<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using both WPA2 and Mac Filtering in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125319#M25159</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nah... You have it configured wrong like George mentioned. It's both or none at all.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 27 Jan 2013 16:06:33 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2013-01-27T16:06:33Z</dc:date>
    <item>
      <title>Using both WPA2 and Mac Filtering</title>
      <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125314#M25154</link>
      <description>&lt;P&gt;I am curious if I can do an either or sitution with a single SSID.&lt;/P&gt;&lt;P&gt;If you are on the mac filtering list then you gain access to the network, if not then enter your WPA2-ENT credentials.&lt;/P&gt;&lt;P&gt;I have a minimal ammount of users that need mac filtering, but do not want to give them there own SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know what you think, and if this is even possible.&lt;/P&gt;&lt;P&gt;Cisco WLC 5508 7.4 code&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:24:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125314#M25154</guid>
      <dc:creator>richardwang5000</dc:creator>
      <dc:date>2021-07-04T06:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Using both WPA2 and Mac Filtering</title>
      <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125315#M25155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to authentication, wpa also provides for an encrypted channel over the wireless link. Mac filtering is just an acl; if you pass the filter you're in, but there's no encryption. I don't think these two are interchangeable as an either/or solution.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 03:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125315#M25155</guid>
      <dc:creator>Jeff Van Houten</dc:creator>
      <dc:date>2013-01-24T03:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Using both WPA2 and Mac Filtering</title>
      <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125316#M25156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to add... You can do both at the same time, but its both together not either or. Since you define both on a SSID, the WLC is expecting that the MAC address of the device is in the list and then the pre shared key is valid.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2013 03:54:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125316#M25156</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-24T03:54:32Z</dc:date>
    </item>
    <item>
      <title>Using both WPA2 and Mac Filtering</title>
      <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125317#M25157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Scott,&lt;/P&gt;&lt;P&gt;&amp;nbsp; If there is mac filtering and wpa psk, clients which have just the PSK configured correctly are able to connect even though they are NOT in the mac filter list. Is this expected behaviour ? I am expecting that the client should be able to join only if BOTH of the conditions are met (that is PSK as well as mac filtering). which one takes precendence or is checked for first ? i think its PSK when PSK is configured. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 15:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125317#M25157</guid>
      <dc:creator>wireless wlc</dc:creator>
      <dc:date>2013-01-27T15:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Using both WPA2 and Mac Filtering</title>
      <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125318#M25158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's not expected behavior. Are you sure you selected max filter under the WLAN ?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 15:47:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125318#M25158</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-01-27T15:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Using both WPA2 and Mac Filtering</title>
      <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125319#M25159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nah... You have it configured wrong like George mentioned. It's both or none at all.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 16:06:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125319#M25159</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-01-27T16:06:33Z</dc:date>
    </item>
    <item>
      <title>Using both WPA2 and Mac Filtering</title>
      <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125320#M25160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp; Then it might be a bug in 7.2.110? I have a customer configured for both and clients who just have WPA PSK only configured are also able to connect to the SSID with mac filtering + WPA PSK enabled. clients with both WPA PSK AND mac filtering are also able to connect. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 20:28:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125320#M25160</guid>
      <dc:creator>wireless wlc</dc:creator>
      <dc:date>2013-01-27T20:28:56Z</dc:date>
    </item>
    <item>
      <title>Using both WPA2 and Mac Filtering</title>
      <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125321#M25161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you take a screen of your configuration page on this?&amp;nbsp; I'll lab this tomorrow... curious.&amp;nbsp; Where are you setting the mac list at, locally on the wlc or a radius server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2013 02:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125321#M25161</guid>
      <dc:creator>raun.williams</dc:creator>
      <dc:date>2013-01-28T02:20:42Z</dc:date>
    </item>
    <item>
      <title>Using both WPA2 and Mac Filtering</title>
      <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125322#M25162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont have the screenshots with me. The problem is not there once they remove the WLAN and recreate it. But only strange thing is , some clients show up in the monitor&amp;gt;clients list in WLC even though they have only the WPA-PSK configured and NOT in the mac filter list. These clients dont get an IP and not able to communicate though. Maybe its a minor bug, but works as expected.&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 06:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125322#M25162</guid>
      <dc:creator>wireless wlc</dc:creator>
      <dc:date>2013-02-06T06:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Using both WPA2 and Mac Filtering</title>
      <link>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125323#M25163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On 7.2.110.0 I had seen where a client can move from a PSK or other WLAN where they have "authenticated" properly to a MAC Filter WLAN and are allowed access without being in the MAC filter list.&amp;nbsp; This behavior was duped to &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=" rel="nofollow"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=&lt;/A&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCub00341" rel="nofollow" target="_blank"&gt;CSCub00341&lt;/A&gt;&amp;amp;from=summary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It states this is related to NAC, however my original bug submission regarding moving to a MAC Filter WLAN after previously authenticating on another WLAN was duped to this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A "workaround" is to disable Fast SSID change&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This shows fixed in &lt;SPAN style="font-size: 10pt;"&gt;7.3(1.73) / &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;7.4(100.0)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I didn't test this scenario with using "both" MAC Filter and PSK, but as George/Scott have said, you "must" do both, one or the other, or neither to authenticate to the WLAN, however it's possible they have already authenticated to another WLAN and simply "moved" to this WLAN and were authenticated even if they aren't in the MAC Filter list.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It could be some variation of this behavior above.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 15:15:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/using-both-wpa2-and-mac-filtering/m-p/2125323#M25163</guid>
      <dc:creator>David Watkins</dc:creator>
      <dc:date>2013-02-06T15:15:36Z</dc:date>
    </item>
  </channel>
</rss>

