01-02-2021 02:48 AM - edited 07-05-2021 12:57 PM
Hi, Everyone!
A cisco AP can be configured as LWAP or Standalone. Respectively, access or trunk to the SWA (layer2 Access Switch)
For an ex: is it recommanded and possible to configure #Port-security max-addr on the SWA port. Whethere access or trunk?
NB : The network can be wlan[known users number]. or guest_wlan[unknown users number] !
01-02-2021 05:12 AM
Personally, I would not use - since we do not know the number of users connects to AP. but good to have some Limitations to configure. but bare in mind in case of more MAC address come in security the action takes place depends on what you like to do.
here is some reference document :
https://cammyd.com/cisco-port-security-settings-and-wireless-access-points/
01-04-2021 05:48 AM - edited 01-04-2021 05:49 AM
Dear Sir,
I agree totally with you, but is there another way to prevent #Mac_Flooding_Attack in the wireless networks without using port-security!
Cordially!
01-02-2021 05:40 AM
local or central mode?
01-04-2021 05:53 AM
Hi Sir!
Im Sorry, i did not get your question!
Do you mean AP standalone || WLC architecture based!
Cordialy!
01-05-2021 11:45 AM
If you’re using WLC and If the AP in local mode or FlexConnect central switching then you don’t need to worry about the MAC addresses because the switchport will show only one MAC which is the AP Eth MAC Address because the AP will tunnel all the traffic from all connected clients to the WLC.
01-14-2021 04:00 AM
Ok, and what about the Standalone based architecture ?
01-14-2021 08:50 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide