<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Simple MAC access control question on 5508 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130783#M12331</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;check &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2182372"&gt;https://supportforums.cisco.com/thread/2182372&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 23 Feb 2013 23:04:48 GMT</pubDate>
    <dc:creator>Saravanan Lakshmanan</dc:creator>
    <dc:date>2013-02-23T23:04:48Z</dc:date>
    <item>
      <title>Simple MAC access control question on 5508</title>
      <link>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130776#M12324</link>
      <description>&lt;P&gt;We are forced to rush a installation of a WLC 5508 various reasons in a testing lab. I eventually want to configure RADIUS and such but cannot do it at this immediate time. What I would like to do is impliment straight forward MAC filtering. The problem I am having is the controller allows either any WLAN or only one WLAN, and a interface setting. I need to have each MAC be able to access several WLAN's but not all of them. Can anyone point me to a artcle or give me a quick idea of what I can do.I have basic WLAN's configured and have MAC filtering generally working. I cannot just use a user authentication becasue each user may have 20-30 devices, but not all of these devices should be allowed on all WLAN's and I do not want to rely on the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130776#M12324</guid>
      <dc:creator>ScottB2113</dc:creator>
      <dc:date>2021-07-04T06:08:38Z</dc:date>
    </item>
    <item>
      <title>Simple MAC access control question on 5508</title>
      <link>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130777#M12325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;wlc supports dot1x and users through internal database. same user credentials can be used for multiple users.&lt;/P&gt;&lt;P&gt;using mac filter is not suggested since it is spoofable. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes, currently mac filter on wlc supports 'allow only' for specific or all wlans. this config could be mixed with interface config and using radius on wlc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 16:48:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130777#M12325</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2012-11-30T16:48:38Z</dc:date>
    </item>
    <item>
      <title>Simple MAC access control question on 5508</title>
      <link>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130778#M12326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand a MAC is spoofable, I am only trying to manage a short term fix of limiting what networks a client can access for specific reasons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also believe that the mixure of ANY WLAN/ specific interface could somewhat do what I need however it does not appear that the interface has any affect. I just don't know if I am missing enabling it somewhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot use a user credential becasue it is not about keeping USERS off certain networks it is about onlyt allowing certain clients on a network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 17:54:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130778#M12326</guid>
      <dc:creator>ScottB2113</dc:creator>
      <dc:date>2012-11-30T17:54:00Z</dc:date>
    </item>
    <item>
      <title>Simple MAC access control question on 5508</title>
      <link>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130779#M12327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;WLC onboard radius can't control specific users to access only specific WLANs like external AAA server. it could be available in the future.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;using mac filter can't map a MAC address to two different WLANs, it has to be either any WLAN or one specific WLAN since WLC doesn't allow duplicate mac filter entry for same mac address on its global mac address database. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mapping MAC address to 'any wlan' tied to a specific interface may still not help on condition where different interface used for different wlan where that client intend to connect/access because of above bottleneck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;'however it does not appear that the interface has any affect'.&lt;/P&gt;&lt;P&gt;//Do you mean the client connects and able to pass traffic though it is not mapped to that interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 19:05:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130779#M12327</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2012-11-30T19:05:20Z</dc:date>
    </item>
    <item>
      <title>Simple MAC access control question on 5508</title>
      <link>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130780#M12328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the info. Most of what you say I though was the case. I did read that the interface is supposed to limit the traffic, not stop connecting but just stop the traffic. And some where I read this only works if AAA is enabled. However I cannot find anything more pointing to this. I know using the combination is not ideal but it would work for the interm. Your last question is correct, the client connects and can pass traffic (atleast ping). So for example SSID A is network 192.168.1.0/24 and is interface A, SSID B is 192.168.2.0/24 and is interface B. A routs to 10.10.10.0/24, b does not. It seems by the documentation that with WLAN set to ANY WLAN/Interface A that it should route. If it was changed to interface B it should not route. However it does.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2012 19:17:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130780#M12328</guid>
      <dc:creator>ScottB2113</dc:creator>
      <dc:date>2012-11-30T19:17:12Z</dc:date>
    </item>
    <item>
      <title>Simple MAC access control question on 5508</title>
      <link>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130781#M12329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Open a TAC case and refer this link to get an fix for this issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Dec 2012 13:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130781#M12329</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2012-12-01T13:37:19Z</dc:date>
    </item>
    <item>
      <title>Simple MAC access control question on 5508</title>
      <link>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130782#M12330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like it is applicable only if AAA is configured for that WLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;– &lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -24px; background-color: #ffffff;" width="17" /&gt;&lt;EM style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -24px; background-color: #ffffff;"&gt;interface_name&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;—The name of the interface. This interface name is used to override the interface configured to the WLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -34.560001373291016px; background-color: #ffffff;"&gt;Note &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -34.560001373291016px; background-color: #ffffff;" width="6" /&gt;You must have AAA enabled on the WLAN to override the interface name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/wireless/controller/7.0/configuration/guide/c70wlan.html#wpmkr1222223"&gt;http://www.cisco.com/en/US/docs/wireless/controller/7.0/configuration/guide/c70wlan.html#wpmkr1222223&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2012 21:06:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130782#M12330</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2012-12-07T21:06:38Z</dc:date>
    </item>
    <item>
      <title>Simple MAC access control question on 5508</title>
      <link>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130783#M12331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;check &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2182372"&gt;https://supportforums.cisco.com/thread/2182372&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Feb 2013 23:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130783#M12331</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2013-02-23T23:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Simple MAC access control question on 5508</title>
      <link>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130784#M12332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We use ACS for this. We have groups on our ACS server and add the Mac addresses to the groups. Works great for us.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Feb 2013 21:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/simple-mac-access-control-question-on-5508/m-p/2130784#M12332</guid>
      <dc:creator>Eric Lindsey</dc:creator>
      <dc:date>2013-02-24T21:58:45Z</dc:date>
    </item>
  </channel>
</rss>

