How MAC authentication works
MAC authentication communicates with the RADIUS server to authenticate a newly found MAC address. The RUCKUS device supports multiple RADIUS servers; if communication with one of the RADIUS servers times out, the others are tried in sequential order. If a response from a RADIUS server is not received within a specified time (by default, 3 seconds), the RADIUS session times out, and the device retries the request up to three times. If no response is received, the next RADIUS server is chosen, and the request is sent for authentication.
The RADIUS server is configured with the usernames and passwords of authenticated
users. For MAC authentication, the username and password is the MAC address itself;
that is, the device uses the MAC address for both the username and the password in
the request sent to the RADIUS server. For example, given a MAC address of 0000000feaa1,
the user's file on the RADIUS server would be configured with the username and password
both set to 0000000feaa1. When traffic from this MAC address is encountered on a MAC
authentication-enabled interface, the device sends the RADIUS server an Access-Request
message with 0000000feaa1 as both the username and password. The format of the MAC
address sent to the RADIUS server can be configured using the
mac-authentication password-format command. You can also specify a password instead of the MAC address for authentication
using the
mac-authentication password-override command.
The request for authentication from the RADIUS server is successful only if the username and password provided in the request matches an entry in the user database on the RADIUS server. When this happens, the RADIUS server returns an Access-Accept message back to the RUCKUS device. When the RADIUS server returns an Access-Accept message for a MAC address, that MAC address is considered authenticated, and traffic from the MAC address is forwarded normally by the RUCKUS device.