Static Authentication with MAC Authentication Filters

Some devices may always need to be authenticated (included on a whitelist), and some may always have to be blocked (included on a blacklist). Device disposition can be determined at the time of authentication through the RADIUS server; however, for convenience, MAC authentication filters can be configured on ICX devices and applied to appropriate ports so that the ports are pre-authenticated (excluded from authentication based on MAC address).

The MAC authentication filter must be used when the RADIUS server itself is connected to an interface on which MAC authentication or 802.1X authentication is enabled. If a MAC authentication filter is not defined for the MAC addresses of the RADIUS server and applied on the interface, the RADIUS authentication process fails because the device drops all packets from the RADIUS server itself.

The MAC authentication filter is applied on an interface using the authentication filter command in interface configuration mode. Use a permit or deny statement to specify the MAC address to permit or deny. The following example permits inbound traffic with the specified MAC address on VLAN 10.

device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# authentication filter permit 0001.1234.1234 ffff.ffff.ffff 10

A client can be authenticated in an untagged VLAN or tagged VLAN. If the MAC authentication filter has a tagged VLAN configuration, the clients are authenticated in the auth-default VLAN and the tagged VLAN provided in the authentication filter statement. The clients authorized in the auth-default VLAN allow both untagged and tagged traffic.