Configuring MAC Registration Lists in the Cloudpath UI

The MAC Registration Lists area of the UI lets you create MAC registrations, and import MAC registration lists or individual MAC addresses into these configurations. MAC Registrations can also be used in a workflow.

Navigate to Configuration > MAC Registration Lists. From here, you can add new MAC registration lists, view current lists, and click the icon next to any list to perform actions on that list. The following screen is an example of the MAC Registration List main screen where one list called "MAC Registrations" already exists and the status of which is enabled for incoming RADIUS MAC Registration-based authentications (described in Creating a New MAC Registration Configuration - Screen 1 of 2).

MAC Registration Lists Main Screen

Note: If you hover over the status of a MAC registration list with your cursor, the status will also indicate if the list is currently referenced from within a workflow.

Adding a New MAC Registration Configuration

Follow these steps to create a new MAC Registration configuration which you can then use to import MAC addresses.

  1. Click Add MAC Registration List in the upper right of the MAC Registration Lists screen.
  2. In the Create MAC Registrations screen in Creating a New MAC Registration Configuration - Screen 1 of 2 and Creating a New MAC Registration Configuration - Screen 2 of 2, configure the values (described after the example screens), then click Save.

    Creating a New MAC Registration Configuration - Screen 1 of 2

    Creating a New MAC Registration Configuration - Screen 2 of 2

    • Display Name: Any descriptive name you want.
    • Description: Optional description of this particular MAC registration configuration.
    • Enabled (RADIUS):
      new for 5.11R2
      This field is enabled by default (but shown as unchecked in the example screen). When a list is enabled for RADIUS, an incoming MAC Registration-based authentication request is considered successful if there is a corresponding valid (not expired, not revoked) MAC Registration (MAC address) entry within the list. If you want to disable this field, uncheck the box; workflows may still use and add MAC addresses to this MAC Registration List even if you disable this option.
      Note: Disabling a list for RADIUS effectively disables the devices with MAC Addresses within the list from authenticating. One reason for doing this could be if you want to build a MAC registration list before enabling it for authentications in a live environment.
    • SSID Regex: SSID to which MAC-registered devices are assigned.
      Note: This field is case sensitive. Separate multiple SSIDs by a vertical pipe (|). The default (*) is any SSID that is pointed at the RADIUS server.
    • Expiration Date Basis: The basis for calculating the default validity period for MAC registration.
      Note: A sponsor can override the validity period configured for MAC registration. Refer to the Cloudpath Enrollment System Sponsored Guest Access Configuration Guide, located on the Support tab, for details.
    • Offset: The number of hours/days/months to be offset from the event date when calculating the registration validity period. If Specified Date is selected, this should be the date in YYYY/MM/DD format.
      Note: This field may be unnecessary and therefore disappear, depending on your selection for Expiration Date Basis.
    • Behavior: Specifies the prompt and redirect settings for the MAC registration configuration. Behavior settings include:
      • Prompt user when MAC is unknown
      • Always prompt the user
      • Redirect when MAC is unknown
      • Always redirect to authenticate user (This is the default and the most commonly used setting)
      • Skip registration when MAC is unknown
    • Use the HTTP Config Shortcuts and HTTPS Config Shortcuts buttons to populate the Redirect URL and POST Parameters according to your controller vendor and preferred protocol.
    • Allow Continuation - If checked, the submit-redirect call is processed; if unchecked, the submit-redirect call is ignored.
    • Kill Session - If checked, the user's session is terminated as the user is redirected. If returned, the user is forced to start over.
    • RADIUS Attributes (also see the flowchart in RADIUS Authentication Flowchart):
      updated info for 5.11R2 …..
      • Assigned Candidate Policies: A list of policies that have been assigned to this MAC Registration List; if no policies have yet been assigned, this is clearly stated on the UI (refer to Creating a New MAC Registration Configuration - Screen 2 of 2 for an example of the statement).
        Note: For these policies to be evaluated, an incoming MAC Registration based authentication must first match the SSID Regex pattern of the List, AND have a valid (not expired, not revoked) MAC Registration (MAC Address) entry within the list.
      • Default Access (No Policy Match): A drop-down where you can select whether to allow a user onto the network even if there is no matching policy for the user. When no policies are assigned, or when policies are assigned but no match is found against any of the policies, the default RADIUS access response will either be accepted or rejected. When the authentication is successful, the RADIUS attributes from the matched policy are sent in the RADIUS reply.
        Note: Once you assign policies to a MAC Registration List, a policies table is included if you edit this screen.
      • updated for 5.11R2
        No Matching MAC Registration RADIUS Behavior: By default, the RADIUS server sends an “Access-Reject” reply if authentication fails. However, you can use the “Access-Accept on No Registration:" feature to send a RADIUS Access-Accept response for authentications to this list without a matching MAC Registration (MAC Address) entry within the list. If you check the “Access-Accept on No Registration:" box, a drop-down list of all configured RADIUS attribute groups appears (Refer to RADIUS Attribute Group Drop-Down List for Access-Accept with No MAC Registration Match); select the group you want. In this case, be sure you have already configured the RADIUS attribute group you want to use. With this field enabled and an attribute group selected, the attributes defined in the group are sent along with an “Access-Accept” RADIUS reply.

        RADIUS Attribute Group Drop-Down List for Access-Accept with No MAC Registration Match

        note to self - ADD XREF to RADIUS attr group

    RADIUS Authentication Flowchart

    MAC Registrations – RADIUS Authentication Logic

    Nick's inputs

    For each incoming MAC authentication-based RADIUS request, the system selects a MAC Registration List based on conditional logic. Policies associated with the selected MAC Registration List provide the context for the outgoing RADIUS response attributes.

    To determine if a MAC Registration List is a match for an incoming RADIUS request, the values from the request must meet both conditions:

    • MAC Registration List SSID Regex pattern matches the SSID value of the RADIUS request.
    • MAC Registration List contains a MAC Registration entry for the MAC Address of the RADIUS request.

    If multiple MAC Registration Lists match both the SSID and MAC Address, then there is a tie:

    • To break the tie, the matching lists are sorted by the SSID Regex pattern in character-based, descending order.. After sorting, list(s) at the beginning take priority. With this scheme, specific SSID patterns take priority over match-all wildcard patterns.
    • If a tie persists, the MAC Registration List containing the MAC Registration entry that was created most recently takes priority.

    If none of the MAC Registration Lists match both the SSID and MAC address, then:

    • If one or more MAC Registration List(s) SSID Regex patterns match the requested SSID value, then the RADIUS response follows the No Matching MAC Registration Behavior from the list with the lowest sequence number.
    • If the SSID value of the RADIUS request matches none of the listed SSID Regex patterns, then the response is Reject without any additional policies.
  3. After you click Save, you are returned to a four-tab view of the MAC Registration List screen for the list you just configured. By default, the Details tab is displayed, reflecting the configuration of the new MAC Registration List. Refer to Details Tab View for Newly Added Mac Registration List (Top Portion of Screen) and Details Tab View for Newly Added Mac Registration List (Lower Portion of Screen) for examples of the Details tab.
    New illustration showing 4 tabs

    Details Tab View for Newly Added Mac Registration List (Top Portion of Screen)

    Details Tab View for Newly Added Mac Registration List (Lower Portion of Screen)

  4. If you click View All MAC Registration Lists (in the preceding screen, though not shown in the illustration), you are returned to the main screen, with the new configuration (MAC Registration-8 in this example) appearing in the list, as shown in MAC Registration Lists Screen After Adding a Second Registration Configuration:

    MAC Registration Lists Screen After Adding a Second Registration Configuration

Importing MAC Registration Entries to a MAC Registration List

Follow these steps to import a MAC Registration List into a MAC registration configuration.

  1. From the main MAC Registrations Lists screen, click the icon for the list in which you want to import a MAC address list.
  2. On the resulting screen, click the MAC Registrations tab. A screen such as the following is invoked:

    MAC Registrations Tab of a MAC Registration List

  3. If you first need a template for adding MAC addresses to an .xls file, click Download Bulk Import Template.
  4. Once you are ready to import the list of MAC addresses to the MAC registration list, click Import.

    Note: If importing from a .csv file, the following date formats are supported:

    yyyyMMdd, HHmmss

    yyyyMMdd HHmm

    yyyyMMdd

    MM/dd/yyyy HHmmss

    MM/dd/yyyy HHmm

    MM/dd/yyyy

    yyyy-MM-dd HH:mm:ss

    yyyy-MM-dd

  5. Browse to select your MAC address list, then click Continue.
  6. A pop-up message appears, where you click Continue Import.

    Pop-up Asking You to Confirm Import of MAC Address List File

  7. The file is imported and the MAC addresses are added to the applicable MAC Registration list.

Importing Individual MAC Addresses

Follow these steps to import individual MAC addresses into a MAC registration configuration.

  1. From the MAC Registrations tab of the desired MAC Registrations List (refer to the example in MAC Registrations Tab of a MAC Registration List), click the Add button in the "MAC Registrations" portion of the screen.
  2. In the pop-up window, enter the MAC addresses, separated by commas, that you wish to add.
  3. Click Save.
  4. Confirm the import on the resulting pop-up window.
    You are returned to the MAC Registrations tab, and there should be a confirmation message at the top, indicating that the MAC addresses have been successfully added. They will also appear at the bottom of that screen.

Removing a MAC Registration Configuration List or Its MAC Addresses

Follow these steps to either remove the MAC addresses from a MAC registration configuration list or to remove both the MAC addresses and the list itself:

  1. In the Cloudpath UI, go to Configuration > MAC Registration Lists to view all existing MAC Registration Lists.
  2. Click the icon for the desired MAC Registration List.
  3. Click the Details tab from an open MAC Registration List screen.
  4. Click Edit.
  5. Scroll to the bottom of the screen until you get to the Cleanup section, and expand the Cleanup section to display the available options.

    Cleanup Options for MAC Registration Configuration List

    Note: You cannot destroy the entire list if it is currently part of a workflow.
  6. Click on the desired option.
    A Warning pop-up appears.
  7. If you wish to continue, be sure to check the box to indicate that you "understand the warning," then click Continue.
    You are returned to the Details tab, where you should see a message indicating that your action has taken effect.

Adding and Viewing MAC OUI Wildcards

The MAC OUI Wildcard tab for a MAC Registration List lets you add, view, or delete a MAC OUI (Organizationally Unique Identifier) wildcard definitions. MAC OUI wildcards allow for all devices that match the OUI pattern prefix to authenticate via the MAC Registration List without the need for manual entry of individual device MAC addresses.

Follow these steps to add a MAC OUI wildcard to a MAC definition and view the details:

  1. In the Cloudpath UI, go to Configuration > MAC Registration Lists to view all existing MAC registration lists.

    MAC Registration Lists View

  2. Click the icon for the desired MAC Registration List; for example, the MAC-Registration-8 entry in the screen above. The four-tab MAC Registration List screen for the list you selected appears. Select the MAC OUI Wildcard tab. The following screen shows the MAC OUI Wildcard tab for the MAC-Registration-8 MAC Registration List.

    MAC Registration List Screen with MAC OUI Tab

  3. Click Add. The Add MAC OUI pop-up window appears.

    Add MAC OUI Pop-up Window

  4. In the pop-up window, enter the first six digits of the MAC address (MAC OUI wildcard) that you want to use, and click Save. In the following example screen, the first six digits of the MAC address entered are A5:B5:C5.

    Entering the MAC OUI Address

  5. You are returned to the MAC OUI Wildcard tab for the MAC Registration List. Verify that the newly defined MAC OUI Wildcard has been added to the MAC OUI Wildcard list, such as the A5:B5:C5 example displayed in the following screen.

    Successfully Added MAC OUI Wildcard

  6. Once the MAC OUI wildcard has been successfully added, you can view details about the MAC OUI wildcard. To view the MAC OUI wildcard details, click the icon next to the MAC OUI wildcard that you want to view. The following example screen, shows details for the A5:B5:C5 MAC OUI wildcard. All devices with a MAC address where the first six digits contain A5:B5:C5 have been added to the MAC OUI wildcard. Any MAC addresses that are prefixed with this MAC OUI wildcard will be able to self-register to the registration list without the need for individual MAC registrations.

    MAC OUI Wildcard Details

  7. If you want to delete a MAC OUI wildcard from a MAC Registration List, click the icon next to the MAC OUI wildcard that you want to remove. A pop-up window appears reminding you that this action does not affect existing MAC Registration Lists. Only the MAC OUI wildcard is removed. Click OK. The selected MAC OUI wildcard is removed.