Configuring MAC Registration Lists in the Cloudpath UI

The MAC Registration Lists area of the UI lets you create MAC registrations, and import MAC registration lists or individual MAC addresses into these configurations. MAC Registrations can also be used in a workflow.

Navigate to Configuration > MAC Registration Lists. From here, you can add new MAC registration lists, view current lists, and click the wrench icon next to any list to perform actions on that list. The following screen is an example of the MAC Registrations List main screen where one list called "MAC Registrations" already exists and whose status is enabled for incoming RADIUS MAC Registration-based authentications (described in ).

MAC Registrations Lists Main Screen

Note: If you hover over the status of a MAC registration list with your cursor, the status will also indicate if the list is currently referenced from within a workflow.

Adding a New MAC Registration Configuration

Follow these steps to create a new MAC Registration configuration which you can then use to import MAC addresses.

  1. Click Add MAC Registration List in the upper right of the screen shown above.
  2. In the Create MAC Registrations screen (see the example screens below), configure the values (described after the example screens), then click Save.

    Creating a New MAC Registration Configuration - Screen 1 of 2

    Creating a New MAC Registration Configuration - Screen 2 of 2

    • Display Name: Any descriptive name you want.
    • Description: Optional description of this particular MAC registration configuration.
    • Enabled (RADIUS):
      new for 5.11R2
      This field is enabled by default (but shown as unchecked in the example screen). When a list is enabled for RADIUS, an incoming MAC Registration-based authentication request is considered successful if there is a corresponding valid (not expired, not revoked) MAC Registration (MAC address) entry within the list. If you want to disable this field, uncheck the box; workflows may still use and add MAC addresses to this MAC Registration list even if you disable this option.
      Note: Disabling a list for RADIUS effectively disables the devices with MAC Addresses within the list from authenticating. One reason for doing this could be if you want to build a MAC registration list before enabling it for authentications in a live environment.
    • SSID Regex: SSID to which MAC registered devices are assigned.
      Note: This field is case sensitive. Separate multiple SSIDs by a vertical pipe (|). The default (*) is any SSID that is pointed at the RADIUS server.
    • Expiration Date Basis: The basis for calculating the default validity period for MAC registration.
      Note: A sponsor can override the validity period configured for MAC registration. Cloudpath Enrollment System Sponsored Guest Access Configuration Guide, located on the Support tab, for details.
    • Offset: The number of hours/days/months/etc to be offset from the event date when calculating the registration validity period. If Specified Date is selected, this should be the date in YYYY/MM/DD format.
      Note: This field may be unnecessary and therefore disappear, depending on your selection for Expiration Date Basis.
    • Behavior: Specifies the prompt and redirect settings for the MAC registration configuration. Behavior settings include:
      • Prompt user when MAC is unknown.
      • Always prompt the user.
      • Redirect when MAC is unknown.
      • Always redirect to authenticate user. (This is the default and the most commonly used setting).
      • Skip registration when MAC is unknown.
    • Use the Config Shortcuts buttons to populate the Redirect URL and POST Parameters according to your controller vendor and preferred protocol.
    • Allow Continuation - If checked, the submit-redirect call is processed; if unchecked, the submit- redirect call is ignored.
    • Kill Session - If checked, the user's session is killed as the user is redirected. If returned, the user is forced to start over.
    • RADIUS Attributes (also see the flowchart below):
      Note:
      updated info for 5.11R2 …..
      :
      • Assigned Candidate Policies: A list of policies that have been assigned to this MAC registration list; if no policies have yet been assigned, this is indicated, as in the earlier example screen.
        Note: For these policies to be evaluated, an incoming MAC Registration based authentication must first match the SSID Regex pattern of the List; AND have a valid (not expired, not revoked) MAC Registration(MAC Address) entry within the list.
      • Default Access (No Policy Match): A drop-down where you can select whether to allow a user onto the network even if there is no matching policy for the user. When no policies are assigned, or when policies are assigned but no match is found against any of the policies, the default RADIUS access response will either be accepted or rejected. When the authentication is successful, the RADIUS attributes from the matched policy are sent in the RADIUS reply.
        Note: Once you assign policies (described later) to a MAC registration list, a policies table is included if you edit this screen.
      • updated for 5.11R2
        No Matching MAC Registration RADIUS Behavior: By default, the RADIUS server sends an “Access-Reject” reply if authentication fails. However, you can use the “Access-Accept on No Registration:" feature to send a RADIUS Access-ACCEPT response for authentications to this list without a matching MAC Registration(MAC Address) entry within the list. If you check the“Access-Accept on No Registration:" box, a drop-down list of all configured RADIUS attribute groups appears (see the screen below); select the group you want. In this case, be sure you have already configured the RADIUS attribute group you want to use. With this field enabled and an attribute group selected, the attributes defined in the group are sent along with an “Access-Accept” RADIUS reply.

        RADIUS Attribute Group Down-Down List for Accept-Accept with No MAC Registration Match

        note to self - ADD XREF to RADIUS attr group

    RADIUS Attributes Flowchart

  3. After you click Save, you are returned to a four-tab of the MAC Registration List screen for the list you just configured, as shown in the following example screens:
    New illustration showing 4 tabs

    Four-Tab View for Newly Added Mac Registration List (Top Portion of Screen)

    Four-Tab View for Newly Added Mac Registration List (Lower Portion of Screen)

  4. If you click View All MAC Registration Lists (in the preceding screen though not shown in the illustration), you are returned to the main screen, with the new configuration (MAC Registration-8 in this example) appearing in the list, as shown below:

    MAC Registration Lists Screen After Adding a Second Registration Configuration

Importing a MAC Registration List

Follow these steps to import a MAC registration list into a MAC registration configuration.

  1. From the main MAC Registrations Lists screen, click the wrench icon for the list in which you want to import a MAC address list.
  2. On the ensuing screen, click the MAC Registrations tab. A screen such as the following is invoked:

    MAC Registrations Tab of a MAC Registration List

  3. If you first need a template for adding MAC addresses to an .xls file, click Download Bulk Import Template.
  4. Once you are ready to import the list of MAC addresses to the MAC registration list, click Import.
    Note: If importing from a .csv file, the following date formats are supported: yyyyMMdd, HHmmss, yyyyMMdd HHmm, yyyyMMdd, MM/dd/yyyy HHmmss, MM/dd/yyyy HHmm, MM/dd/yyyy, yyyy-MM-dd HH:mm:ss, yyyy-MM-dd.
  5. Browse to select your MAC address list, then click Continue.
  6. A popup message appears, where you click Continue Import:

    Popup Asking You to Confirm Import of MAC Address List File

  7. The file is imported and the MAC addresses are added to the applicable MAC Registration list.

Importing Individual MAC Addresses

Follow these steps to import individual MAC addresses into a MAC registration configuration.

  1. From the MAC Registrations tab of the desired MAC Registrations List (refer to the example in MAC Registrations Tab of a MAC Registration List), click the Add button in the "MAC Registrations" portion of the screen.
  2. In the popup window, enter the MAC addresses, separated by commas, that you wish to add.
  3. Click Save.
  4. Confirm the import on the ensuing popup window.
    You are returned to the MAC Registrations tab, and there should be a confirmation message at the top, indicating that the MAC addresses have been successfully added. They will also appear at the bottom of that screen.

Removing a MAC Registration Configuration List or Its MAC Addresses

Follow these steps to either remove the MAC addresses from a MAC registration configuration list or to remove both the MAC addresses and the list itself:

  1. Click the Details tab from an open MAC Registration List screen.
  2. Click Edit.
  3. Scroll to the bottom of the screen until you get to the Cleanup area, and click Cleanup to display the options:

    Cleanup Options for MAC Registration Configuration List

    Note: You cannot destroy the entire list if it is currently part of a workflow.
  4. Click on the desired option.
    A Warning popup appears.
  5. If you wish to continue, be sure to check the box to indicate that you "understand the warning," then click Continue.
    You are returned to the Details tab, where you should see a message indicating that your action has taken effect.

Adding and Viewing MAC OUI Wildcards

The MAC OUI Wildcard tab for a MAC registration list lets you add, view, or delete a MAC OUI (Organizationally Unique Identifier) wildcard definitions. MAC OUI wildcards allow for all devices that match the OUI pattern prefix to authenticate via the Mac Registration List without the need for manual entry of individual device MAC addresses.

Follow these steps to add a MAC OUI wildcard to a MAC registration list and view the details:

  1. In the Cloudpath UI, go to Configuration > MAC Registration Lists to view all existing MAC registration lists:

    MAC Registration Lists View

  2. Click the wrench icon for the desired MAC registration list; for example the MAC-Registration-8 entry in the screen above. The four-tab MAC Registration List screen for the list you selected appears. Select the MAC OUI Wildcard tab. The screen below shows the MAC OUI Wildcard tab for the MAC-Registration-8 MAC registration list.

    MAC Registration List Screen with MAC OUI Tab

  3. Click Add. The Add MAC OUI popup window appears.

    Add MAC OUI Popup Window

  4. In the popup window, enter the first six digits of the MAC address (MAC OUI wildcard) that you want to use, and click Save. In the screen below the first six digits of the MAC address entered are A5:B5:C5.

    Entering the MAC OUI address

  5. You are returned to the MAC OUI Wildcard tab for the MAC Registration List. Verify that the A5:B5:C5 MAC OUI has been added to the MAC OUI Wildcard list, as displayed in the following screen.

    Successfully Added MAC OUI Wildcard

  6. Once the MAC OUI wildcard has been succesfully added, you can view details about the MAC OUI wildcard. To view the MAC OUI wildcard details, click the magnifying glass icon next to the MAC OUI wildcard that you want to view. The screen below shows details for the A5:B5:C5 MAC OUI wildcard. All devices with a MAC address where the first six digits contain A5:B5:C5 have been added to the MAC OUI wildcard. Any MAC addresses that are prefixed with this MAC OUI wildcards will be able to self-register to the registration list without the need for individual MAC registrations.

    MAC OUI Wildcard Details

  7. If you want to delete a MAC OUI wildcard from a MAC registration list:, click X next to the MAC OUI wildcard that you want to remove. A popup window appears reminding you that this action does not affect existing MAC Registration lists. Only the MAC OUI wildcard is removed. Click OK. The selected MAC OUI wildcard is removed.