Setup MAC Authentication
3 min
overview mac authentication is used for endpoints—such as printers, desk phones, sensors, cameras, and other wired devices—connected to nile access switches that do not support 802 1x authentication in these cases, the device’s mac address is used as the authentication credential the nile access service supports integrating mac authentication with external radius servers (for example, cisco ise or aruba clearpass) this enables organizations to leverage their existing radius infrastructure for mac based authentication while retaining centralized management and policy enforcement through the nile access service learn more about radius powered authentication docid\ dpzqed6jqfqucdkx3lpob radius based mac authentication when enabled, the nile access service supports dynamic segment assignment based on attributes returned by the radius server configuring mac authentication log in to the nile portal in the left navigation, select network setup > access management > wired to add and manage mac based approvals, ouis, fingerprints, and bulk uploads to use an external radius server for mac authentication, go to network setup > authentication and add a radius server; enable the wired mac auth option during setup device matching and rule options exact mac address rule authorize a specific device and place it in a chosen segment when the mac matches exactly oui based rule match devices by manufacturer prefix (first 3 octets) and assign them to a segment device fingerprint rule use built in fingerprinting (e g , “hp printer”) to place matching devices into a segment catch‑all (“all”) rule optionally allow unmatched devices and assign a default segment; can be combined with workflows like wired sso ways to add and manage entries approve/deny discovered devices directly from the mac authentication page (approve, deny, delete) add oui entries from the oui tool to approve or deny by vendor and map to a segment bulk csv upload to create multiple rules at once (mac/oui/fingerprint, description, target segment) segment‑wide approve/deny (all) option exists but is not recommended due to security risk descriptions and lifecycle controls add a description per entry/rule; entries have lifecycle behaviors (e g , retention/cleanup, statuses like approved/waiting/deny) the nile access service provides additional controls for managing wired device access, including uploading pre approved device lists to streamline onboarding enabling automatic mac authentication (auto‑mac auth) for specified device categories configuring port locking and geographical restrictions to control where and how devices connect refer to the nile wired access management faq docid\ nqrx00kdrs4w4lgx fqn4 for details external radius mac authentication (offloading approvals to radius) enable wired mac authentication on the radius server object in the nile portal to forward mac authentication requests to your external radius system configure dynamic segment assignment by having radius return the segment using either nile’s vsa (netseg) or the standard tunnel private group id attribute this supports assigning different segments on a single ssid or across multiple segments based on device identity optional portal redirection set a static portal redirect on the radius server using the static url field, or rely on server‑initiated redirects when integrating with an external captive portal workflow driven by mac authentication
