You cannot limit the number of clients analogous to the switch port. However, you can determine the number of sessions via ClearPass.
Activate Insight under Server configuration

You can then query the Active Sessions
property in Rolemapping under Authorization:[Insight Repository]
and set a corresponding TIPS role. This role can be evaluated under Enforcement.

------------------------------
Regards,
Waldemar
ACCX # 1377, ACEP, ACX - Network Security
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------
Original Message:
Sent: Feb 07, 2025 10:33 PM
From: chulcher
Subject: Restricting MAC Addresses on Hospitality APs
AP wired port is handled differently than switch ports, more like a wireless network. I would recommend experimenting with the setup to see actual behavior and then determine if any other actions are required.
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: Feb 07, 2025 12:54 PM
From: bwoodroof
Subject: Restricting MAC Addresses on Hospitality APs
We are using ClearPass so it should support it. Thank you!
Is it possible to limit the number of MACs on a port? I found documentation for enabling this on an Aruba switch but not for an AP.
Original Message:
Sent: Feb 07, 2025 12:41 PM
From: chulcher
Subject: Restricting MAC Addresses on Hospitality APs
Assuming the RADIUS server used supports such, yes.
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: Feb 07, 2025 12:35 PM
From: bwoodroof
Subject: Restricting MAC Addresses on Hospitality APs
So, if I enable MAC auth, would I be able to allow access to all new MACs and then block a MAC later on if needed?
Original Message:
Sent: Feb 07, 2025 11:20 AM
From: chulcher
Subject: Restricting MAC Addresses on Hospitality APs
Implement 802.1X or MAC auth for the wired profiles to restrict what can connect.
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: Feb 07, 2025 11:04 AM
From: bwoodroof
Subject: Restricting MAC Addresses on Hospitality APs
I'm looking for some guidance on managing MAC addresses on our hospitality access points (APs). Specifically, I need to:
- Block a MAC Address on an AP Port: We want to block a rogue AP's MAC address if detected on our network. On our wired ports, we achieve this by adding a drop rule to the MAC address table on the switch. Is there a similar method to block a MAC address on the AP or controller, either for all ports on a single AP or across all APs in a group?
- Limit Connections to One MAC per Port: We want to prevent switches from being connected to our AP ports by restricting each port to a single MAC address. We use port security to accomplish this on our wired ports. Is there a way to implement this on a hospitality AP?
Any advice or solutions would be greatly appreciated!