I assume you have created the WLAN so you will have to configure at least the following:
-MAC authentication profile (Config - Authentication - L2 Authentication)
-MAC authentication server group (you can use the default)
-Captive portal profile (Config - Authentication - L3 Authentication)
-A user-role (Config - Access Control - User role): Add the logon-control and captiveportal policies to this role and assign the captive portal profile to it.
Find the AAA profile which is used by this virtual AP profile and assign the MAC profiles to it. Choose the created user role as the "MAC Authentication Default Role" in the AAA profile.
Add the MAC addresses to the internal DB:
(this is from user guide)
Navigate to the Configuration > Security > Authentication > Servers page.
Select Internal DB.
Click Add User in the Users section. The user configuration page displays.
For User Name and Password, enter the MAC address for the client. Use the format specified by the Delimiter parameter in the MAC Authentication profile. For example, if the MAC Authentication profile specifies the default delimiter (none), enter MAC addresses in the format xxxxxxxxxxxx.
Click Enabled to activate this entry on creation.
Click Apply to apply the configuration.
After this your network should work as you expected.
You can find detailed step-by-step guide on each section in the user guide.