Wireless Access

 View Only
  • 1.  Restricting MAC Addresses on Hospitality APs

    Posted Feb 07, 2025 11:05 AM

    I'm looking for some guidance on managing MAC addresses on our hospitality access points (APs). Specifically, I need to:

    1. Block a MAC Address on an AP Port: We want to block a rogue AP's MAC address if detected on our network. On our wired ports, we achieve this by adding a drop rule to the MAC address table on the switch. Is there a similar method to block a MAC address on the AP or controller, either for all ports on a single AP or across all APs in a group?
    2. Limit Connections to One MAC per Port: We want to prevent switches from being connected to our AP ports by restricting each port to a single MAC address. We use port security to accomplish this on our wired ports. Is there a way to implement this on a hospitality AP?

    Any advice or solutions would be greatly appreciated!



  • 2.  RE: Restricting MAC Addresses on Hospitality APs

    Posted Feb 07, 2025 11:21 AM

    Implement 802.1X or MAC auth for the wired profiles to restrict what can connect.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: Restricting MAC Addresses on Hospitality APs

    Posted Feb 07, 2025 12:36 PM

    So, if I enable MAC auth, would I be able to allow access to all new MACs and then block a MAC later on if needed?  




  • 4.  RE: Restricting MAC Addresses on Hospitality APs

    Posted Feb 07, 2025 12:41 PM

    Assuming the RADIUS server used supports such, yes.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 5.  RE: Restricting MAC Addresses on Hospitality APs

    Posted Feb 07, 2025 12:55 PM

    We are using ClearPass so it should support it.  Thank you!

    Is it possible to limit the number of MACs on a port?  I found documentation for enabling this on an Aruba switch but not for an AP.




  • 6.  RE: Restricting MAC Addresses on Hospitality APs

    Posted Feb 07, 2025 10:33 PM

    AP wired port is handled differently than switch ports, more like a wireless network.  I would recommend experimenting with the setup to see actual behavior and then determine if any other actions are required.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 7.  RE: Restricting MAC Addresses on Hospitality APs

    Posted Feb 08, 2025 03:19 AM

    You cannot limit the number of clients analogous to the switch port. However, you can determine the number of sessions via ClearPass.

    Activate Insight under Server configuration

    You can then query the Active Sessions property in Rolemapping under Authorization:[Insight Repository] and set a corresponding TIPS role. This role can be evaluated under Enforcement.



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACX - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------