Reference Guide

5. MAC Authentication Service Setup
Previously, the MAC Authentication Bypass was physically enabled via the switch. This configuration
setup permits non-802.1x devices to authenticate via their MAC address.
Note: MAC addresses are easily falsified and it recommended that a profiler service is used to verify the
MAC address. Profilers inspect the DHCP request for an added level of security.
Navigate to Configuration->Services. Click Add Service. Enter the profile properties to reflect the
options as displayed below:
Figure 13 Adding a non-802.1x MAC authentication Service
Click Next. The Authentication Method is preset to MAC AUTH and the Authentication Source is preset
to Endpoints Repository displayed:
Figure 14 Configuring a non-802.1x MAC Authentication Method and Authentication Source
Click Next. Role Mapping will not be set up at this time. Click Next.
Click Next to accept the default Enforcement Policy.
Click Next. Click Save.
Reorder Services
Reordering is important as CPPM evaluates requests against the service rules of each service
configured, in the order in which these services are defined. The service associated with the first
matching service rule is then associated with this request.
ClearPass Policy manager Cisco Switch Setup with CPPM| | 23