06-10-2011 03:06 AM - edited 07-03-2021 08:18 PM
Hi,
I tried to add some more MACs to our Controllers through the WCS. I hate mac-filtering. We plan on stopping sometime. Three of the Controllers(4402s) are reporting that we have reached the max which appears to be 506.
First, is there anyway to increase this number?
Second, if not, does anybody have any ideas/experience with deleting clients? Should I use reporting to find MACs that haven't been used for sometime and delete them? Is there a better way?
Thanks, Pat.
Solved! Go to Solution.
06-10-2011 03:12 AM
Hi,
First, is there anyway to increase this number?
ANS - No there is no way we can increase it on the WLC.. however we can use ACS to save the the MAC instead of WLC.
Second, if not, does anybody have any ideas/experience with deleting clients? Should I use reporting to find MACs that haven't been used for sometime and delete them? Is there a better way?
ANS - The one that you have mentioned is the better way.. i dont think there is one whic is better than that!!
Lemme know if this answered ur question and please dont forget to rate the usefull posts!!
Regards
Surendra
06-10-2011 03:21 AM
Hi,
If we have cisco ACS.. we can do the MAC filtering and the MAC will be on the ACS not on the WLC>. here is the link to do the same..
http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008084f13b.shtml
Lemme know if this answered ur question and please dont forget to rate the usefull posts!!
Regards
Surendra
06-10-2011 03:12 AM
Hi,
First, is there anyway to increase this number?
ANS - No there is no way we can increase it on the WLC.. however we can use ACS to save the the MAC instead of WLC.
Second, if not, does anybody have any ideas/experience with deleting clients? Should I use reporting to find MACs that haven't been used for sometime and delete them? Is there a better way?
ANS - The one that you have mentioned is the better way.. i dont think there is one whic is better than that!!
Lemme know if this answered ur question and please dont forget to rate the usefull posts!!
Regards
Surendra
06-10-2011 03:17 AM
I don't understand your suggestion:
"ANS - No there is no way we can increase it on the WLC.. however we can use ACS to save the the MAC instead of WLC."
How would I use the ACS? Can I MAC-filter using the TACACS server? Or are you hinting dot1x?
06-10-2011 03:21 AM
Hi,
If we have cisco ACS.. we can do the MAC filtering and the MAC will be on the ACS not on the WLC>. here is the link to do the same..
http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a008084f13b.shtml
Lemme know if this answered ur question and please dont forget to rate the usefull posts!!
Regards
Surendra
06-10-2011 10:33 AM
Surendra,
Do I have to disable the mac-filtering from the controller? I've have followed the instructions for using the ACS for mac-filtering but, it won't allow clients to connect if I configure them only on the ACS.
06-10-2011 08:54 PM
Either we can use WLC database or ACS.. there is no need to configure them on both.. please follow the step by step process from the below link..
lemme know if this answered ur question and please dont forget to rate the usefull posts!!
Regards
Surendra
06-13-2011 03:12 AM
Surendra,
It's not working for me. I followed the instructions but, it is not working. I was wondering if I have to check - Allow AAA Override? But, I would think that if I checked this, it would disassociate all users that were only in the WLC mac-filter database? Don't really know.
Thanks, Pat.
06-13-2011 09:26 AM
Hi,
AAA override is for Dynamic VLAN assignment.. I have this set up in my lab and it just works awesome!!
Regards
Surendra
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide