//
× We are experiencing an outage with Chat Support, Knowledgebase Articles and guided assistance.
× Sept. 1st 12AM to 3AM PT Self-Service Online Portal and Support Phone Lines unavailable for scheduled maintenance.
× BR500 VPN Currently Experiencing Intermittent Connectivity Issues. Subscribe for Updates.
× Holiday Networking Deals Guide for Business!
NETGEAR ® COMMUNITY
  • Downloads
  • MyNETGEAR
  • Community
  • Support
  • Netgear
  • United States
    • 中国 (汉语)
    • Deutschland (Deutsch)
    • España (Español)
    • France (Français)
    • Italia (Italiano)
    • 日本 (日本語)
    • Netherlands (Dutch)
    • Sweden (Svenska)
    • United States (English)
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • English
  • /
  • NETGEAR Forum
  • /
  • Business Solutions
  • /
  • Switches
  • /
  • Smart / Plus / Click Switches
  • /
  • Mac Auth Bypass
Log In
Join Now
  • Community Home
  • Community Browser:
  • NETGEAR Website
  • Support
  • Downloads
  • MyNETGEAR
Log In
  • English
  • /
  • NETGEAR Forum
  • /
  • Business Solutions
  • /
  • Switches
  • /
  • Smart / Plus / Click Switches
  • /
  • Mac Auth Bypass
  • Join Now
  • |
  • Log In
  • |
  • Help

Start a New Discussion

Discussion stats
  • 1 reply
  • ‎2019-11-11 01:11 AM
  • 96 views
  • 0 kudos
  • 2 in conversation
    • EricZ
    • lcoNET
Announcements

Networking Deals Guide for Business and SoHo

Enabling Next-Gen AV over IP Networks - Analyst Day 2019

Cost effective network deployment for small business #Webinar 11/6

New Managed M4300 Fiber and PoE Switches #Webinar

Let us help with AV-over-IP proavdesign@NETGEAR.com

Evolution of PoE #NowAtNETGEAR

Insight 5.7 Features #Webinar

NETGEAR Business Produces and Services @ IFA2019 Berlin

Insight 5.7 Update Now Available

Ethernet Splitter Vs. Ethernet Switch

New Small Remote Managed PoE Switches GC108P & GC108PP

NETGEAR Insight Pro Network Management System enables higher profitability for Resellers

Top Contributors
User Count
schumaku
schumaku Sensei
7
xgonc
xgonc Initiate
2
docstrange
docstrange Tutor
1
kevin_hong
kevin_hong Apprentice
1
jsit
jsit Tutor
1
See All
Latest NETGEAR Switching Community News:
Reply
Topic Options
  • Subscribe to RSS Feed
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Printer Friendly Page
  • All forum topics
  • Previous Topic
  • Next Topic
lcoNET
lcoNET Aspirant
Aspirant
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2019-11-11 01:11 AM
‎2019-11-11 01:11 AM

Mac Auth Bypass

Hello,

 

My Goal is @mac of supplicants allow Radius/Switch to set it in dynamic VLAN (not created on switch but on Radius). Nevertheless not sure if I can do it with my swith XS716T. I know that it is 802.1x compliant but not sure for a Mac Auth authent only. My Radius and Switch are configured according to documentation (802.1x enable and port authent to Auto or Mac Auth), Radius server identified in switch and up.

 

My equipment (the supplicant) is receiving the request from the switch but does not answer back with an EAP identity response. Therefore port goes to unauthorized state.

 

Indeed, my supplicant could not be configured for 802.1x (special requirement). Guest VLAN is not an option also. So I think Mac Auth ByPass (not sure for the ByPass part :-)) should solve this problem.

 

Can I do it with my XS716T?

 

Thanks

 

 

 

Model: XS716T|16-Port 10-Gigabit Copper Smart Managed Pro Switch with 2 Copper/SFP+ Combo Ports
Message 1 of 2
0 Kudos
Reply
EricZ
EricZ NETGEAR Expert
NETGEAR Expert
  • Mark as New
  • Bookmark
  • Subscribe
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content
‎2019-11-11 11:28 PM
‎2019-11-11 11:28 PM

Re: Mac Auth Bypass

Hi @lcoNET 

 

Welcome to Community!

 

Suggest set 802.1x in different scenario:

 

1. If require user input 'username/password' with EAP/MD5.... , please set 'Port Control' type to 'Auto';

2. If reuire user authenticate by MAC address, please set 'Port Control' type to 'MAC Based';

3. If there is no need do authenticate on the port(like: uplink port), please set 'Port Control' type to 'Authorized';

4. If want forbidden one port for ever, please set 'Port Control' type to 'Unauthorized';

 

So in your case, you can set 'Port Control' type to 'MAC Based' for these special supplicant. Meanwhile, you have to add accout with the username/password is MAC of this supplicant.

 

 

Hope it helps!

 

Regards,

EricZ

 

Message 2 of 2
0 Kudos
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
Need More Help?
  • Contact Support
  • About Us
  • Investor Relations
  • Contact us
  • Careers
  • Sign Up
  • United States
    • 中国 (汉语)
    • Deutschland (Deutsch)
    • España (Español)
    • France (Français)
    • Italia (Italiano)
    • 日本 (日本語)
    • Netherlands (Dutch)
    • Sweden (Svenska)
    • United States (English)

© 1996-2019 NETGEAR®