Wireless MAC Address Filtering and User Identification

Kimon11
New here

Wireless MAC Address Filtering and User Identification

I am looking for a solution to implement mac-address filtering along with user identification when a users connect to an SSID.  From what I've read, to identify users Meraki Authentication must be used with a splash page, and LDAP/AD/RADIUS cannot be used.https://speedtest.vet/ https://vidmate.bid/ 

 

I saw that there was an option to connect via mac-address but that the solution does not offer encryption, which is upsetting.

 

The only thing I've come up with to accomplish these goals is to set a small DHCP scope with hardcoded reservations for users and expand the scope by one any time a new user needs access to the network.  This solution, coupled with splash screen Meraki Authentication seems cumbersome.  I pondered simply renaming the wireless devices with the user's name, which may be a solution, but also cumbersome.

 

Am I going about this the wrong way?  Is there another option out there?

 

Thank you,

1 Reply 1
BrechtSchamp
Kind of a big deal

As far as I know, the only way to do MAC-address filtering without external AAA is described here:

https://documentation.meraki.com/MR/MR_Splash_Page/Using_a_Sign-on_Splash_Page_to_Restrict_Wireless_...

 

It just checks for the MAC-address and bypasses the splash page, so not what you need.

 

To do what you need, you need to implement an external AAA server such as Cisco ISE.

 

More info here:

https://documentation.meraki.com/MR/Encryption_and_Authentication/Configuring_RADIUS_Authentication_...

 

And here:

https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/workflow/Cisco_ISE_2_7_Admin_Guid...

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels