clients with specific MAC addresses
and in specific VLANs to access the network. The clients do not need to install any client
software, nor do any operation during the MAC authentication process.
With this feature configured, when a client tries to access the network, the AP sends
the MAC address and VLAN information of the client to the AC. Based on the preset
MAC Authentication entries, the AC checks whether the client is allowed to access the
network or not. Only the clients allowed to access the network can go for the further portal
authentication process.
As the following diagram shows, we configure Client 1 and Client 2 to the whitelist, and
Client 3 to the blacklist on the AC. When these clients are trying to access the network,
the AC will check the MAC authentication entries. According to these entries, Client 1 and
Client 2 will be allowed to access the network, and Client 3 will be denied to access the
network.
Figure 7-1
Topology for MAC Authentication
Client 1
01-86-FC-75-B1-02
VLAN 2
Client 2
01-86-FC-75-B2-75
VLAN 2
Client 3
01-86-FC-75-B3-34
VLAN 3
CAP
PoE Switch
AC
Internet
Whitelist of MAC Addresses:
01-86-FC-75-B1-02 VLAN2
01-86-FC-75-B2-75 VLAN2
Blacklist of MAC Address:
01-86-FC-75-B3-34 VLAN 3
To configure MAC Authentication, refer to the following steps: