Wireless Configuration 6 - 11
6.1.2.2 MAC Authentication
MAC is a device level authentication method used to augment other security schemes. MAC can be used open, with WEP
64 or WEP 128, KeyGuard, TKIP or CCMP.
MAC authentication can be used for device level authentication by permitting WLAN access based on device MAC
address. MAC authentication is typically used to augment WLAN security options that do not use authentication (such as
static WEP, WPA-PSK and WPA2-PSK). MAC authentication can also be used to assign VLAN memberships, Firewall
policies and time and date access restrictions.
MAC authentication can only identify devices, not users. MAC authentication only references a client’s wireless interface
card MAC address when authenticating the device, it does not distinguish the device’s user credentials. MAC
authentication is somewhat poor as a standalone data protection technique, as MAC addresses can be easily spoofed by
hackers who can mimic a trusted device within the network.
MAC authentication is enabled per WLAN, augmented with the use of a RADIUS server to authenticate each device. A
device’s MAC address can be authenticated against an access point’s local RADIUS server (if supported) or centrally (from
a datacenter). For RADIUS server compatibility, the format of the MAC address can be forwarded to the RADIUS server in
non-delimited and or delimited formats:
To configure MAC authentication on a WLAN:
1. Select
Configuration
>
Wireless
>
Wireless LANs
to display a high-level display of the existing WLANs available.
2. Select the
Add
button to create an additional WLAN, or select an existing WLAN and
Edit
to modify the security
properties of an existing WLAN.
3. Select
Security
.
4. Select
MAC
as the Authentication Type.
Selecting MAC enables the radio buttons for the Open, WEP 64, WEP 128, WPA/WPA2-TKIP, WPA2-CCMP and
Keyguard encryption options as additional measures for the WLAN.
5. Either select an existing AAA Policy from the drop-down menu or select the
Create
icon to the right of the AAA Policy
parameter to display a screen where new AAA policies can be created. A default AAA policy is also available if
configuring a WLAN for the first time and there’s no existing policies. Select the
Edit
icon to modify the configuration
of a selected AAA policy.
Authentication, authorization
, and
accounting
(AAA) is a framework for intelligently controlling access to the wireless
client managed network, enforcing user authorization policies and auditing and tracking usage. These combined
processes are central for securing wireless client resources and wireless network data flows. For information on
defining a new AAA policy, see
6. Select the
Reauthentication
radio button to force MAC supported clients to reauthenticate. Use the spinner control
set the number of minutes (between 30 - 86,400) that, once exceeded, forces the EAP supported client to
reauthenticate.
7. Select
OK
when completed to update the WLAN’s MAC configuration. Select
Reset
to revert the screen back to the
last saved configuration.
MAC Authentication Deployment Considerations
Before defining a MAC authentication configuration on a WLAN, refer to the following deployment guidelines to ensure
the configuration is optimally effective:
• MAC authentication can only be used to identify end-user devices, not the users themselves.
Содержание WiNG 5
Страница 1: ...Motorola Solutions WiNG 5 Access Point System Reference Guide ...
Страница 2: ......
Страница 10: ...viii WiNG 5 Access Point System Reference Guide ...
Страница 16: ...1 4 WiNG 5 Access Point System Reference Guide ...
Страница 28: ...2 12 WiNG 5 Access Point System Reference Guide ...
Страница 48: ...3 20 WiNG 5 Access Point System Reference Guide ...
Страница 197: ...Device Configuration 5 137 Figure 5 78 Profile Management Settings screen ...
Страница 335: ...Device Configuration 5 275 Figure 5 155 Profile Overrides Management Settings screen ...
Страница 348: ...5 288 WiNG 5 Access Point System Reference Guide ...
Страница 350: ...6 2 WiNG 5 Access Point System Reference Guide Figure 6 1 Configuration Wireless ...
Страница 448: ...6 100 WiNG 5 Access Point System Reference Guide ...
Страница 492: ...8 32 WiNG 5 Access Point System Reference Guide ...
Страница 538: ...9 46 WiNG 5 Access Point System Reference Guide ...
Страница 564: ...11 10 WiNG 5 Access Point System Reference Guide ...
Страница 606: ...12 42 WiNG 5 Access Point System Reference Guide ...
Страница 732: ...13 126WiNG 5 Access Point System Reference Guide Figure 13 67 Access Point Certificate Trustpoint screen ...
Страница 762: ...A 2 WiNG 5 Access Point System Reference Guide ...
Страница 801: ......