Want to learn the best practice for configuring Chromebooks with 802.1X authentication?

Sign up for a Webinar!

How to integrate RADIUS and MAC Authentication with Ubiquiti Unifi Access Point

Creating a MAC Authentication Identity Provider in SecureW2

This section describes the steps to create an Identity Provider and configure it for MAC Authentication:

  1. Log in to the JoinNow MultiOS Management Portal.
  2. Navigate to Identity Management > Identity Providers.
  3. Click Add Identity Provider.
  4. In the Name field, enter the name of the identity provider.
  5. In the Description field, enter the suitable description for the identity provider.
  6. From the Type drop-down list, select MAC Authentication
  7. Click Save.
  8. The page refreshes and the Conditions tab is displayed.
  9. Select the Conditions tab.
  10. Click Add Device.
  11. In the MAC Address field, type the MAC Address of the device you need to authenticate.
  12. Click Save.
  13. Click Update.

Creating a Role Policy

To configure a role policy, perform the following steps:

  1. Log in to the JoinNow MultiOS Management Portal.
  2. Navigate to Policy Management > Roles Policies.
  3. Click Add Role.
  4. In the Name field, enter a name for your role policy.
  5. In the Display Description field, enter a suitable description.
  6. Click Save.
  7. The page refreshes and the Conditions tab appears.
  8. Select the Conditions tab.
  9. From the Identity Provider drop-down list, select the Identity Provider you created with MAC Authentication type. NOTE: Devices for MAC Authentication must be added in this Identity Provider.
  10. Click Update.

Creating a Network Policy

  1. Navigate to Policy Management > Network Policies.
  2. Click Add Network Policy.
  3. In the Name field, enter a name for your network policy.
  4. In the Display Description field, enter a suitable description.
  5. Click Save.
  6. Select the Conditions tab.
  7. Select Match All or Match Any based on your requirement to set an authentication criteria. In the case explained here, we are selecting Match All.

  8. Click Add rule.
  9. Expand Identity and click Select adjacent to the Role option.
  10. Click Save.
  11. The Role option appears under the Conditions tab.
  12. From the Role Equals drop-down list, select the role policy you created earlier (refer Creating a Role Policy section).
  13. Click Update.

Configuring MAC-based RADIUS Authentication in Unifi

Follow the below steps to set-up MAC based Authentication using Unifi:

  1. Log in to the Unifi Portal.
  2. On the left pane, select Profiles.
  3. Click Create New RADIUS Profile.
  4. In the New RADIUS Profile page, for the Name field, enter the name for your RADIUS profile.
  5. Under the RADIUS Assigned VLAN Support section, select the Enable checkbox for Wireless Networks.

  6. In the RADIUS Settings section, for Authentication Servers, enter the IP Address, Port and Shared Secret. From the JoinNow MultiOS Management Portal (navigate to RADIUS > RADIUS Configuration), copy the IP Address, Port, and Shared Secret and paste them in the IP Address, Port, and Shared Secret fields in the Unifi.

    NOTE: The details of the RADIUS profile must be from the Organization in which MAC based authentication IDP was created in the Creating a MAC Authentication Identity Provider in SecureW2 section.
  7. After entering the RADIUS details, click Add. section.
  8. Click Apply Changes.

Creating a New Wi-Fi Network

To create a new Wi-Fi Network in Unifi:

  1. Log in to the Unifi Portal.
  2. On the left pane, select WiFi.
  3. Click Create New WiFi.
  4. In the New WiFi Network page, for the Name field, enter a suitable name for your Wi-Fi network.
  5. From the Network drop-down list, select Default.

  6. Toggle the Advanced option to Manual.
  7. Under the Security section, for Security Protocol, select Open.
  8. Under the Device Filtering section, select the Enable checkbox for RADIUS MAC Authentication.

  9. For RADIUS Profile, select the RADIUS Profile which is configured with MAC Based Authentication.
  10. Click Apply Changes.