ā04-21-2020 11:01 AM
Hi all.
I would like to submit a question, my access points are configured with two radio networks: one corporate and one dedicated to mobile devices.
These two radio networks are on different vlan.
Many users uses the corporate network for their own mobiles, so my question is: is it possible to create a rule how reject all Android/iOS devices (by MAC OUI/other) if a device tries to connect to that network?
If yes, how can I do?
I hope I was clear, if not, don't hesitate to ask.
Thanks for your time
Mauro
My setup is:
- VX9000 controller version 5.9.1.3-007R
- Access points: AP-8432, AP-7632, AP-7522
ā04-21-2020 01:35 PM
Thanks Chris for your support, itās very usefull in order to block/allow specific MAC.
Do you know if thereās a better way to block/allow an entire brand (all iphones/ipad) without write by hand every single mac oui?
ā04-21-2020 01:03 PM
VERY IMPORTANT:
If you created an association ACL, there is an explicit Deny All rule at the end of the ACL (you canāt see it but itās there) so it is imperative that you add an allow all rule in your ACL or else all traffic will be denied.
Add this line at end of your ACL after youāve entered all the deny rules:
Chris
ā04-21-2020 12:54 PM
Hello Mauro,
Check step 2 of this article for instructions on mapping the ACL to the WLAN:
https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-create-an-Association-ACL-using-CLI
From GUI:
Configuration Ā» Wireless Ā» Select the WLAN you want to apply this to Ā» Edit Ā» Firewall Ā» Association ACL Ā» Select the ACL you created from the drop down menu Ā» OK Ā» Commit and Save
Thank you,
Chris
ā04-21-2020 12:38 PM
Thanks for your reply.
Now I configured my device fringer print group, how can I apply this group to a policy who deny these āfingerprintā to connect to a specifc SSID?
Thanks again
ā04-21-2020 11:26 AM
Hello!
You can use device fingerprinting.
From page 864
Thank you!