Community discussions

MikroTik App
 
User avatar
tgrand
Long time Member
Long time Member
Topic Author
Posts: 667
Joined: Mon Aug 21, 2006 2:57 am
Location: Winnipeg, Manitoba, Canada

client radio authentication

Wed Jul 25, 2007 6:40 am

In the Radius Client is a checkbox for wireless authentication.
I would have thought that from reading the manual the wireless registration would make a radius request
to authenticate the client radio (NOT MAC hotspot user authentication).

I would like to register the MACS on the user manager instead of the wireless ACL and have default authenticate turned off.

I have tryed this and it does not work.
Is this something that can be implimented in the future?

Or could I be doing something wrong?
 
User avatar
tgrand
Long time Member
Long time Member
Topic Author
Posts: 667
Joined: Mon Aug 21, 2006 2:57 am
Location: Winnipeg, Manitoba, Canada

Re: client radio authentication

Thu Jul 26, 2007 6:29 pm

Bump....

Anyone?
 
User avatar
mipland
Member Candidate
Member Candidate
Posts: 210
Joined: Thu Sep 14, 2006 4:02 am

Re: client radio authentication

Thu Jul 26, 2007 10:01 pm

I made this kind of setup some times ago, but with FreeRadius on a Linux machine, and it goes very well.
I think it's the same thing with User Manager, which is a local radius on RouterOS.
Use MAC address as username.

Enable MAC radius authentication, default authenticate to OFF, create e new entry on radius section pointing on localhost, configure user manager and give your user entries as:
/tool user-manager user add username=XX:XX:XX:XX:XX:XX subscriber=MikroTik
 
User avatar
tgrand
Long time Member
Long time Member
Topic Author
Posts: 667
Joined: Mon Aug 21, 2006 2:57 am
Location: Winnipeg, Manitoba, Canada

Re: client radio authentication

Wed Aug 01, 2007 3:19 am

Thanks mipland.

I did figure it out.
In the wireless security profile, under the radius tab.
mac authenticate setting must be checked, and of course under radius it must be configured to talk to the user-manager enabled router.

Works Great!

When I receive new radios I configure the radio macs in user manager, then when I deploy to the customer, it does not matter which AP I setup the Radio, I simply have to Create the User in the user-manager.

This way all Authentication is centralized, which will be a great thing when I start playing with the Roaming and WDS etc.

Way Kewl !!!
 
rumiclord
Frequent Visitor
Frequent Visitor
Posts: 65
Joined: Fri Jul 23, 2010 10:20 pm

Re: client radio authentication

Thu May 12, 2011 8:26 pm

I like this setup, however is there a way to implement a way to disallow a client radio from user manager, after that client radio has already authenticated. I would like it to be an easy place for my technicians to turn off customers who are past-due. If I disable the user, then I still have to go to the AP to remove someones connection. Then they are not able to re-auth. Anyone have an idea on how to streamline this from the user manager. I want to be able to turn off a customer directly from User-man.
 
mbsteez
just joined
Posts: 16
Joined: Wed May 26, 2010 2:37 pm

Re: client radio authentication

Fri May 13, 2011 12:55 am

You can always turn off the ethernet port on the client's radio, assuming you are using a RouterBoard solution for CPE's. Just make sure you don't have the IP address on the ethernet interface you disable, or you'll have to roll a truck anyways.
 
rumiclord
Frequent Visitor
Frequent Visitor
Posts: 65
Joined: Fri Jul 23, 2010 10:20 pm

Re: client radio authentication

Fri May 13, 2011 4:28 pm

Lol, been doing that for customers we have on the motorola canopy cpe, disabling the client in the Access list for the mikrotik, also if u happen to accidently have the ip on the ethernet port and disable that, then mac-telnet can become a thing of beauty. I was thinking there might be someway to have at least the mtk AP's check the user-mgr on regular intervals to see if the authenticated cpe's still have authentication.
 
fewi
Forum Guru
Forum Guru
Posts: 7717
Joined: Tue Aug 11, 2009 3:19 am

Re: client radio authentication

Fri May 13, 2011 4:33 pm

I don't know if the wireless registration table supports DM: http://wiki.mikrotik.com/wiki/Manual:RA ... rom_RADIUS

Might be worth a try. Also don't know if UM supports sending DMs. Other RADIUS servers do.

Who is online

Users browsing this forum: No registered users and 19 guests