02-07-2024 06:17 PM
i am an IT w 9800 WLC and use 802.1x authentication w ISE.
i set up a test 9100 ap for test purpose. most of the time, i need to make change and test it on this test AP whether my 9800 changes work or not...
bad thing is i work in open office and time, my other colleaugue laptop will pick up this test AP signal and connect to it...
when i down or reboot this AP, their work session got disruption..
is there any easy way just to restrict connections (mac address etc) to this single AP while all other securitys (back to ISE) + wlan settings all remain the same? i do not wanna to mess with all the production settings...
thanks.
02-07-2024 10:40 PM
Get one testing AP for your testing purposes and deploy only the test SSIDs that mimic your prod.
02-07-2024 11:36 PM
Config new SSID but config it as hidden'
Dont broadcast' in this why the clinet dont see it' and only ypu you can enter the ssid name manually see it.
MHM
02-12-2024 04:22 AM
Reduce your AP power to the lowest and keep your test clients very close to your AP.
If that does not help, you have to go with new test SSID rather using production WLANs
HTH
Rasika
*** Pls rate all useful responses ***
02-12-2024 04:26 AM
The main thing is that your test SSID needs to have a different name. You can still use the same profile etc.
Just hiding the SSID won't stop devices from joining if it still has the same name which they'll be probing for already.
02-12-2024 05:55 AM
Tune your Cisco ISE policy so it won't accept any request coming from the AP's radio MAC "Called-Station-ID", or that only authorize your devices on it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide