Configuring a Cisco Controller for MAC Registration

You must have a RADIUS server defined in the Cisco WLC. From the WLANs > Edit window, define the RADIUS server in the Security > Radius Authentication window and Enable the RADIUS server.
  1. On the wireless controller, go to the WLANs tab and select the WLAN for MAC registration.
  2. Select the General tab. In the Interface/Interface Group field, select the interface to which the WLAN is mapped.
  3. Select Security > Layer 2 tab.

    Layer 2 Security

  4. In the Layer 2 Security section:
    • Select NONE for an open SSID.
    • Select WPA+WPA2 +AuthKeyMgmt = PSK for a PSK SSID.
  5. Enable Mac Filtering. This enables MAC authentication for the WLAN.
  6. Layer 3 Settings:
    • Layer 2 Mac Filtering - Select to filter clients by MAC address. Locally configure clients by MAC address in the MAC Filters > New page. Otherwise, configure the clients on a RADIUS server.
    • When using Layer 2 Mac Filtering: Web Policy - On MAC Filter failure - Enables web authentication MAC filter failures.

      Layer 3 Settings when Using Layer 2 Mac Filtering

    • When NOT using Layer 2 Mac Filtering: Web Policy - Authentication - If you select this option, the user is prompted for username and password while connecting the client to the wireless network.

      Layer 3 Settings when Not Using Layer 2 Mac Filtering

  7. Select the Security > AAA Servers tab. In the Authentication Servers section, select the RADIUS server that will be used for MAC authentication.
    Note: If you are using Cloudpath as a RADIUS server, define the ES RADIUS server in the Cisco WLC in the Security > Radius Authentication window.

    Select RADIUS Server

  8. Apply changes.
The wireless controller is configured for MAC registration against the RADIUS server.