cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
696
Views
10
Helpful
2
Replies

ISE CWA MAC spoof

ozgguler
Cisco Employee
Cisco Employee

Hi All

 

Is there any way to prevent Mac spoofing with ISE CWA guest access by cookies etc? Concern: If someone learns an authenticated guest's MAC address, he can spoof this MAC and connect to the SSID without authentication before session timeout.

Do we have a solution for this with ISE CWA? 

2 Accepted Solutions

Accepted Solutions

gbekmezi-DD
Level 5
Level 5
This is a known limitation with anything MAC address based. If you are very concerned, you can require authentication every time a session is started instead of letting an endpoint on the network because it is in a particular endpoint identity group.

View solution in original post

Right, this is open guest network ☺ not really secure as it is.

If that’s a concern then don’t remember the MAC address and require login everytime. Or implement wpa-psk at a minimum

View solution in original post

2 Replies 2

gbekmezi-DD
Level 5
Level 5
This is a known limitation with anything MAC address based. If you are very concerned, you can require authentication every time a session is started instead of letting an endpoint on the network because it is in a particular endpoint identity group.

Right, this is open guest network ☺ not really secure as it is.

If that’s a concern then don’t remember the MAC address and require login everytime. Or implement wpa-psk at a minimum