Petri IT Knowledgebase Forums
 

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri IT Knowledgebase Forums > Networking > Cisco Routers & Switches How-to
Petri.co.il is happy to award auglan the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri IT Knowledgebase Forums Search Todays Posts Today's Posts Mark Forums Read

Notices

Restrict access to Cisco Aironet 1200 by MAC address

Restrict access to Cisco Aironet 1200 by MAC address

this thread has 5 replies and has been viewed 6325 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 20th October 2006, 16:13
tonyyeb's Avatar
tonyyeb tonyyeb is offline
Moderator
 
 Join Date: Dec 2004
  6 month star 12 month star
 Location: Hull, UK
 Posts: 2,182
 Reputation: tonyyeb is a jewel in the roughtonyyeb is a jewel in the roughtonyyeb is a jewel in the rough (283)
Default Restrict access to Cisco Aironet 1200 by MAC address

Hi all

Spent a little bit of searching trying to get our Cisco Aironet 1200 series wireless access points to only allow certain MAC addresses.

My phone doesn't like to connect to an SSID which isn't broadcast. So i thought create another SSID but only allow the MAC address of my phone connect.

I thought it would be simple, but everything i come accross talks about RADIUS and other stuff that i haven't a clue about. We have 15+ AP's so I want a simple way of doing it... any ideas?

Thanks in advance.
__________________
Server 2000 MCP
Development: ASP, ASP.Net, PHP, VB, VB.Net, MySQL, MSSQL - Check out my blog http://tonyyeb.blogspot.com

** Remember to give credit where credit is due and leave reputation points To grant some reputation points to the user that helped you, just click on the little Yin-Yang icon on the right of the user's answer and follow the prompt. where appropriate **
  #2  
Old 20th October 2006, 19:19
Dumber's Avatar
Dumber Dumber is offline
Moderator
 
 Join Date: Dec 2003
  6 month star 12 month star
 Location: The Netherlands
 Posts: 8,067
 Reputation: Dumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to behold (820)
Default Re: Restrict access to Cisco Aironet 1200 by MAC address

not sure if this help?
http://www.cisco.com/en/US/products/...f.html#1028504
__________________
Marcel
Netherlands
http://www.phetios.com
http://blog.nessus.nl

MCITP(EA, SA), MCSA/E 2003:Security, CCNA, SNAF, DCUCI, CCSA/E/E+ (R60), VCP4/5, NCDA, NCIE - SAN, NCIE - BR, EMCPE
No matter how secure, there is always the human factor.
  #3  
Old 20th October 2006, 19:30
daviddavis's Avatar
daviddavis daviddavis is offline
Moderator
 
 Join Date: May 2006
  6 month star 12 month star
 Location: Hilton Head, South Carolina, USA
 Posts: 685
 Reputation: daviddavis is a jewel in the roughdaviddavis is a jewel in the roughdaviddavis is a jewel in the roughdaviddavis is a jewel in the rough (348)
Default Re: Restrict access to Cisco Aironet 1200 by MAC address

Hi Tony,

Checkout this link:
http://www.cisco.com/univercd/cc/td/....htm#wp1029067

Looks like you could manually enter the MAC addresses or use Cisco ACS.

Let us know if this is helpful or not.

Thanks
David
  #4  
Old 21st October 2006, 01:13
tonyyeb's Avatar
tonyyeb tonyyeb is offline
Moderator
 
 Join Date: Dec 2004
  6 month star 12 month star
 Location: Hull, UK
 Posts: 2,182
 Reputation: tonyyeb is a jewel in the roughtonyyeb is a jewel in the roughtonyyeb is a jewel in the rough (283)
Default Re: Restrict access to Cisco Aironet 1200 by MAC address

Both those links have screen shots of what i can only assume is a very old IOS on the AP's.

I think ive found where i needed to be. Security > Advanced Settings > MAC Authentication

But it looks like this is per access point rather than per SSID.

Oh well - bang goes that idea!
__________________
Server 2000 MCP
Development: ASP, ASP.Net, PHP, VB, VB.Net, MySQL, MSSQL - Check out my blog http://tonyyeb.blogspot.com

** Remember to give credit where credit is due and leave reputation points To grant some reputation points to the user that helped you, just click on the little Yin-Yang icon on the right of the user's answer and follow the prompt. where appropriate **
  #5  
Old 21st October 2006, 21:52
theterranaut theterranaut is offline
Junior Member
It's not a coincidence
 
 Join Date: Oct 2006
  6 month star 12 month star
 Posts: 107
 Reputation: theterranaut has a spectacular aura abouttheterranaut has a spectacular aura about (156)
Default Re: Restrict access to Cisco Aironet 1200 by MAC address

Tony, this is easy to do if you have ACS. No other way I know of if you are running disparate access points. I know this means £££ but ACS dovetails so neatly with ACS.

Alternately- what about some higher security such as one of the flavours of 802.1x? Even WPA2, using a Windows box as a a certificate server? More involved, but easier to centrally manage when its all set up. There's an excellent guide here: http://www.ifm.net.nz/cookbooks/wpa_sbs2003/index.html

on running this on SBS, but easily extrapolates to Win Server 2003.

theterranaut
  #6  
Old 21st October 2006, 23:33
tonyyeb's Avatar
tonyyeb tonyyeb is offline
Moderator
 
 Join Date: Dec 2004
  6 month star 12 month star
 Location: Hull, UK
 Posts: 2,182
 Reputation: tonyyeb is a jewel in the roughtonyyeb is a jewel in the roughtonyyeb is a jewel in the rough (283)
Default Re: Restrict access to Cisco Aironet 1200 by MAC address

Thanks for the suggestion but i want to spend nothing on this as it is for me, not really the company. Thanks anyway.
__________________
Server 2000 MCP
Development: ASP, ASP.Net, PHP, VB, VB.Net, MySQL, MSSQL - Check out my blog http://tonyyeb.blogspot.com

** Remember to give credit where credit is due and leave reputation points To grant some reputation points to the user that helped you, just click on the little Yin-Yang icon on the right of the user's answer and follow the prompt. where appropriate **
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
IPv4 Addressing ozgursen Cisco Routers & Switches How-to 2 13th October 2006 10:46
Round Robin priority vs. MX preference. lukeandmax Exchange 2000 / 2003 2 1st June 2006 14:58
Address List Access morjo Windows Server 2000 / 2003 3 14th November 2005 17:00
blocking a MAC address david-uk General Security 8 14th October 2005 15:28
Citrix Access Suite 4.0 Offers Major Advancements yuval14 Terminal Services 1 26th April 2005 23:02


All times are GMT +3. The time now is 10:14.

Steel Blue 3.5.4 vBulletin Style ©2006 vBEnhanced
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri