• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Mac-based Vlan Authetification

Scheduled Pinned Locked Moved L2/Switching/VLANs
4 Posts 4 Posters 633 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dominikmorawietz
    last edited by Feb 6, 2025, 10:11 PM

    Hey Guys,

    Is in pfsense an Option where i can define my mac-adress to an specific vlan, the plan is that when i plug a device in, the pfsense checks if he know it, if it it should move it in the right Vlan, if it is an unknown device it should stay in vlan 1 (public-vlan) for example.

    I read many ways to do it on the switch-side, but i had around 15 switches in a Hotel and amusement park and if we add a Device i dont want to edit the config on all switches.

    Hope you can help me Guys
    Thank a lot
    Dominik

    K J M 3 Replies Last reply Feb 7, 2025, 9:11 AM Reply Quote 0
    • K
      keyser Rebel Alliance @dominikmorawietz
      last edited by keyser Feb 7, 2025, 9:12 AM Feb 7, 2025, 9:11 AM

      @dominikmorawietz Yes and no. If you are talking about built in switchports on the pfsense device itself, then there is no way to do that.
      But i you have VLAN capable switches downstream (like your 15 switches), you can configure all VLANs in them and transport them to pfSense like you probably already have. You can then install the “Freeradius” package on pfSense and create all the known Macaddress as clients and return their VLAN number via Radius to the switch. The trick is then to create a “defaul” Macaddress user that is accepted regardless of the Macaddress and returns VLAN 1 for that user.

      You then need to enable Mac-auth (Mac address authentication) in the switches using Freeradius as the Radius server (authentication server). Works like a charm - I use it in several setups.

      Love the no fuss of using the official appliances :-)

      1 Reply Last reply Reply Quote 0
      • J
        JKnott @dominikmorawietz
        last edited by Feb 7, 2025, 2:11 PM

        @dominikmorawietz

        That sounds like something that was available on Cisco routers, but not Adtran (speaking from experience) where the MAC could be used to assign a VLAN & DHCP server. Is this what you have in mind?

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • M
          marvosa @dominikmorawietz
          last edited by Feb 16, 2025, 2:20 AM

          @dominikmorawietz Sounds like you want SDA or something with similar functionality. I don't think the functionality you're looking for is done at the firewall level. You'll likely need to implement something internally before it hits the firewall.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received