Adding RADIUS Attributes

During association, the access point performs a MAC authentication with the RADIUS server. The RADIUS server looks up the MAC address, verifies that it has not expired, and returns an Access- Accept. If additional attributes are configured, they are returned with the Access-Accept.
  1. In the Authentication Attributes section, click Add Attribute for Successful (or Unsuccessful) Attempts.
  2. Enter the Attribute, Operator, and Value. The attribute is added to the MAC Registration configuration.

    For example, to return a Filter-Id for a guest user, enter Filter-Id in the Attribute field, and Guest in the Value field. If the authentication request is authorized, the RADIUS server returns the Filter- Id=Guest, along with the Access-Accept attribute to the user device.

After the registration expires (or if an unregistered MAC address associates to the SSID), the RADIUS server replies with an AccessReject. If additional attributes are configured for unsuccessful authentications, they are returned with the AccessReject.