How to achieve LAN MAC address authentication Internet

"MAC address authentication" to the client authenticates with the MAC address of the client, you can only access the network and server resources certified client devices. Network structure is as follows:

Drawing 1.png

As shown above, the WSG a security gateway connected between the server network, the Internet, and network switches, so that the control network client to access the network server and the external network. In this example, we used the bridge deployment mode, bridge configuration as shown below:

201909171568699025837583.png

Sites define the bridge provided in the WSG IP segment (not including the server network segment) so that it can on the Internet, access to the network server, management and control are performed. Other relevant policy configuration as follows:

1. The MAC address has been authenticated join groups related

201909171568699331123393.png

2. Application filtering prohibit all access

First of all prohibit the use of all application filtering policy.

201909171568699411541354.png

3. And then on the "certified" is set to release all

201909171568699899697593.png

201909171568699914994227.png

After these configuration steps, the Internet will need to be authorized to join the "authenticated MAC address" after the group before they can be accessed.


Guess you like

Origin blog.51cto.com/12800391/2440349