Configuring MAC Registration Lists in the Cloudpath UI
Navigate to Configuration > MAC
Registration Lists. From here, you can add new MAC registration lists, view
current lists, and click the
icon next to any list to perform actions on that list.
The following screen is an example of the MAC Registration List main screen
where one list called "MAC Registrations" already exists and the status of which
is
enabled for incoming RADIUS MAC Registration-based authentications (described
in
Creating a New MAC
Registration Configuration - Screen 1 of 2).
Adding a New MAC Registration Configuration
Follow these steps to create a new MAC Registration configuration which you can then use to import MAC addresses.
- Click Add MAC Registration List in the upper right of the MAC Registration Lists screen.
- In the Create MAC
Registrations screen in Creating a New MAC
Registration Configuration - Screen 1 of 2 and Creating a New MAC
Registration Configuration - Screen 2 of 2, configure the values (described after the example
screens), then click Save.
- Display Name: Any descriptive name you want.
- Description: Optional description of this particular MAC registration configuration.
- Enabled
(RADIUS):
new for 5.11R2This field is enabled by default (but shown as unchecked in the example screen). When a list is enabled for RADIUS, an incoming MAC Registration-based authentication request is considered successful if there is a corresponding valid (not expired, not revoked) MAC Registration (MAC address) entry within the list. If you want to disable this field, uncheck the box; workflows may still use and add MAC addresses to this MAC Registration List even if you disable this option.Note: Disabling a list for RADIUS effectively disables the devices with MAC Addresses within the list from authenticating. One reason for doing this could be if you want to build a MAC registration list before enabling it for authentications in a live environment.
- SSID Regex: SSID to
which MAC-registered devices are assigned.
Note: This field is case sensitive. Separate multiple SSIDs by a vertical pipe (|). The default (*) is any SSID that is pointed at the RADIUS server.
- Expiration Date Basis: The basis for calculating the default validity period for MAC registration.
- Offset: The number of hours/days/months to be offset from the event date when calculating the registration validity period. If Specified Date is selected, this should be the date in YYYY/MM/DD format.
- Behavior: Specifies the prompt and redirect settings for the MAC registration configuration. Behavior settings include:
- Use the HTTP Config Shortcuts and HTTPS Config Shortcuts buttons to populate the Redirect URL and POST Parameters according to your controller vendor and preferred protocol.
- Allow Continuation - If checked, the submit-redirect call is processed; if unchecked, the submit-redirect call is ignored.
- Kill Session - If checked, the user's session is terminated as the user is redirected. If returned, the user is forced to start over.
- RADIUS Attributes
(also see the flowchart in RADIUS
Authentication Flowchart):
updated info for 5.11R2 …..
- Assigned Candidate Policies: A list of
policies that have been assigned to this MAC Registration
List; if no policies have yet been assigned, this is clearly
stated on the UI (refer to Creating a New MAC
Registration Configuration - Screen 2 of 2 for an example of the statement).
Note: For these policies to be evaluated, an incoming MAC Registration based authentication must first match the SSID Regex pattern of the List, AND have a valid (not expired, not revoked) MAC Registration (MAC Address) entry within the list.
- Default Access (No Policy Match): A
drop-down where you can select whether to allow a user onto
the network even if there is no matching policy for the
user. When no policies are assigned, or when policies are
assigned but no match is found against any of the policies,
the default RADIUS access response will either be accepted
or rejected. When the authentication is successful, the
RADIUS attributes from the matched policy are sent in the
RADIUS reply.
Note: Once you assign policies to a MAC Registration List, a policies table is included if you edit this screen.
-
updated for 5.11R2No Matching MAC Registration RADIUS Behavior: By default, the RADIUS server sends an “Access-Reject” reply if authentication fails. However, you can use the “Access-Accept on No Registration:" feature to send a RADIUS Access-Accept response for authentications to this list without a matching MAC Registration (MAC Address) entry within the list. If you check the “Access-Accept on No Registration:" box, a drop-down list of all configured RADIUS attribute groups appears (Refer to RADIUS Attribute Group Drop-Down List for Access-Accept with No MAC Registration Match); select the group you want. In this case, be sure you have already configured the RADIUS attribute group you want to use. With this field enabled and an attribute group selected, the attributes defined in the group are sent along with an “Access-Accept” RADIUS reply.note to self - ADD XREF to RADIUS attr group
- Assigned Candidate Policies: A list of
policies that have been assigned to this MAC Registration
List; if no policies have yet been assigned, this is clearly
stated on the UI (refer to Creating a New MAC
Registration Configuration - Screen 2 of 2 for an example of the statement).
RADIUS Authentication Flowchart

MAC Registrations – RADIUS Authentication Logic
Nick's inputsFor each incoming MAC authentication-based RADIUS request, the system selects a MAC Registration List based on conditional logic. Policies associated with the selected MAC Registration List provide the context for the outgoing RADIUS response attributes.
To determine if a MAC Registration List is a match for an incoming RADIUS request, the values from the request must meet both conditions:
- MAC Registration List SSID Regex pattern matches the SSID value of the RADIUS request.
- MAC Registration List contains a MAC Registration entry for the MAC Address of the RADIUS request.
If multiple MAC Registration Lists match both the SSID and MAC Address, then there is a tie:
- To break the tie, the matching lists are sorted by the SSID Regex pattern in character-based, descending order.. After sorting, list(s) at the beginning take priority. With this scheme, specific SSID patterns take priority over match-all wildcard patterns.
- If a tie persists, the MAC Registration List containing the MAC Registration entry that was created most recently takes priority.
If none of the MAC Registration Lists match both the SSID and MAC address, then:
- If one or more MAC Registration List(s) SSID Regex patterns match the requested SSID value, then the RADIUS response follows the No Matching MAC Registration Behavior from the list with the lowest sequence number.
- If the SSID value of the RADIUS request matches none of the listed SSID Regex patterns, then the response is Reject without any additional policies.
- After you click Save, you are returned to a four-tab view of the MAC Registration List screen for the list you just configured. By default, the Details tab is displayed, reflecting the configuration of the new MAC Registration List. Refer to Details Tab View for Newly Added Mac Registration List (Top Portion of Screen) and Details Tab View for Newly Added Mac Registration List (Lower Portion of Screen) for examples of the Details tab.
- If you click View All MAC Registration Lists (in the preceding screen, though not shown in the illustration), you are returned to the main screen, with the new configuration (MAC Registration-8 in this example) appearing in the list, as shown in MAC Registration Lists Screen After Adding a Second Registration Configuration:
Importing MAC Registration Entries to a MAC Registration List
Follow these steps to import a MAC Registration List into a MAC registration configuration.
- From the main MAC
Registrations Lists screen, click the
icon for the list in which you want to import a MAC address list. - On the resulting screen, click the MAC Registrations tab. A screen such as the following is invoked:
- If you first need a template for adding MAC addresses to an .xls file, click Download Bulk Import Template.
- Once you are ready to import the list of MAC addresses to the MAC registration list, click Import.
- Browse to select your MAC address list, then click Continue.
- A pop-up message appears, where you click Continue Import.
- The file is imported and the MAC addresses are added to the applicable MAC Registration list.
Importing Individual MAC Addresses
Follow these steps to import individual MAC addresses into a MAC registration configuration.
- From the MAC Registrations tab of the desired MAC Registrations List (refer to the example in MAC Registrations Tab of a MAC Registration List), click the Add button in the "MAC Registrations" portion of the screen.
- In the pop-up window, enter the MAC addresses, separated by commas, that you wish to add.
- Click Save.
- Confirm the import on the resulting pop-up window.
Removing a MAC Registration Configuration List or Its MAC Addresses
Follow these steps to either remove the MAC addresses from a MAC registration configuration list or to remove both the MAC addresses and the list itself:
- In the Cloudpath UI, go to to view all existing MAC Registration Lists.
- Click the
icon
for the desired MAC Registration List. - Click the Details tab from an open MAC Registration List screen.
- Click Edit.
- Scroll to the bottom of the screen until you get to the Cleanup section, and expand the Cleanup section to display the available options.
- Click on the desired option.
A Warning pop-up appears.
- If you wish to continue, be sure to check the box to indicate that you "understand the warning," then click Continue.
Adding and Viewing MAC OUI Wildcards
The MAC OUI Wildcard tab for a MAC Registration List lets you add, view, or delete a MAC OUI (Organizationally Unique Identifier) wildcard definitions. MAC OUI wildcards allow for all devices that match the OUI pattern prefix to authenticate via the MAC Registration List without the need for manual entry of individual device MAC addresses.
Follow these steps to add a MAC OUI wildcard to a MAC definition and view the details:
- In the Cloudpath UI, go to Configuration > MAC Registration Lists to view all existing MAC registration lists.
- Click the
icon for the desired MAC Registration List; for example, the
MAC-Registration-8 entry in the screen above. The four-tab MAC
Registration List screen for the list you selected appears. Select
the MAC OUI
Wildcard tab. The following screen shows the MAC OUI
Wildcard tab for the MAC-Registration-8 MAC Registration
List.
- Click Add. The Add MAC OUI pop-up window appears.
- In the pop-up window, enter the first six digits of the MAC address (MAC OUI wildcard) that you want to use, and click Save. In the following example screen, the first six digits of the MAC address entered are A5:B5:C5.
- You are returned to the MAC OUI Wildcard tab for the MAC Registration List. Verify that the newly defined MAC OUI Wildcard has been added to the MAC OUI Wildcard list, such as the A5:B5:C5 example displayed in the following screen.
- Once the MAC OUI wildcard
has been successfully added, you can view details about the MAC OUI
wildcard. To view the MAC OUI wildcard details, click the
icon next to the MAC OUI wildcard that you want to view. The following
example screen, shows details for the A5:B5:C5 MAC OUI wildcard. All devices
with a MAC address where the first six digits contain A5:B5:C5 have been
added to the MAC OUI wildcard. Any MAC addresses that are prefixed with this
MAC OUI wildcard will be able to self-register to the registration list
without the need for individual MAC registrations.
- If you want to delete a MAC
OUI wildcard from a MAC Registration List, click the
icon next to the MAC OUI
wildcard that you want to remove. A pop-up window appears reminding you that
this action does not affect existing MAC Registration Lists. Only the MAC
OUI wildcard is removed. Click OK. The selected MAC
OUI wildcard is removed.















