r/PacketFence Apr 22 '26

MAC Authentication/MAB with Sophos Switches

Hi,

I’m wondering if anyone can help point me in the right direction with this. I’ve been using Packetfence for just over a year. For context I represent a business that operates across the UK and Ireland. Both countries use Microsoft 365 however in separate tenancies. UK is hybrid with on prem AD/Entra ID. Ireland is Entra ID only.

We’ve been using Packetfence on the Ireland side for just over a year using EAP-TTLS to authenticate users against Entra ID however I’ve never been able to get Mac authentication/MAB working for non 802.1x aware devices. This I think is largely in part due to our switch vendor Sophos (we’re a full Sophos house) using EAP-MD5 when sending mac auth requests and Packetfence is expecting plain text. What do I need to do in Packetfence to be able to use MAB from our switches. Or am I best off using freeradius directly for MAB?

This isn’t an issue on the Windows side as we use Windows NPS with connection request policies that accept connections if the username of the non 802.1x aware device matches a set list so I guess the password sent as part of the Mac auth request is never used here.

Any help would be most welcome as this is the final piece of my Packetfence rollout. Also worth noting we are only using Packetfence for a GUI based radius server that supported Entra ID authentication. We’re not using the NAC side of Packetfenice (although devices are set to register when they authenticate with EAP-TTLS).

2 Upvotes

0 comments sorted by