07-13-2015 03:14 AM - edited 07-05-2021 03:33 AM
Hi,
We have WPA2-PSK configured on network but would also like to implement MAC filtering in order to restrict mobile devices from being connected to network.
WPA-Enterprise is the best to use but it will require Radius to be configured with EAP
Is it possible to use MAC address configured locally on AP from where users get autheticated
07-13-2015 11:03 PM
I have 2602/ 2702 AP's.
All the laptops are connected to them except the ones with Ralink RT3290 802.11bgn Wi-Fi Adapter they are connected in limited mode or wireless is not shown wifi list.
tried to manually add the network but no success
this was working fine with WEP until i moved to WPA2-PSK with AES encryption
commands used on AP
encryption mode ciphers aes-ccm tkip
dot11 SSID Gotcha
auth key-management wpa ver 2
wpa-psk ascii Abf78d99a0
07-21-2015 09:55 PM
Is this undo able or something else
07-22-2015 04:24 AM
Hi
Change as per below and try again:
encryption mode ciphers aes-ccm tkip -->Remove this
encryption mode ciphers aes-ccm
dot11 SSID Gotcha
auth key-management wpa ver 2
wpa-psk ascii Abf78d99a0
Regards
Don't forget to rate helpful posts
07-23-2015 03:10 AM
07-27-2015 03:20 AM
Sandeep
Any update on this
07-22-2015 05:25 AM
I never faced this kind of scenario but at least you can give a try...
Check this out: https://supportforums.cisco.com/discussion/11265661/cisco-aironet-ap1142n-configuration-wpav2-psk-local-mac-auth-only
Regards
Don't forget to rate helpful posts
07-22-2015 05:43 AM
check below link but it will be hectic if you have multiple MAC address like 80-100
https://supportforums.cisco.com/discussion/9713856/wpa-psk-and-mac-filtering
One more option is to implement EAP-FAST
http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/116580-configure-eapfast-00.html
Guide me which one is best
07-22-2015 06:07 AM
Of-course 1st option is very difficult to implement and i will not recommend.
yes you can try to implement EAP-FAST.
here is my post on it:
https://rscciew.wordpress.com/2014/07/24/autonomous-ap-with-local-radius-server-eap-fast/
Reagrds
Don't forget to rate helpful posts
07-22-2015 06:24 AM
correct me if I am wrong,
Do i have to install Cisco Anyconnect Client on all the PC's if I configure EAP-FAST
Since the its mentioned in your post but not in below link (if its mandatory)
http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/116580-configure-eapfast-00.html
07-27-2015 03:15 AM
@Sandeep
Any comment
07-27-2015 03:41 AM
No its not mandatory, I don't think you need Any-connect on each client computer.
Regards
07-28-2015 02:50 AM
Than how will the user created under Radius Server Local be used or it will prompt for User/PWD after entering the WPA2 Key
We have some MAC OSx's which also needs access over the network configuring EAP-Fast
Secondly, we need to restrict Smartphones /Tablets from accessing network which is not possible with EAP-Fast. So have to move to PEAP or EAP-TLS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide