Aironet 600 with Mac Filtering and a switch..

How does the Aironet 600 handle Mac Filtering if I were to connect a switch to port 4 on the back ("Secured" network port). Does it authenticate each MAC or does it do somthing similar to how 802.1x with multi-host works, the first mac authenticates and then the port's wide open? My use-case here is a printer at a remote home-office. The printer doesn't have a supplicant in it so I need to use mac filtering. Thanks.

MAC authentication is all I use for my OutStationed workers.  No wifi, just the rlan.  Since the rlan is configured for DHCP only, no IP gets passed until MAC auth occurs.
When Cisco packaged this up, they said 4 is enough..  IF you use an un-managed (non-cisco) switch. 
I had a need for 2 workstations and 2 digiports..  SOP sys a managed switch..  oops.  the switch consumed 2 MAC's right off the top.. 1 for itself and 1 for each vlan.
After enablilng 2 rlans, and configuring a pair on different networks, we discovered that they were bridged in the 602 (or somewhere).
We ended up switching out the 602 for an ASA5505

Similar Messages

  • 802.1x deployment with MAC filtering

    Hi All
    I read "Enhance your 802.1x deployment security with MAC filtering" on NAP blogs with link as below.
    http://blogs.technet.com/nap/archive/2006/09/08/454705.aspx
    I am wondering this tip might not be correct somehow and would like to know how to imployment it correctly.
    First of all, there is only a "Verify Caller ID" field in "dial-in" tab of user properties, not "Calling Station ID". I tried to add MAC address in this field and the authenticaiton works.
    As the description of the tip, we can add multiple MAC addresses in that field but it doesn't work. I tried to use
    "AA-BB-CC-DD-EE-FF | BB-AA-FF-EE-DD-CC" format as multiple MAC address and IAS always responce error with wrong calling staiton ID. Does anyone know how to correctly add multiple MAC addresses in "Verify Caller ID"?
    Thanks

    Hi Sam
    Thank you for your reply.
    I would like to explain why I want to use multiple MAC addresses authenticaiton for an account on a singel AD.
    Genereally, 802.1X can be imploymeted for wired and wireless authenticaiton on many network devices in a company or entriprise. An employee in a company or entriprise is supposed to have only one account but might have multiple devices such as a PC, laptop, or PDA. For the convenience of authenticaiton imployment, I think I should only create an account for that person and make a MAC filtering for any devices he is autrorized to use.
    I had tried the first example you mention but it didn't work. The switch and wireless gateway I used for test only sent one MAC address (calling station  ID) to AD and AD only recognized the first MAC address of all MAC addresses I key in. Of course, your example can be succesful if the device sends multiple MAC addresses simultaneously because AD thinks the those "MAC addresses" is just one string or one calling staiton ID. But that's is not what I want.
    Anyway, I will try the second way you suggest.
    Thanks a lot.

  • I am a new mac user and I switch to mac due to the graphics that it brings. I do website in pc and I heard iweb is the best.NOW i heard that iweb will be discontinue. so what is the best application there for website using MAC OSX lion?

    I am a new mac user and I switch to mac due to the graphics that it brings. I do website in pc and I heard iweb is the best.NOW i heard that iweb will be discontinue. so what is the best application there for website using MAC OSX lion?

    It is now confirmed  that iWeb, and iDVD, has been discontinued by Apple. This is evidenced by the fact that new Macs are shipping with iLife 11 installed but without iWeb and iDVD.
    On June 30, 2012 MobileMe will be shutdown. However, iWeb will still continue to work but without the following:
    Features No Longer Available Once MobileMe is Discontinued:
    ◼ Password protection
    ◼ Blog and photo comments
    ◼ Blog search
    ◼ Hit counter
    ◼ MobileMe Gallery
    All of these features can be replaced with 3rd party options.
    I found that if I published my site to a folder on my hard drive and then uploaded with a 3rd party FTP client subscriptions to slideshows and the RSS feed were broken.  If I published directly from iWeb to the FPT server those two features continued to work correctly.
    There's another problem and that's with iWeb's popup slideshows.  Once the MMe servers are no longer online the popup slideshow buttons will not display their images.
    Click to view full size
    However, Roddy McKay and I have figured out a way to modify existing sites with those slideshows and iWeb itself so that those images will display as expected once MobileMe servers are gone.  How to is described in this tutorial: #26 - How to Modify iWeb So Popup Slideshows Will Work After MobileMe is Discontinued.
    It now appears that the iLife suite of applications offered on disc is now a discontinued product and the remaining supported iApps will only be available thru the App Store from now on. However, the iLife 11 boxed version that is still available at the online Apple Store (Store button at the top of the page) and those still on the shelves of retailers will include iWeb and iDVD. Those two apps were listed in small, gray text on the iLife 11 box that I bought.
    Personally, if I didn't already have a copy I would purchase one to have it for reinstallation purposes if ever needed.
    This might be of some interest to you at this time: Life After MobileMe.
    OT

  • Web Auth with Mac Filtering

    I am trying to setup a scenario where a user logs in via Web Auth and witha  successfull connection the Mac Address is remembered for 7 days. That way if the user connects again during the course of 7 days they aren't required to authenticate via web auth again they just get access. After 7 days they will need to login again through the web auth. Similar scenario to what you see at a Hotel wireless network. Anyone know how I would go about setting up the dyanmic mac filtering and set the timer for 7 days? With that said I want it to be for a single SSID.

    well, it's not possible with just the WLC.
    You can do it, but you need to have a way to pull the MAC address from the webauth page, and insert that into a LDAP db, which you control the age out process in.
    Then on a subsequent visits they get mac-authed instead of having to re-accept the page.
    in the webauth config you would check the On MAC filter failure box.
    HTH,
    Steve
    Please remember to rate useful posts, and mark questions as answered

  • I have itunes set up on a PC with all my music, apps, etc. I want to stop using PC and move my iTunes and files to a Mac I bought and synch my iPhone with the Mac. Can I just synch iPhone with Mac iTunes and will it copy all my stuff onto Mac, or will I h

    I have itunes set up on a PC with all my music, apps, etc. I want to stop using PC and move my iTunes and files to a Mac I bought and synch my iPhone with the Mac. Can I just synch iPhone with Mac iTunes and will it copy all my stuff onto Mac, or will I have to copy files from PC onto Mac?

    Here are some of the links to get you started.
    https://discussions.apple.com/thread/3727530?start=0&tstart=0
    http://support.apple.com/kb/HT4527
    http://www.macworld.com/article/1146958/move_itunes_windows_mac.html

  • SUGGESTION ON BEST External HD to work with Mac Air and Logic - for sample streaming.

    SUGGESTION ON BEST External HD to work with Mac Air and Logic - for sample streaming.

    huge storage, low cost, high quality, very small and portable.
    BEST FOR THE COST, Toshiba "tiny giant" 15mm thick  2TB drive (have several of them, lots of storage in tiny package)    $100
    http://www.amazon.com/Toshiba-Canvio-Connect-Portable-HDTC720XK3C1/dp/B00CGUMS48    /ref=sr_1_3?ie=UTF8&qid=1390020791&sr=8-3&keywords=toshiba+2tb
    best options for the price, and high quality HD:
    Quality 1TB drives are $50 per TB on 3.5" or  $65 per TB on 2.5"
    Perfect 1TB for $68
    http://www.amazon.com/Toshiba-Canvio-Portable-Hard-Drive/dp/B005J7YA3W/ref=sr_1_ 1?ie=UTF8&qid=1379452568&sr=8-1&keywords=1tb+toshiba
    Nice 500gig for $50. ultraslim perfect for use with a notebook
    http://www.amazon.com/Toshiba-Canvio-Portable-External-Drive/dp/B009F1CXI2/ref=s    r_1_1?s=electronics&ie=UTF8&qid=1377642728&sr=1-1&keywords=toshiba+slim+500gb
    *This one is the BEST portable  external HD available that money can buy:
    HGST Touro Mobile 1TB USB 3.0 External Hard Drive $88
    http://www.amazon.com/HGST-Mobile-Portable-External-0S03559/dp/B009GE6JI8/ref=sr    _1_1?ie=UTF8&qid=1383238934&sr=8-1&keywords=HGST+Touro+Mobile+Pro+1TB+USB+3.0+7 2 00+RPM
    Most storage experts agree on the Hitachi 2.5"
    Hitachi is the winner in hard drive reliability survey:
    Hitachi manufacturers the safest and most reliable hard drives, according to the Storelab study. Of the hundreds of Hitachi hard drives received, not a single one had failed due to manufacturing or design errors. Adding the highest average lifespans and the best relationship between failures and market share, Hitachi can be regarded as the winner.

  • Which sony HD camcorder best matches with Mac OS and its software?

    HI. Everyone. Which sony HD camcorder best matches with Mac OS and its software?
    Thanks.

    There may be a better forum to ask this question in -- not all Keynote users have Sony HD camcorders.

  • I'm trying to set up Continuity with mac mini and iPhone 5s and not working

    I'm trying to set up Continuity with mac mini and iPhone 5s and not working, bluetooth not pairing

    Your Mini is not supported.
    Connect your iPhone, iPad, iPod touch, and Mac using Continuity

  • Bootcamp setup with Mac OS and WinXP; now what to use Ghost to image

    We have successfully taken a Mac and setup bootcamp with Mac OS and Windows XP; however, we have another 50 Mac's to deploy. It was our thought we could use Ghost to image the initial system and deploy to all others. However, in our attempts Ghost is only seeing the Mac side.
    Has anyone does this? Is there a way to get it to pick it all up? or do we have to manually install all 50 Mac's?

    jjoe141 wrote:
    I'm hearing with any of these tools we could image the Mac side, then do bootcamp and manually install WinXP OS/software on each system.
    If you use SuperDuper and your target drive is larger than your HD, you can use a block clone which will include everything on your internal drive including XP.

  • Dont connect with mac AppStore and iTunes store, but Safari and other apps is working good. pleeeease help.(OS X 10.8.5)

    Dont connect with mac AppStore and iTunes store, but Safari and other apps is working good. pleeeease help.(OS X 10.8.5)

    Error message?

  • WLC 5760 multiple SSIDs with MAC filtering

    Dear All,
    I am implementing a wireless network with 5760 WLCs. The client requires a few SSIDs with MAC-based authentication. So I created different MAC filters using the commands "aaa authorization network MAC_FILTER01 local", "aaa authorization network MAC_FILTER02 local" etc
    These filters are bound to different SSIDs using the commands "mac-filtering MAC_FILTER01" "mac-filtering MAC_FILTER02" etc. and users are added to their required MAC filters using the commands "username <mac-address> mac aaa attribute list MAC_FILTER01", "username <mac-address> mac aaa attribute list MAC_FILTER02" etc.
    Now I am facing a serious issue - users belonging to any one MAC filter can connect to the all SSIDs. It seems like the MAC addresses added to the controller under different filter names are going to a common database, thereby providing access to users to all SSIDs irrespective of their MAC filter.
    Is it a limitation of local database of 5760? Has anyone faced the same issue? How can I implement independent MAC filters bound to different SSIDs?
    Thanks,
    Arun John

    Hi Arun,
    this feature currently does not exist on the  5760. it is due to release in one of the MR's of 3.6
    -Joseph

  • PEAP authentication with MAC filtering

    Hi,
    I have an SSID, which required mac filtering as first level of security and Radius authentication also. I have done necessary configuration in  ACS and WLC. In ACS, the rule for MAC filtering is taking a hit, but the users are not asked for credentials. The wireless association also fails. The mac addresses are saved in End station filter on ACS. 
    Attached document has the complete configuration which I performed. Please let me know what I am missing here. Thank you.
    Regards,
    Madhan kumar G

    Hi,
    as per maldehne you have to play with the service type.
    check this discussion: http://goo.gl/R9E8ae
    To the authentication policy you have to add a 'service type' attributes and check based on that attribute.
    based on maldehne as per the past discussion the service type value in the rule condition should be:
    For MAC filtering: value should be:  call check
    For 802.1x: value should be : Framed
    Note that the MAC filter rule should come first.
    Hope this helps.
    Regards,
    Amjad

  • WLC 4402 Web Authentication, Mac Filtering and Layer 2 Seciruty

    Hi All,
    I have configured web authentication and Mac filtering on WLC 4402 for my wireless network and its working fine. I wants to configure layer 2 security for the same Wireless network without pre shared key. Could you please advice how to configure layer 2 security with web authentication withour preshare key.
    Is there any security issue with web authentication and Mac FIltering only? My concern in my wireless network shows open.
    Thanks,
    Kashif

    Hi,
    if you have a ACS, then you can do Web auth Splash page!!! Please refer to the below doc!!
    http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080956185.shtml
    Lemme know if this answered ur question!!
    Regards
    Surendra

  • Problem with Mac mini and HP w2207h

    I have a new Mac mini and a HP w2207h screen. I have a problem with the resolution. The screen wants to be on 1680x1050, but when i turn that mode on, the screen is just blinking and you can't see anything. so i have to use the 1080p modus. But it's kind of blury. Can anyone help? Does apple has some kind of support mail??

    Don't waste your time or money on the adaptors. I have a hp 2207h and I tried th dvi to hdmi and the dvi to vga, neither work, I still don't have a working monitor. Waited on the phone for tech support for 30 minutes. Then got a total line of crap.
    This monitor works flawlessly with my comcast motorola hd cable box, with my sony dvd player, with my toshiba laptop, with my hp computer. But will not work with a mac mini... The only logical reason given the wide varity of equipment it will work on, is that apple does not support HDMI standards, if they did, it would work.
    The apple does work on my 40 in tv. But thats not where I want it. So, this is useless to me. And after the line of crap I got from tech support, I'm thinking about quiting apple all together.
    This ***, I was really excited about my first apple computer. Now after 4 hours, and nothing but frustration and no support at all from apple, I'm thinking about giving up and sticking with PC's from here on out. Worst experiance ever.
    I may even switch to android and chuck my 4...

  • Ideal network to share 2TB iTunes library with mac mini and iMacs by wifi?

    Greetings,
    Just made the move from pc to apple world. First time poster. Please feel free to suggest if this topic is better suited in another area.
    I am looking for an ideal means of sharing my music library (+/- 1.5TB size) from my mac mini with my 2 kids iMacs.
    The mac mini has an internal 80GB SSD and 4 GB RAM. It connects via ethernet to my Netgear WNDR 3700 wifi a/b/n router which connects to a Docsis 3 modem. Speed and signal strength is great.
    My music library is currently backed up on a Seagate USB desktop HDD. My interim plan is to use USB to connect it to the mini. Long term plan is to migrate to a NAS system.
    The kids iMacs (1x 2006 model with core duo and 1 x 20008 with core 2 duo) both run snow leopard 10.6.3 and access wifi signals for internet. Wifi signals ~16-20 Mbps strength.
    Is there prefered method to share the music library with the kids by wifi? Only one way? do I need to add airport devices, or? It would be extremely difficult to provide ethernet to their rooms.
    Thanks
    Kenreau

    kenreau wrote:
    It would be extremely difficult to provide ethernet to their rooms.
    have you consider *powerline adapters* _*such as these*_
    here's an interesting read on the subject.
    JGG

Maybe you are looking for

  • What chair stand for and how to use it ?

    I cannot find any explanation about "chair" and "group" in lightning, when to use them, and what difference there is between chair and required or optional attendee. Moreover if I send an appointment to a list, do I have to use chair and individual o

  • How to create a Email Notification in SRM5.0 ?

    Dear SRM Experts, This is my requirement: Requirement: If Delivery date for a PO is approaching, system should send notification E-mails to approvers and PO initiators. Program execution and dates for notifications will be affiliate specific. Each af

  • Mail messages missing after copying to new folder

    I am recovering some email messages and have imported the mbox into a new folder. It contains 8860 messages. When I copy these messages to the inbox, about 750 messages do not copy over. There is no warning that the file copy is incomplete. Also If I

  • Hand icon on screen

    Hi! I have Windows XP on my computer. Today when I opened my Illustrator CS3, all I can get is this little hand icon. I cannot switch to another tool. I don't know if I happened to hit something accidentally, or if there is something wrong with the h

  • How do I save my bookmarks in Mavericks

    How do I save my bookmarks in Mavericks & how do I reinsert them after a reinstall?