Only Mab

This scenario shows how to configure the only-MAB authentication mode.

../../../../../_images/topologydut0dut1.svg

Test Successful MAB Authentication

Description

This scenario shows how to configure MAB-only authentication. DUT1 uses a correct MAC address.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set interfaces ethernet eth1 address 192.168.100.1/24
set interfaces ethernet eth1 authenticator aaa authentication list1
set interfaces ethernet eth1 authenticator log-level debug
set interfaces ethernet eth1 authenticator mode only-MAB
set interfaces ethernet eth1 authenticator quiet-period 60
set interfaces ethernet eth1 authenticator reauth-period 0
set system aaa group radius radgroup1 server serv1
set system aaa list list1 method 1 group radius radgroup1
set system aaa server radius serv1 address 10.215.168.1
set system aaa server radius serv1 encrypted-key U2FsdGVkX1/sJU33E1Xm6ChxfT1wSQfj14M5nMiqrJVxfPOPNNy7HzRxsQtNOs31U3Xq0cpMHfcYU7GTCRr9zQ==
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Ping the IP address 10.215.168.1 from DUT0:

admin@DUT0$ ping 10.215.168.1 count 1 size 56 timeout 1
Show output
PING 10.215.168.1 (10.215.168.1) 56(84) bytes of data.
64 bytes from 10.215.168.1: icmp_seq=1 ttl=64 time=0.483 ms

--- 10.215.168.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.483/0.483/0.483/0.000 ms

Step 3: Set the following configuration in DUT1 :

set interfaces ethernet eth1 address 192.168.100.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 4: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.629 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.629/0.629/0.629/0.000 ms

Step 5: Run the command interfaces ethernet eth1 authenticator show stats on DUT0 and check whether the output matches the following regular expressions:

Authentication Successes\s+1
Authentication Mode\s+MAB
Show output
-------------------------------------------
Field                  Value
-------------------------------------------
Access Challenges                         0
Authentication Backend               RADIUS
Authentication Failures                   0
Authentication Mode                     MAB
Authentication Status      Authorized (MAB)
Authentication Successes                  1
EAPoL frames (Rx)                         0
EAPoL frames (Tx)                         0
Quiet Period                             60
Reauthenticate                        FALSE
Reauthenticate Period                     0
Session Time                              0
Session User MAC          de:ad:be:ef:6c:11
Session User Name                       N/A

Step 6: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=1.43 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 1.433/1.433/1.433/0.000 ms

Step 7: Run the command system journal show | grep "osdx hostapd" on DUT0 and check whether the output contains the following tokens:

802.1X: MAB: station successfully authenticated
Show output
Sep 16 14:30:16.285284 osdx hostapd[83256]: eth1: IEEE 802.11 Fetching hardware channel/rate support not supported.
Sep 16 14:30:16.285298 osdx hostapd[83256]: eth1: RADIUS Authentication server 10.215.168.1:1812
Sep 16 14:30:16.285503 osdx hostapd[83256]: connect[radius]: Network is unreachable
Sep 16 14:30:16.285328 osdx hostapd[83256]: eth1: IEEE 802.1X Initializing IEEE 802.1X: mode=MAB-only, eap_server=0, eap_quiet_period=60, eap_max_retrans=5
Sep 16 14:30:16.285331 osdx hostapd[83256]: eth1: IEEE 802.1X IEEE 802.1X: Enabling packet capture discovery mode
Sep 16 14:30:16.305125 osdx hostapd[83256]: Discovery mode enabled on eth1
Sep 16 14:30:16.305204 osdx hostapd[83256]: eth1: interface state UNINITIALIZED->ENABLED
Sep 16 14:30:16.305244 osdx hostapd[83256]: eth1: AP-ENABLED
Sep 16 14:30:21.305506 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 DRIVER: Device discovered, triggering MAB authentication
Sep 16 14:30:21.305543 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 IEEE 802.1X: New STA de:ad:be:ef:6c:11 added
Sep 16 14:30:21.305552 osdx hostapd[83257]: eth1: IEEE 802.1X IEEE 802.1X: Disabling packet capture discovery mode
Sep 16 14:30:21.329185 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 IEEE 802.1X: MAB-only mode: Starting MAB authentication
Sep 16 14:30:21.329213 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 IEEE 802.1X: MAB: Starting RADIUS query
Sep 16 14:30:21.329228 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 IEEE 802.1X: MAB: User-Name = de:ad:be:ef:6c:11
Sep 16 14:30:21.330976 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 IEEE 802.1X: MAB: User-Password = de:ad:be:ef:6c:11
Sep 16 14:30:21.330986 osdx hostapd[83257]: eth1: RADIUS Authentication server 10.215.168.1:1812
Sep 16 14:30:21.331065 osdx hostapd[83257]: eth1: RADIUS Sending RADIUS message to authentication server
Sep 16 14:30:21.331097 osdx hostapd[83257]: eth1: RADIUS Next RADIUS client retransmit in 1 seconds
Sep 16 14:30:21.331382 osdx hostapd[83257]: eth1: RADIUS Received 20 bytes from RADIUS server
Sep 16 14:30:21.331388 osdx hostapd[83257]: eth1: RADIUS Received RADIUS message
Sep 16 14:30:21.331391 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 RADIUS: Received RADIUS packet matched with a pending request, round trip time 0.00 sec
Sep 16 14:30:21.331395 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 IEEE 802.1X: MAB: Processing RADIUS response
Sep 16 14:30:21.331408 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 IEEE 802.1X: MAB: Identity set to 'de:ad:be:ef:6c:11'
Sep 16 14:30:21.331426 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 IEEE 802.1X: MAB: station successfully authenticated
Sep 16 14:30:21.331429 osdx hostapd[83257]: eth1: IEEE 802.1X IEEE 802.1X: Discovery already disabled
Sep 16 14:30:21.331439 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 IEEE 802.1X: authorizing port
Sep 16 14:30:21.331442 osdx hostapd[83257]: eth1: STA de:ad:be:ef:6c:11 RADIUS: starting accounting session 841802E8575719DB

Test Unsuccessful MAB Authentication

Description

This scenario shows how to configure MAB-only authentication. DUT1 uses an incorrect MAC address.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set interfaces ethernet eth1 address 192.168.100.1/24
set interfaces ethernet eth1 authenticator aaa authentication list1
set interfaces ethernet eth1 authenticator log-level debug
set interfaces ethernet eth1 authenticator mode only-MAB
set interfaces ethernet eth1 authenticator quiet-period 60
set interfaces ethernet eth1 authenticator reauth-period 0
set system aaa group radius radgroup1 server serv1
set system aaa list list1 method 1 group radius radgroup1
set system aaa server radius serv1 address 10.215.168.1
set system aaa server radius serv1 encrypted-key U2FsdGVkX18PIeOulI10kUe9CZINE2y2Vy3qUYIN/9z82GBZKSDJbKS3nctoRl4tIwJcd/PQYY7iQWN5LYLRpw==
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Ping the IP address 10.215.168.1 from DUT0:

admin@DUT0$ ping 10.215.168.1 count 1 size 56 timeout 1
Show output
PING 10.215.168.1 (10.215.168.1) 56(84) bytes of data.
64 bytes from 10.215.168.1: icmp_seq=1 ttl=64 time=0.478 ms

--- 10.215.168.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.478/0.478/0.478/0.000 ms

Step 3: Set the following configuration in DUT1 :

set interfaces ethernet eth1 address 192.168.100.2/24
set interfaces ethernet eth1 mac '00:11:22:33:44:55'
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 4: Run the command interfaces ethernet eth1 authenticator show stats on DUT0 and check whether the output matches the following regular expressions:

Authentication Failures\s+[1-9]\d?
Show output
-------------------------------------------
Field                  Value
-------------------------------------------
Access Challenges                         0
Authentication Backend               RADIUS
Authentication Failures                   2
Authentication Mode                     N/A
Authentication Status          Unauthorized
Authentication Successes                  0
EAPoL frames (Rx)                         0
EAPoL frames (Tx)                         0
Quiet Period                             60
Reauthenticate                        FALSE
Reauthenticate Period                     0
Session Time                              0
Session User MAC          00:11:22:33:44:55
Session User Name                       N/A

Step 5: Expect a failure in the following command: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 0 received, 100% packet loss, time 0ms

Step 6: Run the command system journal show | grep "osdx hostapd" on DUT0 and check whether the output contains the following tokens:

802.1X: MAB: Authentication failed
Show output
Sep 16 14:30:33.376072 osdx hostapd[83838]: eth1: IEEE 802.11 Fetching hardware channel/rate support not supported.
Sep 16 14:30:33.376088 osdx hostapd[83838]: eth1: RADIUS Authentication server 10.215.168.1:1812
Sep 16 14:30:33.376430 osdx hostapd[83838]: connect[radius]: Network is unreachable
Sep 16 14:30:33.376144 osdx hostapd[83838]: eth1: IEEE 802.1X Initializing IEEE 802.1X: mode=MAB-only, eap_server=0, eap_quiet_period=60, eap_max_retrans=5
Sep 16 14:30:33.376147 osdx hostapd[83838]: eth1: IEEE 802.1X IEEE 802.1X: Enabling packet capture discovery mode
Sep 16 14:30:33.403845 osdx hostapd[83838]: Discovery mode enabled on eth1
Sep 16 14:30:33.403941 osdx hostapd[83838]: eth1: interface state UNINITIALIZED->ENABLED
Sep 16 14:30:33.403941 osdx hostapd[83838]: eth1: AP-ENABLED
Sep 16 14:30:38.404124 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 DRIVER: Device discovered, triggering MAB authentication
Sep 16 14:30:38.404176 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 IEEE 802.1X: New STA 00:11:22:33:44:55 added
Sep 16 14:30:38.404186 osdx hostapd[83839]: eth1: IEEE 802.1X IEEE 802.1X: Disabling packet capture discovery mode
Sep 16 14:30:38.423894 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 IEEE 802.1X: MAB-only mode: Starting MAB authentication
Sep 16 14:30:38.423934 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 IEEE 802.1X: MAB: Starting RADIUS query
Sep 16 14:30:38.423949 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 IEEE 802.1X: MAB: User-Name = 00:11:22:33:44:55
Sep 16 14:30:38.425809 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 IEEE 802.1X: MAB: User-Password = 00:11:22:33:44:55
Sep 16 14:30:38.425821 osdx hostapd[83839]: eth1: RADIUS Authentication server 10.215.168.1:1812
Sep 16 14:30:38.425905 osdx hostapd[83839]: eth1: RADIUS Sending RADIUS message to authentication server
Sep 16 14:30:38.425939 osdx hostapd[83839]: eth1: RADIUS Next RADIUS client retransmit in 1 seconds
Sep 16 14:30:39.426047 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 RADIUS: Resending RADIUS message (id=128)
Sep 16 14:30:39.426092 osdx hostapd[83839]: eth1: RADIUS Next RADIUS client retransmit in 2 seconds
Sep 16 14:30:39.428733 osdx hostapd[83839]: eth1: RADIUS Received 20 bytes from RADIUS server
Sep 16 14:30:39.428742 osdx hostapd[83839]: eth1: RADIUS Received RADIUS message
Sep 16 14:30:39.428748 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 RADIUS: Received RADIUS packet matched with a pending request, round trip time 0.00 sec
Sep 16 14:30:39.428753 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 IEEE 802.1X: MAB: Processing RADIUS response
Sep 16 14:30:39.428812 osdx hostapd[83839]: eth1: IEEE 802.1X IEEE 802.1X: Discovery already disabled
Sep 16 14:30:39.428816 osdx hostapd[83839]: eth1: IEEE 802.1X IEEE 802.1X: Discovery already disabled
Sep 16 14:30:39.428819 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 IEEE 802.1X: MAB: Authentication failed, entering held state (quiet period 60 sec)
Sep 16 14:30:39.428823 osdx hostapd[83839]: eth1: STA 00:11:22:33:44:55 IEEE 802.1X: MAB: Retry timeout registered for 60 seconds
Sep 16 14:30:39.428832 osdx hostapd[83839]: eth1: RADIUS Received 20 bytes from RADIUS server
Sep 16 14:30:39.428836 osdx hostapd[83839]: eth1: RADIUS Received RADIUS message
Sep 16 14:30:39.428839 osdx hostapd[83839]: eth1: RADIUS No matching RADIUS request found (type=0 id=128) - dropping packet