It should work without radius-mac-authentication, monitor /radius monitor <0> to find out whether any packets are send to RADIUS or not, when MAC RADIUS authentication is off.
When EAP authentication is used (eap-method=passthrough),
router should send these attributes in Access-Request,
Access-Request is send, which contains:
User-Name - EAP supplicant identity (suplicant-identity from security-profles)
Nas-Port-Id - interface name
Acct-Session-Id - session-id (when radius-eap-accounting=yes)
Acct-Multi-Session-Id - id, when radius-eap-accounting=yes, to distinguish different sessions, format "AA-AA-AA-AA-AA-AA-CC-CC-CC-CC-CC-CC-XX-XX-XX-XX-XX-XX-XX-XX", where AA - AP
mac-adress, CC - client mac address, XX unique number;
Calling-Station-Id - client MAC-address "XX-XX-XX-XX-XX-XX"
Called-Station-Id - AP MAC address and SSID "XX-XX-XX-XX-XX-XX:ssid";
I have also problem with connection mikrotik as cliente to 802.1x. Problme is that mikrotik dont send the identity. Here is all images can i get help here: viewtopic.php?p=1059141&hilit=wpa2+enterprise#p1059141
Statistics: Posted by toniojst — Tue Mar 05, 2024 11:15 am