02-20-2014 02:33 PM - edited 07-05-2021 12:14 AM
I have AP's in Flexconnect Mode doing local switching, central auth. For a particular WLAN, we are using mac-filtering. When creating the local mac filter, should we select none under interface name where you would normally map the interface for the mac-address entry since the clients are local switched? Or does this matter?
02-20-2014 03:48 PM
Mac-filtering isn't supported on FlexConnect local switching, only on central switching and local mode AP's.
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
02-20-2014 03:49 PM
Here is a link:
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
02-20-2014 04:00 PM
Thanks Scott. Please correct me if I'm wrong, but according to that doc Mac filtering is supported with flexconnect local switching, not local auth. Am I reading this incorrectly?
Sent from Cisco Technical Support iPhone App
02-20-2014 04:07 PM
Yes that is correct.... so keep that in mind if the ap's goes into stand alone. Mac-filtering is done the same way as local mode AP's.... you enter the mac address and the choose the wlan... interface doesn't matter for flexconnect.
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
02-20-2014 04:09 PM
What is the purpose you want to use mac-filtering?
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
02-20-2014 04:18 PM
It has to do with these particular clients and the lack of supporting 802.1X. I understand mac-filtering is not very secure.
Although it appears to be working, I had my doubts because the clients were just showing 0.0.0.0 for ip address. We have the "learn client IP address checked" under the wlan, but I cannot see the IP address.
02-20-2014 04:23 PM
Yeah.... there are limitations to what the WLC has visibility to.... only when traffic comes back to the WLC, will the WLC have that information. Take a look at the client statistics from the monitor tab and compare that to a client that is connected to a local mode AP or an ssid that is centrally switched. As long as you only see the clients you allow on the WLAN, then your good.
Thanks,
Scott
*****Help out other by using the rating system and marking answered questions as "Answered"*****
03-14-2014 09:26 AM
I'm also having trouible applying MAC Filtering to a locally switched/centrally authourised WLAN
We are using WPA2 with dot1x AKM. It works fine until I enable MAC Filtering
In the MAC Filter I have tried using None/management/<Dynamic Interface> and none of these work
Is there a chance the AP is using local auth even though it can see the WLCs?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide