05-10-2023 05:14 AM
Hello Guys,
Currently in my network setup we have one SSID which is with [WPA2][Auth(802.1X)].
Can i enable MAC filtering on same SSID.
if yes, any impact on currently connected users? Any changes reqired on ISE end policy if MAC filterning enabled only at WLC end?
05-10-2023 05:37 AM
Hello,
Which WLC do you have?
Yes you can use Do1x with Mac filter and yes there will be impact if you do not register all the valid mac address on the network.
This guide is for WLC 9800 but the ISE part must be the same.
05-10-2023 05:44 AM
I am having 5520 WLC.
So are you saying , if i enable mac filtering on SSID with dot1X, so all connected users will impacted if their MAC address is not present on WLC?
My main question is, what is preference
like, first it will prefer mac filtering, but all users mac should be present locally on WLC. Here user whose mac address is present on WLC will get permitted on network.
second, user whose MAC is not preset on WLC, will go for dot1x in ISE for authentication, it that true or MAC addresses of dot1X users also should be present on WLC?
05-10-2023 05:59 AM - edited 05-10-2023 05:59 AM
You are implying that the users on the WLC will be permitted by default because they are connected on the WLC ? They dont.
You need to add them in "SECURITY" > "MAC Filtrering"> "New"
There is no IF /ELSE logic as far as I know. My experience is that if you check the option "Mac Filter" on the WLAN, you better have all your clients properly registered on the Mac Filtering database.
I used to manage an infra with Mac Filter checked and it was a pain in the ass. All the time new mac address coming and I need to add or users going and I had to remove from the databse.
05-10-2023 06:05 AM
Thanks Flavio.
that means better we can do modifications in ISE to check certificate or MAC endpoint whitelisting.
so that it will not require to add all connected user mac address
05-10-2023 06:23 AM
that´s correct.
05-10-2023 05:42 AM
M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide