EAP245v3 - Omada Controller 5.4.7 - RADIUS MAC-Based Auth w/VLAN Assignment - WPA-Personal

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

EAP245v3 - Omada Controller 5.4.7 - RADIUS MAC-Based Auth w/VLAN Assignment - WPA-Personal

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
EAP245v3 - Omada Controller 5.4.7 - RADIUS MAC-Based Auth w/VLAN Assignment - WPA-Personal
EAP245v3 - Omada Controller 5.4.7 - RADIUS MAC-Based Auth w/VLAN Assignment - WPA-Personal
2022-08-12 14:13:38
Model: EAP245  
Hardware Version: V3
Firmware Version: 5.0.6 Build 20220429 Rel.44315

Greetings.

 

Controller:

    Model: OC200 v1
    Firmware: 1.18.3 Build 20220715 Rel.56221
    Software: 5.4.7

EAP:

    Model: EAP245 v3
    Firmware: 5.0.6 Build 20220429 Rel.44315

 

I noticed the following in the 5.4.7 release notes:

 

https://static.tp-link.com/upload/firmware/2022/202208/20220803/OC200_Release_Note.pdf

 

"6. Added MAC-Based Authentication for wireless networks that use WPA Personal encryption.
Note that this requires EAPs to be upgraded to subsequent releases of adapted firmware.
With the current firmware, clients will be able to connect to the wireless network if the
RADIUS server is offline."

 

*Note - "...this requires EAPs to be upgraded to subsequent releases of adapted firmware."

 

I tried to set this up on a test SSID:

 

3edbee6867ba47fa8d0a48ff60c01f73

 

a1dad1482cb445a4a0029d4e53a5f548

 

*Note - "It will not be applied to SSIDs ... with older firmware version"

 

However, the RADIUS server is never contacted and the device always gets the untagged (default) VLAN.

 

I know the RADIUS configuration is correct because I successfully use it on the switch ports, I can see in its logs where it is contacted for auth when I plug a device in, etc. but not with this configuration for a SSID.

 

Questions

 

    - can it be confirmed that the current EAP245 v3 firmware (5.0.6 Build 20220429 Rel.44315) does not support this?

 

    - can it be confirmed that a new firmware update is coming to EAP245 v3 (hopefully soon) that DOES support this?

 

Thanks!

 

 

  0      
  0      
#1
Options
4 Reply
Re:EAP245v3 - Omada Controller 5.4.7 - RADIUS MAC-Based Auth w/VLAN Assignment - WPA-Personal
2022-08-15 12:05:11

  @user223344 

 

I don't think the current firmware version of EAP is compatible with this new feature, as the latest version of EAP was updated in June, but controller 5.4.7 is a recent update.

Just striving to develop myself while helping others.
  0  
  0  
#2
Options
Re:EAP245v3 - Omada Controller 5.4.7 - RADIUS MAC-Based Auth w/VLAN Assignment - WPA-Personal
2022-08-21 14:44:19

Thank you @Virgo for the reply.

 

I was looking for some confirmation that a firmware update for the EAP245v3 is coming (hopefully soon) that will enable this functionality?

 

Thanks again!

  0  
  0  
#3
Options
Re:EAP245v3 - Omada Controller 5.4.7 - RADIUS MAC-Based Auth w/VLAN Assignment - WPA-Personal
2023-02-19 12:01:55

  @user223344 

I have tried to do the same just now with EAP245v3 und current firmware as well as with EAP610 and 610Outdoor, in neither case the Radius Server is contacted.

 

I have also failed locating a list of products/firmware that support the feature fully, which is utterly frustrating as you set up a feature in the OCC and it doesn't tell you whether any of your EAPs will support it - that is basically rediculous.

 

Ideally the Omada Control Center might display a warning that certain features set up there might not be support by the EAPs connected.

  1  
  1  
#4
Options
Re:EAP245v3 - Omada Controller 5.4.7 - RADIUS MAC-Based Auth w/VLAN Assignment - WPA-Personal
2023-02-19 15:01:27

  @user223344 

I just saw, that, albeit not listet as new firmware in the OCC, there is a 5.1.0 for the EAP245 v3 available and I did a manual upgrade.

After that upgrade the feature worked perfectly with the 245.

 

I just hope there will updates for the 610 soon.

  0  
  0  
#5
Options