Zyxel UAG5100 [229/361] Mac auth example

Zyxel UAG5100 [229/361] Mac auth example
Chapter 44 User/Group
UAG CLI Reference Guide
229
44.2.4.1 MAC Auth Example
This example uses an external server to authenticate wireless clients by MAC address. After
authentication the UAG maps the wireless client to a mac-address user account (MAC role).
Configure user-aware features to control MAC address user access to network services.
The following commands:
Create a MAC role (mac-address user type user account) named ZyXEL-mac
Map a wireless client’s MAC address of 00:13:49:11:a0:c4 to the ZyXEL-mac MAC role (MAC
address user account)
Modify the WLAN security profile named secureWLAN1 as follows:
Turn on MAC authentication
Use the authentication method named Auth1
Use colons to separate the two-character pairs within account MAC addresses
Use upper case letters in the account MAC addresses
[no] mac-auth database mac oui type ext-oui mac-role
username description description
Maps the specified OUI (Organizationally Unique Identifier)
authenticated by an external server to the specified MAC
role (MAC address user account). The OUI is the first three
octets in a MAC address and uniquely identifies the
manufacturer of a network device.
The
no command deletes the mapping between the OUI
and the MAC role.
[no] mac-auth database mac oui type int-oui mac-role
username description description
Maps the specified OUI (Organizationally Unique Identifier)
authenticated by the UAG’s local user database to the
specified MAC role (MAC address user account). The OUI is
the first three octets in a MAC address and uniquely
identifies the manufacturer of a network device.
The
no command deletes the mapping between the OUI
and the MAC role.
Table 142 mac-auth Commands Summary
COMMAND DESCRIPTION
Router(config)# username ZyXEL-mac user-type mac-address
Router(config)# mac-auth database mac 00:13:49:11:a0:c4 type ext-mac-address mac-role
ZyXEL-mac description zyxel mac
3. Modify wlan-security-profile
Router(config)# wlan-security-profile secureWLAN1
Router(config-wlan-security default)# mac-auth activate
Router(config-wlan-security default)# mac-auth auth-method Auth1
Router(config-wlan-security default)# mac-auth delimiter account colon
Router(config-wlan-security default)# mac-auth case account upper
Router(config-wlan-security default)# exit

Содержание

Похожие устройства

Скачать