<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic So if I created a Policy in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785959#M147459</link>
    <description>&lt;P&gt;So if I&amp;nbsp;created a Policy without any macs, no APs join the controller...&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sounds like exactly what I need.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2016 19:29:54 GMT</pubDate>
    <dc:creator>JASON SIMMONS</dc:creator>
    <dc:date>2016-01-14T19:29:54Z</dc:date>
    <item>
      <title>Prevent LWAPs from joining a Controller</title>
      <link>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785957#M147457</link>
      <description>&lt;P&gt;Is there a way to prevent LWAPs from joining a controller? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I know I can change the primary controller config on each AP, but that would only affect the APs that are online when I make that change.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I need to make some pretty extensive changes to a controllers configuration and I'd like to be able to take my time and do it during business hours, instead of rushing to make all of the changes during a maintenance window.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 11:29:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785957#M147457</guid>
      <dc:creator>JASON SIMMONS</dc:creator>
      <dc:date>2021-07-05T11:29:33Z</dc:date>
    </item>
    <item>
      <title>It may not be what you are</title>
      <link>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785958#M147458</link>
      <description>&lt;P&gt;It may not be what you are looking for but you can use AP Policy. You would need to enter a mac address for each AP which would be allowed on said controller.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 18:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785958#M147458</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2016-01-14T18:08:45Z</dc:date>
    </item>
    <item>
      <title>So if I created a Policy</title>
      <link>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785959#M147459</link>
      <description>&lt;P&gt;So if I&amp;nbsp;created a Policy without any macs, no APs join the controller...&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sounds like exactly what I need.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 19:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785959#M147459</guid>
      <dc:creator>JASON SIMMONS</dc:creator>
      <dc:date>2016-01-14T19:29:54Z</dc:date>
    </item>
    <item>
      <title>Correct, only MACs that would</title>
      <link>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785960#M147460</link>
      <description>&lt;P&gt;Correct, only MACs that would be on the AP list would be allowed to join.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 19:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785960#M147460</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2016-01-14T19:55:45Z</dc:date>
    </item>
    <item>
      <title>Looking at the AP Policies</title>
      <link>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785961#M147461</link>
      <description>&lt;P&gt;Looking&amp;nbsp;at the AP Policies screen on one of my controllers, accept MIC is checked and there are several MACs in the authorization list. &amp;nbsp;Do I just uncheck MIC and remove the APs from the auth list?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 20:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785961#M147461</guid>
      <dc:creator>JASON SIMMONS</dc:creator>
      <dc:date>2016-01-14T20:04:03Z</dc:date>
    </item>
    <item>
      <title>yes that would do it i think.</title>
      <link>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785962#M147462</link>
      <description>&lt;P&gt;yes that would do it i think. or checkk box&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Authorize MIC APs against auth-list or AAA&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and remove the aps on&amp;nbsp;the list&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 20:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785962#M147462</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2016-01-14T20:08:23Z</dc:date>
    </item>
    <item>
      <title>Hi Jason,</title>
      <link>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785963#M147463</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;
&lt;P&gt;On the WLC, use the AP authorization list to restrict LAPs based on their MAC address. The AP authorization list is available under Security &amp;gt; AP Policies in the WLC GUI.&lt;/P&gt;
&lt;P&gt;yes, you need to remove the mac of AP, which you don't want to join to this WLC.&lt;/P&gt;
&lt;P&gt;More info:http://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/98848-lap-auth-uwn-config.html#backinfo&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Don't forget to rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 06:38:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785963#M147463</guid>
      <dc:creator>Sandeep Choudhary</dc:creator>
      <dc:date>2016-01-15T06:38:56Z</dc:date>
    </item>
    <item>
      <title>If I accepted SSC,MIC, &amp; LSC</title>
      <link>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785964#M147464</link>
      <description>&lt;P&gt;If I accepted SSC,MIC, &amp;amp; LSC certificates, will I need to add the MACs to the auth-list when I'm ready to put the controller back in production?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 16:28:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785964#M147464</guid>
      <dc:creator>JASON SIMMONS</dc:creator>
      <dc:date>2016-01-15T16:28:47Z</dc:date>
    </item>
    <item>
      <title>Let's cover what these are ..</title>
      <link>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785965#M147465</link>
      <description>&lt;P&gt;Let's cover what these are ..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ssc, mic, lsc are different certs installed on the ap. By check boxing these you are saying aps with these types of certs are allowed to join the WLC. Ssc is only needed if you converted very old 1131 1242 model aps and during that conversion a self signed cert was created. If don't tic that ssc box these aps won't join.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Mic is is what every newer ap comes with. Same applies you don't tic that box they wouldn't join.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Lsc is if you had a PKI and you installed your own cert. Same apples.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So if you tic mic your aps will come back and join.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If if you want to limit what aps can join say if you have mic enabled and you only want set aps to join the WLC you would tic mic and ap authorization and add the ap Ethernet MAC address.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Make sense ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 17:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/prevent-lwaps-from-joining-a-controller/m-p/2785965#M147465</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2016-01-15T17:25:39Z</dc:date>
    </item>
  </channel>
</rss>

