Wireless Access

 View Only
last person joined: 14 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

Aruba OS 8 how to setup Mac filtering ?

This thread has been viewed 64 times
  • 1.  Aruba OS 8 how to setup Mac filtering ?

    Posted Mar 23, 2023 08:34 AM

    Can we setup   Mac filtering  on Aruba 7010 with OS 8.6 ?

    Only allow the user in the MAC white list ?



  • 2.  RE: Aruba OS 8 how to setup Mac filtering ?

    MVP EXPERT
    Posted Mar 23, 2023 12:12 PM

    Yes, there is a few ways to do it depending on your authentication source. 

    MAC Based Authentication




  • 3.  RE: Aruba OS 8 how to setup Mac filtering ?

    Posted Mar 23, 2023 08:40 PM

    Hi Syme,

    Thanks for your reply .My thought is using WPA2 for authentication ,but only allow the users on the MAC white list  .

    Seems MAC authentication can't  archieve this goal .




  • 4.  RE: Aruba OS 8 how to setup Mac filtering ?

    MVP
    Posted Mar 24, 2023 08:06 AM

    Do you mean WPA2-Personal (preshared key)?  That is designed to be simple, for home use. WPA-Enterprise is designed for more complex situations. There may be ways to achieve what you wish but that would be outside the anticipated uses of that standard.



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 5.  RE: Aruba OS 8 how to setup Mac filtering ?

    Posted Mar 24, 2023 07:18 AM

    You can create a user rule. Base on the mac address you can drop it to a user role or a vlan. Make the  vlan of the SSID a blackhole (VLAN with no access)  so that if a device with the mac address that is not listed in the user rule will not be able to get to anywhere even if they know the preshared key. 




  • 6.  RE: Aruba OS 8 how to setup Mac filtering ?

    Posted Mar 24, 2023 11:40 AM

    Do you want to whitelist every MAC address? That means create a user for each MAC address?
    You can solve this with the help of the internal authentication server. In the used AAA profile you have to create MAC Authentication Profile under "MAC Authentication", under "MAC Authentication Server Group" you have to select the "internal" server.

    In the internal server you can create one user per MAC address. You can find the internal server under Configuration/authentication/Auth Servers.

    With each WLAN connection the internal server is requested, if the MAC-Address-User exists the aruba user role configured by you is assigned to the device. If  not the device remains in the initial role from the AAA profile.



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACA - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 7.  RE: Aruba OS 8 how to setup Mac filtering ?

    Posted Mar 25, 2023 07:56 AM

    My configuration as below ,But seems user can access the WLAN did not need to add to internal user 




  • 8.  RE: Aruba OS 8 how to setup Mac filtering ?

    Posted Mar 25, 2023 10:06 AM

    Hi, what is the initial role in the AAA profile? since the ssid is/was PSK, the role is, probably, authenticated already and you need to change to logon (something that doesn't have access to the network until is authenticated) and then, the device will get the role configured in the internal database for that mac-add.

    If you get this working and wants to assign a different role let us know and we can continue. 

    I hope this helps




  • 9.  RE: Aruba OS 8 how to setup Mac filtering ?

    Posted Mar 26, 2023 08:49 PM

    Hi Lord,

    The default rols is aready logon,and seems un changeable. 




  • 10.  RE: Aruba OS 8 how to setup Mac filtering ?

    Posted Mar 27, 2023 08:49 AM

    Hi, can you show what is configured in AAA profiles - Teset_aaa as the initial and default roles? Click on Test_aaa when you are on the profiles page.




  • 11.  RE: Aruba OS 8 how to setup Mac filtering ?

    Posted Mar 27, 2023 08:58 AM

    See below screen. 




  • 12.  RE: Aruba OS 8 how to setup Mac filtering ?

    Posted Mar 25, 2023 06:04 PM

    So with the aruba wifi with a psk-ssid the device remains associated with the wifi when the mac-auth fails. Through mac-auth the postauthenticated aruba user role can be set.

    If mac-auth fails, the device remains in the initial role. You have to set the initial role to login or deny-access. Or create a custom role that does not enable network traffic. Then the device is associated with the WLAN, but cannot reach the network if there is no account for the mac-address.



    ------------------------------
    Regards,

    Waldemar
    ACCX # 1377, ACEP, ACA - Network Security
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------