Community discussions

MikroTik App
 
alexv87
just joined
Topic Author
Posts: 9
Joined: Wed May 02, 2018 8:39 pm

radius authentication wifi with wifi-qcom-ac 7.13rc3

Wed Dec 13, 2023 7:26 pm

Hello,
Does anybody know if radius authentication with an external radius servers works with the new drivers wifi-qcom-ac 7.13 to allocate different vlans to clients? My setup worked very well on V6 with capsman. Currently and trying to do the same on 7.13 and struggling to make it work. Read about the issues with vlan assignments but not sure if this affects radius authentication also. At the moment just trying to make one AP work with wifi radius authentication beforing adding capsman. With wpa2-psk i manage to make the configuration work with an untagged vlan.

Current config below

/interface bridge
add name=bridge vlan-filtering=yes
/interface wifi
# SSID not set
set [ find default-name=wifi1 ] configuration.manager=local .mode=ap disabled=no
/interface vlan
add interface=bridge name=MGMT vlan-id=217
/interface wifi security
add authentication-types=wpa2-eap,wpa3-eap disabled=no eap-accounting=yes name=sec1
/interface wifi
set [ find default-name=wifi2 ] channel.band=5ghz-ac .skip-dfs-channels=all .width=20/40/80mhz configuration.country=Romania .manager=local .mode=ap .ssid=B1 disabled=no security=sec1
/interface bridge port
add bridge=bridge interface=ether1
add bridge=bridge frame-types=admit-only-vlan-tagged interface=wifi2 pvid=320
/interface bridge vlan
add bridge=bridge tagged=ether1,bridge vlan-ids=217
add bridge=bridge tagged=ether1,bridge untagged=wifi2 vlan-ids=320
/interface wifi cap
set caps-man-addresses=172.17.0.251 discovery-interfaces=ether1 slaves-static=no
/ip address
add address=172.17.0.169/24 interface=MGMT network=172.17.0.0
/ip dns
set servers=192.168.13.200
/ip route
add distance=1 gateway=172.17.0.254
/radius
add accounting-port=2041 address=XX.XX.XX.XX authentication-port=2040 service=wireless
/radius incoming
set accept=yes
/system clock
set time-zone-name=Europe/Bucharest
/system logging
add topics=wireless,info
add topics=caps,info
add prefix=error topics=radius
add topics=wireless,info
add topics=caps,info
add prefix=error topics=radius
/system note
set show-at-login=no
/system package update
set channel=development

Any advice would be appreciated:)
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 12979
Joined: Thu Mar 03, 2016 10:23 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Wed Dec 13, 2023 9:03 pm

Your setup isn't possible when running wave2/wifi drivers. The new driver doesn't handle VLAN tags natively (neither per user set by radius or ACLs nor static set as datapath property).

We're quite a large group of users hoping and waiting for this support to get added.
 
alexv87
just joined
Topic Author
Posts: 9
Joined: Wed May 02, 2018 8:39 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Wed Dec 13, 2023 9:38 pm

Thank you. At least i know what i have to do now. Hopefully it will fixed soon.
 
snuggerbonzen
just joined
Posts: 18
Joined: Tue Jan 16, 2024 9:08 am

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Wed Jan 17, 2024 3:56 pm

Your setup isn't possible when running wave2/wifi drivers. The new driver doesn't handle VLAN tags natively (neither per user set by radius or ACLs nor static set as datapath property).

We're quite a large group of users hoping and waiting for this support to get added.

Could you elaborate please? I am a RouterOS newbie. I am asking because I think I have something like OP wants working.

My current setup is one CRS-323 (currently on SwitchOS) and two cAP-ax running wifi-qcom. I have dynamic vlan assignment working with WPA2-EAP, without capsman for now. The clients are authenticated against a FreeRadius running on a pfsense, which also tells the APs which VLAN each client belongs to. What I am struggling with is to do dynamic VLAN assignment with wifi-qcom and WPA2-PSK by MAC address. But I asked about that in a different topic.
 
alexv87
just joined
Topic Author
Posts: 9
Joined: Wed May 02, 2018 8:39 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Thu Jan 18, 2024 9:48 pm

Your setup isn't possible when running wave2/wifi drivers. The new driver doesn't handle VLAN tags natively (neither per user set by radius or ACLs nor static set as datapath property).

We're quite a large group of users hoping and waiting for this support to get added.

Could you elaborate please? I am a RouterOS newbie. I am asking because I think I have something like OP wants working.

My current setup is one CRS-323 (currently on SwitchOS) and two cAP-ax running wifi-qcom. I have dynamic vlan assignment working with WPA2-EAP, without capsman for now. The clients are authenticated against a FreeRadius running on a pfsense, which also tells the APs which VLAN each client belongs to. What I am struggling with is to do dynamic VLAN assignment with wifi-qcom and WPA2-PSK by MAC address. But I asked about that in a different topic.
There are 2 different wifi drivers for ac and ax devices. The ax devices work with dynamic vlan tagging as you mentioned. The ac ones not yet.
 
snuggerbonzen
just joined
Posts: 18
Joined: Tue Jan 16, 2024 9:08 am

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Fri Jan 19, 2024 2:58 pm

There are 2 different wifi drivers for ac and ax devices. The ax devices work with dynamic vlan tagging as you mentioned. The ac ones not yet.
Oh right, that makes sense. Thanks!
 
User avatar
gustavohellwig
just joined
Posts: 9
Joined: Wed Jan 03, 2024 9:37 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Fri Jul 19, 2024 12:30 am

Hey all,
Does someone have any updates on this topic? It's very critical that it still doesn't support it.
Thank you!
 
User avatar
gustavohellwig
just joined
Posts: 9
Joined: Wed Jan 03, 2024 9:37 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Tue Jul 23, 2024 6:15 pm

This is still not solved. Or it is in a new beta firmware?
 
alexv87
just joined
Topic Author
Posts: 9
Joined: Wed May 02, 2018 8:39 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Thu Jul 25, 2024 6:08 pm

This is still not solved. Or it is in a new beta firmware?
Apologies I clicked on the solved button by accident. Based on my testing of the latest beta version and the changelog it's not yet resolved still waiting.
 
grundic
just joined
Posts: 10
Joined: Sun Sep 01, 2024 12:41 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Sun Sep 01, 2024 12:56 pm

I've bought Mikrotik cAP ax, hoping that everything would just work as before on previous models (currently I have hAP-Ac-2 and hAP-mini) -- I need to replace AP from my ISP.
Started to configure RADIUS authentication today and figured out there are no "Security Profiles" anymore and the "Security" tab doesn't have RADIUS option at all :(

This is really bad user experience and apparently the issue is almost 1 year old. Subscribed to the topic to get updates.
 
alexv87
just joined
Topic Author
Posts: 9
Joined: Wed May 02, 2018 8:39 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Sat Sep 21, 2024 2:32 pm

Cap ax works with wifi radius authentication. I use an external radius and it s fine. Older models like cap ac do not yet because of the driver. If you want to use miikrotik radius it's a different package that needs to be installed and setup.
 
grundic
just joined
Posts: 10
Joined: Sun Sep 01, 2024 12:41 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Sat Sep 28, 2024 10:59 am

@alexv87, thank for reply.

I guess the RADIUS authentication is not the issue in my case. I want to have per MAC VLAN tagging using external RADIUS server. And this feature seems to be unsupported. Or do I miss something?

I don't see a VLAN ID configuration on Wireless settings anywhere :-/
 
User avatar
tangent
Forum Guru
Forum Guru
Posts: 1656
Joined: Thu Jul 01, 2021 3:15 pm
Contact:

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Sat Sep 28, 2024 11:04 am

I want to have per MAC VLAN tagging using external RADIUS server. And this feature seems to be unsupported. Or do I miss something?

That feature was just added in 7.17beta2 as part of the new PPSK feature, but only for ax devices. Details here.
 
grundic
just joined
Posts: 10
Joined: Sun Sep 01, 2024 12:41 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Sat Sep 28, 2024 11:42 am

@tangent, brilliant and I just upgraded my MikroTik-cAP-ax. I guess it is compatible:
/system/resource/ print 
    uptime: 1h19m16s           
    version: 7.17beta2 (testing)
    build-time: 2024-09-27 07:07:42
    factory-software: 7.7                
    free-memory: 669.6MiB           
    total-memory: 1024.0MiB          
    cpu: ARM64              
    cpu-count: 4                  
    cpu-frequency: 864MHz             
    cpu-load: 0%                 
    free-hdd-space: 94.7MiB            
    total-hdd-space: 128.0MiB           
    write-sect-since-reboot: 108                
    write-sect-total: 62126              
    bad-blocks: 0.1%               
    architecture-name: arm64              
    board-name: cAP ax             
    platform: MikroTik  
Is there any newby friendly guide I can follow to configure it? I got it configured, but the wireless device can't acquire an IP address :(

Or maybe I can list my current options and someone could point to miss-configurations?
 
User avatar
tangent
Forum Guru
Forum Guru
Posts: 1656
Joined: Thu Jul 01, 2021 3:15 pm
Contact:

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Sat Sep 28, 2024 11:56 am

Is there any newby friendly guide I can follow to configure it?

That's a big ask for a brand-new feature.

Your best bet right now is the official docs.

I have no idea how this integrates with the optional (!) on-device RADIUS server called User Manager, available as user-manager-*.npk in the extra packages archive, much less with third-party RADIUS servers.
 
grundic
just joined
Posts: 10
Joined: Sun Sep 01, 2024 12:41 pm

Re: radius authentication wifi with wifi-qcom-ac 7.13rc3

Sat Sep 28, 2024 12:15 pm

Okay, got it. Will experiment. Thank you for the provided links!

Who is online

Users browsing this forum: No registered users and 13 guests