cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
348
Views
1
Helpful
5
Replies

Catalyst WLC 9800 configuration for MAC white list

vahitalp
Level 1
Level 1

Hi all,

I currently configure wlc9800 with 4 ssid on it. In one of the wlan I use radius server for domain users to authenticate but I need to restrict them to connect only with their workstation laptops or tablets. I have all wlan MAC addresses available and need a Mac white list to allow the connection request before even trying to use their domain username and passwords. 
can anyone please assist me with this?

5 Replies 5

marce1000
VIP
VIP

 

  - Is it worth the effort  ? Modern devices can easily change ; use random and or allowed mac addresses ; it's probably better to stick to the stronger authentication schemes such as username and password (only).

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Hi, 
yes i understand what you mean but in one of our WLAN we need to make sure that users just use their work laptop and not to be able to login to our network by any other devices.

- For company devices , you can for instance a mandatory supplicant.
Together with Cisco ISE additional policies and checks can then be enforced,

M.


-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '


@vahitalp wrote:
but I need to restrict them to connect only with their workstation laptops or tablets.

So restrict only to laptops OR tablets.  

Rich R
VIP
VIP

If they're domain based laptops then you can install certificates and use the certificates to authenticate the devices.  Non corporate devices will not have the certificates and therefore will not be able to authenticate.
https://howiwifi.com/2020/04/08/cisco-9800-802-1x-eap-tls-using-windows-server-ca-and-nps/

And as the others have said MAC addresses can change so filtering on MAC is just a waste of time.

Review Cisco Networking for a $25 gift card