Community discussions

 
wojo
just joined
Topic Author
Posts: 13
Joined: Tue Aug 21, 2018 4:37 am

802.1x / dot1x client not working when interface is on a bridge

Wed Jul 31, 2019 11:14 pm

I'm able to successfully authenticate with a 802.1x server using RouterOS on a bare interface, but once that interface is a part of a bridge (with default settings) I cannot successfully complete the EAPOL process. It seems to never get to the TLSv1 packet exchange, but I do see the identity request and response.

I have pcaps that I'll clean up soon, but curious if anyone else has tried this or can reproduce it.

If you are wondering why is this interface on a bridge, it lets me handle a situation of stripping VLAN 0 (due to 802.1p priority tagging without VLAN) with VLAN Filtering so I can utilize standard IP features including DHCP, etc. I have to be able to handle those tagged frames inbound to the Mikrotik, but not produce them.

ROS version 4.45.2
 
vikinggeek
just joined
Posts: 13
Joined: Sat Aug 02, 2014 4:14 am

Re: 802.1x / dot1x client not working when interface is on a bridge

Thu Aug 01, 2019 4:01 pm

+1 Me Too!
 
sindy
Forum Guru
Forum Guru
Posts: 3803
Joined: Mon Dec 04, 2017 9:19 pm

Re: 802.1x / dot1x client not working when interface is on a bridge

Thu Aug 01, 2019 6:06 pm

Question - what protocol-mode have you set on the bridge? One of the STP flavors or none?
Instead of writing novels, post /export hide-sensitive. Use find&replace in your favourite text editor to systematically replace all occurrences of each public IP address potentially identifying you by a distinctive pattern such as my.public.ip.1.
 
wojo
just joined
Topic Author
Posts: 13
Joined: Tue Aug 21, 2018 4:37 am

Re: 802.1x / dot1x client not working when interface is on a bridge

Thu Aug 01, 2019 8:27 pm

Question - what protocol-mode have you set on the bridge? One of the STP flavors or none?

I've tried both both also thinking it could be the restrictions around 802.1D. I also spent way too much time tinkering with all the settings I could think of in the dark for weird interactions/bugs but couldn't find anything that works while the interface was on a bridge.
 
robbz
just joined
Posts: 16
Joined: Wed Mar 02, 2016 9:22 pm

Re: 802.1x / dot1x client not working when interface is on a bridge

Wed Sep 11, 2019 11:01 pm

+1 here

Who is online

Users browsing this forum: No registered users and 56 guests