How to realize MAC address Authentication in Local area Network
"MAC address authentication" authenticates the client through the client's MAC address, and only authenticated client devices can access network and server resources. The network structure is as follows:
As shown in the figure above, a WSG security gateway is connected in series between the server segment, the Internet and the intranet switch to control the access from the client of the intranet to the server segment and the extranet. In this example, we are using the bridge deployment mode, and the configuration of the bridge is shown below:
Define the IP segment of the internal network (excluding the server network segment) in the bridge setting of the WSG, so that the access to the Internet and to the server network segment can be controlled. Other related policies are configured as follows:
1. Add the authenticated MAC address to the relevant group
two。 All access is prohibited in application filtering
First, use the policy of banning all application filtering for everyone.
3. Then release all the members of the "certified" group.
After the above configuration steps, you need to be authorized to join the "authenticated MAC address" group before you can access the Internet.