Re: Wireless 802.1x with MAB as fallback and FreeRadius

Alan DeKok via Freeradius-Users <[email protected]>
Newsgroups gmane.comp.freeradius.user
Message-ID <[email protected]>
On Jul 16, 2025, at 12:37 PM, Rodrigo Antunes via Freeradius-Users <[email protected]> wrote:
> Hello, I use EAP to authenticate wireless clients that support 802.1x. 
> But we have some IoT devices that don't support 802.1x, is it possible to make them connect to the same SSID with some kind of fallback?

  Pretty much, no.  An SSID either does 802.1X, or is open / PSK.  It can't do 802.1X and be open.

> I saw a lot of articles teaching how to do this in ISE.

  For wired.  Not for WiFi.

> Basically you enable Mac Authentication Bypass in the wireless controller and then it sends the mac to the radius server, if the mac is invalid then it try 802.1x.
> I tried that, but when the client connects to the ssid It sends the MAC and is rejected by radius.

  If only there was some kind of debug output you could read.  Oh well.

  Alan DeKok.

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.