cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1489
Views
10
Helpful
2
Replies

WLC MAC filtering whitelist behaviour

AkimboJimbo
Level 1
Level 1

Hi,

 

 

I was looking at the configuration of one of our customer networks and it had the mac filtering on on a single SSID with a whitelist permitting that user to use the said SSID.

 

I was wondering what would happen in the following scenario.

Total four SSIDs are in the network, all SSIDs are using WPA2-Personal and only one configured to use mac filtering. We will call the SSID with mac filtering as "A", and others as "B, C, D"

Configure the mac filtering for a particular user (We will call it "User_A") with the type as whitelist and apply it to ANY WLAN instead of a single WLAN, which is the SSID "A".

 

Will the SSIDs B, C, D be applied with the whitelist mac filtering and allow User_A to enter even though they are not configured to use Mac filtering?

Or will User_A only be able to access the SSID A as expected since that SSID is the one with mac filtering configured?

Also, what would happen if the SSIDs A and B both had mac filtering configured with the user User_A and have the whitelist applied to ANY WLAN, will User_A be able to access both WLANs?

 

What is the general behaviour of the whitelist in WLC?

 

Thanks in advance

 

 

1 Accepted Solution

Accepted Solutions

ammahend
VIP Alumni
VIP Alumni

when you whitelist mac address of User_A, you have a choice to whitelist for all SSID or specific SSID.

if you only whitelisted for SSID A, the database will only be validated for SSID A

if you choose any WLAN, then database can be used for SSID B,C or D as well, however, SSID B,C,D still needs to be configure for mac filtering at L2 security for the users to connect.

 

hope this answers your question.

-hope this helps-

View solution in original post

2 Replies 2

ammahend
VIP Alumni
VIP Alumni

when you whitelist mac address of User_A, you have a choice to whitelist for all SSID or specific SSID.

if you only whitelisted for SSID A, the database will only be validated for SSID A

if you choose any WLAN, then database can be used for SSID B,C or D as well, however, SSID B,C,D still needs to be configure for mac filtering at L2 security for the users to connect.

 

hope this answers your question.

-hope this helps-

Hi @ammahend @AkimboJimbo 

I have an issue related this.. my 9800-CL has ben configure for lets say 2 WLAN ssid, WLAN A and WLAN B

Mac xx:x1 whitelisted for WLAN A

Mac xx:x2 whitelisted for WLAN B

All Mac Filtering used different attribute for different WLAN. 

The mac filtering is working.. only mac address specified in mac fitering which can connected to WLAN.

The issue is.. mac xx:x1 can access WLAN B and xx:x2 can access WLAN A.

They are still can do like "crossing" mac filtering. 

This is my thread on cisco forum 

https://community.cisco.com/t5/wireless/9800-cl-17-6-4-mac-filtering-can-access-different-wlan-ssid/m-p/4809395#M254207

 

Thanks and regards

Review Cisco Networking for a $25 gift card