<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAC filtering - DHCP issue in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/mac-filtering-dhcp-issue/m-p/229452#M163428</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The DHCP request is a layer 2 and layer 3 broadcast which you are filtering.&lt;/P&gt;&lt;P&gt;The server sends a DHCPACK response and it is a L3 broadcast and a L2 unicast as well.  You need to allow UDP ports 67 and 68 through your ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 May 2004 13:06:40 GMT</pubDate>
    <dc:creator>kmarrero</dc:creator>
    <dc:date>2004-05-10T13:06:40Z</dc:date>
    <item>
      <title>MAC filtering - DHCP issue</title>
      <link>https://community.cisco.com/t5/wireless/mac-filtering-dhcp-issue/m-p/229451#M163427</link>
      <description>&lt;P&gt;Hi all,i'm experincing some trouble about a 1100 access point and a/b/g cardbus adapters AIR-CB21AG-E-K9.The AP seems to work correctly with WLAN clients statically IP addressed, but the client doesn't obtain a DHCP address. Tried to disable MAC filtering, the problem disappears, but the policy of my customer is that the MAC filtering is to be enabled.Maybe i'm wrong,i've 3 client adapters and applied their MAC list to the radio interface. Here the AP config, can you help me ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Giovanni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using 2367 out of 32768 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.2&lt;/P&gt;&lt;P&gt;no service pad&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ap&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;enable secret xxxxxxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username xxx password xxxx&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;bridge irb&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dot11Radio0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; encryption key 1 size 128bit xxxxxxxxxxxxxxxxxxxxxxxxxx transmit-key&lt;/P&gt;&lt;P&gt; encryption mode wep mandatory mic&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; ssid YYYYYYYYYY&lt;/P&gt;&lt;P&gt;    authentication open&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt; speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.&lt;/P&gt;&lt;P&gt; 54.0&lt;/P&gt;&lt;P&gt; rts threshold 2312&lt;/P&gt;&lt;P&gt; station-role root&lt;/P&gt;&lt;P&gt; l2-filter bridge-group-acl&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt; bridge-group 1 subscriber-loop-control&lt;/P&gt;&lt;P&gt; bridge-group 1 input-address-list 700&lt;/P&gt;&lt;P&gt; bridge-group 1 output-address-list 700&lt;/P&gt;&lt;P&gt; bridge-group 1 block-unknown-source&lt;/P&gt;&lt;P&gt; no bridge-group 1 source-learning&lt;/P&gt;&lt;P&gt; no bridge-group 1 unicast-flooding&lt;/P&gt;&lt;P&gt; bridge-group 1 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; bridge-group 1&lt;/P&gt;&lt;P&gt; no bridge-group 1 source-learning&lt;/P&gt;&lt;P&gt; bridge-group 1 spanning-disabled&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface BVI1&lt;/P&gt;&lt;P&gt; ip address 10.236.8.10 255.255.255.0&lt;/P&gt;&lt;P&gt; ip access-group 101 in&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip default-gateway 10.236.8.1&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http help-path &lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/ea" target="_blank"&gt;http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/ea&lt;/A&gt;&lt;/P&gt;&lt;P&gt;/ivory/1100&lt;/P&gt;&lt;P&gt;ip radius source-interface BVI1&lt;/P&gt;&lt;P&gt;access-list 101 permit icmp any any&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 10.236.8.29 host 10.236.8.10 eq www&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 10.236.8.29 host 10.236.8.10 eq telnet&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 10.236.8.29 host 10.236.8.10 eq 22&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 10.236.8.30 host 10.236.8.10 eq www&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 10.236.8.30 host 10.236.8.10 eq telnet&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 10.236.8.30 host 10.236.8.10 eq 22&lt;/P&gt;&lt;P&gt;access-list 101 deny   ip any any&lt;/P&gt;&lt;P&gt;access-list 700 permit 0040.96a2.9077   0000.0000.0000&lt;/P&gt;&lt;P&gt;access-list 700 permit 0040.96a2.8be6   0000.0000.0000&lt;/P&gt;&lt;P&gt;access-list 700 permit 0040.96a2.907d   0000.0000.0000&lt;/P&gt;&lt;P&gt;access-list 700 deny   0000.0000.0000   ffff.ffff.ffff&lt;/P&gt;&lt;P&gt;bridge 1 route ip&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login local&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; login&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 16:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mac-filtering-dhcp-issue/m-p/229451#M163427</guid>
      <dc:creator>gdevesco</dc:creator>
      <dc:date>2021-07-04T16:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: MAC filtering - DHCP issue</title>
      <link>https://community.cisco.com/t5/wireless/mac-filtering-dhcp-issue/m-p/229452#M163428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The DHCP request is a layer 2 and layer 3 broadcast which you are filtering.&lt;/P&gt;&lt;P&gt;The server sends a DHCPACK response and it is a L3 broadcast and a L2 unicast as well.  You need to allow UDP ports 67 and 68 through your ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 May 2004 13:06:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mac-filtering-dhcp-issue/m-p/229452#M163428</guid>
      <dc:creator>kmarrero</dc:creator>
      <dc:date>2004-05-10T13:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: MAC filtering - DHCP issue</title>
      <link>https://community.cisco.com/t5/wireless/mac-filtering-dhcp-issue/m-p/229453#M163429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply,Kyle.Sorry but i've not understood where i could allow those ports: i thought&lt;/P&gt;&lt;P&gt;that ACL 700 as configured is only to permit in input to the radio intf the traffic of the frames with the source and destination MAC of my wireless clients and L3 is not to be checked.I thought also that FFFF.FFFF.FFFF is to be passed, where i'm wrong ? (i'm new to L2 ACLs)&lt;/P&gt;&lt;P&gt;Thanks for your patience&lt;/P&gt;&lt;P&gt;Giovanni &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 May 2004 15:14:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/mac-filtering-dhcp-issue/m-p/229453#M163429</guid>
      <dc:creator>gdevesco</dc:creator>
      <dc:date>2004-05-10T15:14:17Z</dc:date>
    </item>
  </channel>
</rss>

