Showing results for 
Search instead for 
Did you mean: 

How to block/disconnect unwanted clients from Aironet 2800



We have a few Aironet 2800 on our company and 2 networks configured, internal and guests.

Happens that we want to move some internal users to the guest network and, beside asking politely through email, some of them have not switched to guests.

I cannot find documentation neither google search it, to drop those users or maybe block them to use the internal network, through the GUI Cisco interface.

Is there a way to perform this through GUI or only by physically connecting and using the CLI?

*We dont want to change the password to achieve this.

1 Accepted Solution
3 Replies 3

Hi Flavio, thank you for your suggestion.

It seems that the MAC filtering from that article is to add MAC addresses to the wlan which would do but for us there would be much more work involved so, based on that article I was able to find another one to block mac address.

Thank you.

Rich R
VIP Advisor VIP Advisor
VIP Advisor

Remember MAC addresses can easily be spoofed so that is not a secure approach (easily bypassed).

Moreover most modern devices/OS use dynamic (private) MAC address so the MAC can change without the user doing anything.

If you want a secure corporate WLAN you need to use 802.1x with user/device authentication to a radius or other AAA server.

TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's   and   Best Practices for 9800 WLC's
Cisco Wireless compatibility matrix
Field Notice: FN-63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN-72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN-72524 - During Software Upgrade/Downgrade IOS APs Might Remain in Downloading State
     after 4 Dec 2022 Due to Certificate Expiration - Fixed in and latest 9800 IOS-XE releases
     also fixed in (8.5 mainline) and (8.5 IRCM) if you can't upgrade to 8.10
     TAC confirmed that Mobility Express AP TFTP download is not affected so ME still works but see FN-74035 below
Field Notice: FN-70479 Out-Of-The-Box AP Fails to Join WLC or Joins with Single Radio due to Country Mismatch - RMA required
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN-74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
     fixed in and see the field notice for 8.5, Mobility Express and other fixed releases
Check your WLC config with Wireless Config Analyzer using "show tech wireless" output (9800) or "config paging disable" then "show run-config" output (AireOS) and use Wireless Debug Analyzer to analyze your WLC client debugs
Leo Laohoo's list of bugs affecting 2800/3800/4800/1560 APs
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers