cancel
Showing results for 
Search instead for 
Did you mean: 

Question in the maximun supported counter of MAC firewall object in Classic NG

Question in the maximun supported counter of MAC firewall object in Classic NG

rickywong
New Contributor

Hi all,

 

 

Previously, we have a controller and using MAC filter to allow only the added object MAC addresses to join the SSID.

 

But there is a limitation that only 256 objects are already supported.

 

 

Can I use "MAC firewall object" and have the AP firewall policy to achieve the same purpose but support more than 256 clients?

 

 

Also, what is the different between Mac filter and MAC Firewall?

 

 

 

 

1 ACCEPTED SOLUTION

samantha_lynn
Esteemed Contributor III

Of course, here is the guide we have for setting up MAC authentication in Classic. HiveManager (formerly NG) is a separate platform from Classic, just for future reference.

 

https://thehivecommunity.aerohive.com/s/article/MAC-Authentication-Set-Up

View solution in original post

3 REPLIES 3

samantha_lynn
Esteemed Contributor III

Of course, here is the guide we have for setting up MAC authentication in Classic. HiveManager (formerly NG) is a separate platform from Classic, just for future reference.

 

https://thehivecommunity.aerohive.com/s/article/MAC-Authentication-Set-Up

rickywong
New Contributor

Yes, is also ok to use Radius for the authentication.

 

Might I have the configuration guidance for Classic NG?

 

Appreciate if also an example to show how to setup MAC in a Radius, assume using Windows server 2012 R2 as Radius.

samantha_lynn
Esteemed Contributor III

The maximum firewall rule limit is going to be 64 rules. The difference between a MAC filter and a MAC firewall is that the MAC filter screens authentication requests from client devices to the AP, where MAC firewall screens the traffic sent by the clients associated to the AP already.

 

You could set up MAC authentication to only allow devices with pre-approved MAC addresses to connect to your network, does that sound like what you're looking for? This guide reviews how to do that: https://thehivecommunity.aerohive.com/s/article/Radius-SSID-in-NG

 

I wouldn't recommend using the APs for extensive MAC filtering or firewall purposes; if there are large filtering needs, then a network firewall would be better at managing that.

GTM-P2G8KFN