<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello,I hope this will help in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491761#M87129</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I hope this will help you. The username and password will be the MAC-Address of your client wirelss device, e.g.&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;Username:&amp;nbsp; aabbccddeeff&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;Password:&amp;nbsp; aabbccddeeff&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You've to check, in which kind you have to send the MAC Address (aa:bb:cc:dd:ee:ff, aabbcc-ddeeff, AA:BB:CC:DD:EE:FF, and so on)&lt;/P&gt;&lt;P&gt;The attachments will show you a sample ACS Access Policy and the "caller-station-id" configuration and the configuration of a SSID from a Cico WLC 5508.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Dec 2014 07:29:18 GMT</pubDate>
    <dc:creator>Kai Onken</dc:creator>
    <dc:date>2014-12-03T07:29:18Z</dc:date>
    <item>
      <title>ACS - SSID - MAC-Filter separation</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491758#M87109</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I’m trying to setup following environment:&lt;/P&gt;&lt;OL style="margin-left: 40px;"&gt;&lt;LI&gt;WLC 5508 (OS 7.5)&lt;/LI&gt;&lt;LI&gt;Up to 60 Access Points 1602I&lt;/LI&gt;&lt;LI&gt;Two SSID’s are required&lt;/LI&gt;&lt;LI&gt;WPA/WPA2 Authentication is required&lt;/LI&gt;&lt;LI&gt;MAC-Filter should also be used&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I’ve done the following configuration:&lt;/P&gt;&lt;UL style="margin-left: 40px;"&gt;&lt;LI&gt;LAN Enviroment works&lt;/LI&gt;&lt;LI&gt;WLC Setup works also with all Access Points&lt;/LI&gt;&lt;LI&gt;SSID with WPA/WPA2 Authentication work&lt;/LI&gt;&lt;LI&gt;Clients can connect to each SSID&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;For the MAC Filter Setup I’m going to use an ACS 5.4 and an Active Directory. The ACS has successfully joined the Active Directory and at the active Directory I’ve create to groups:&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;CN=SSID1,OU=Authentication,DC=global,DC=lan&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;CN=SSID2,OU=Authentication,DC=global,DC=lan&lt;/P&gt;&lt;P&gt;These two groups I’ve selected after I joined the Active Directoy. I used the Active Directory (AD1) as an Identity group, which is used by a Network Access based Access Service. In my second step, I configured the WLC to use Radius authentication for MAC-Filter and everything works.&lt;/P&gt;&lt;P&gt;But now I’ve found my problem:&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;The ACS Server like work top down and first rule matches:&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;If a MAC is member of group SSID1 and the Client wants to join SSID 1 it works&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;If a MAC is member of group SSID2 and the Client wants to join SSID 1 it works, too. Because the rules are checkt top down first match. And the ACS will find the MAC in group SSID.&lt;/P&gt;&lt;UL style="margin-left: 80px;"&gt;&lt;LI&gt;Is it possible to check at the ACS which SSID send the MAC-Filter request? or&lt;/LI&gt;&lt;LI&gt;Is it possible to get the ssid value from the Active Directory to use this value in my policies?&lt;/LI&gt;&lt;/UL&gt;&lt;P style="margin-left: 40px;"&gt;I would like to restrict the MACs from group SSID1 to SSID 1 and the MACs from group SSID to SSID 2.&lt;/P&gt;&lt;P style="margin-left:18.0pt;"&gt;Thanks and kind regards&lt;/P&gt;&lt;P style="margin-left:18.0pt;"&gt;Kai&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:33:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491758#M87109</guid>
      <dc:creator>Kai Onken</dc:creator>
      <dc:date>2019-03-11T04:33:49Z</dc:date>
    </item>
    <item>
      <title>Problem is solved, the caller</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491759#M87114</link>
      <description>&lt;P&gt;Problem is solved, the caller-station-id can be used, it transfers the SSID and "contains" can be used.&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2014 18:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491759#M87114</guid>
      <dc:creator>Kai Onken</dc:creator>
      <dc:date>2014-05-05T18:37:06Z</dc:date>
    </item>
    <item>
      <title>Hello, I am looking for this</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491760#M87121</link>
      <description>&lt;P&gt;Hello, I am looking for this config as well. Is it possible to post screenshots of ACS showing how you created your Access Policies, and how you restricted authentication by SSID (Using end-station filters for calling-station-id, DNIS??)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2014 19:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491760#M87121</guid>
      <dc:creator>cmonks119</dc:creator>
      <dc:date>2014-12-02T19:11:51Z</dc:date>
    </item>
    <item>
      <title>Hello,I hope this will help</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491761#M87129</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I hope this will help you. The username and password will be the MAC-Address of your client wirelss device, e.g.&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;Username:&amp;nbsp; aabbccddeeff&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;Password:&amp;nbsp; aabbccddeeff&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You've to check, in which kind you have to send the MAC Address (aa:bb:cc:dd:ee:ff, aabbcc-ddeeff, AA:BB:CC:DD:EE:FF, and so on)&lt;/P&gt;&lt;P&gt;The attachments will show you a sample ACS Access Policy and the "caller-station-id" configuration and the configuration of a SSID from a Cico WLC 5508.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2014 07:29:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491761#M87129</guid>
      <dc:creator>Kai Onken</dc:creator>
      <dc:date>2014-12-03T07:29:18Z</dc:date>
    </item>
    <item>
      <title>Hi Onken, Is your problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491762#M87133</link>
      <description>&lt;P&gt;Hi Onken,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is your problem solved only basis on ACS configuration SSID "contains" , in which corporate user connect only corporate ssid and staff users connects only staff ssid?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2015 10:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-ssid-mac-filter-separation/m-p/2491762#M87133</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2015-05-27T10:06:57Z</dc:date>
    </item>
  </channel>
</rss>

