This concept explains how wireless clients use random (locally administered) MAC addresses, why they improve privacy, and how Cisco controllers control their use within networks.
A random MAC address is a locally administered hardware address that
-
is generated by a device (instead of assigned by the manufacturer),
-
helps protect user privacy by making device tracking more difficult, and
-
can be permitted or denied on wireless networks through controller settings.
Random MAC address denial
Wireless clients traditionally use manufacturer-assigned, globally unique MAC addresses (burn-in addresses) for network association. Devices may also use locally administered, random MAC addresses for Wi-Fi operations to improve privacy. Network administrators can deny access to these clients using this feature.
Beginning with Cisco IOS XE 17.5.1, access controllers can block clients with random MAC addresses using the local-admin-mac deny feature. This feature is disabled by default.
This feature is not supported on Cisco Wave 1 access points.
Example: Denying Random MAC Address Clients
When the local-admin-mac deny knob is enabled on the controller, a client attempting to join the network with a random MAC address is rejected, preventing unauthorized or untraceable devices from accessing the wireless network.
For example, a phone may use a new random MAC address whenever it joins a public Wi-Fi network, which prevents tracking by Wi-Fi infrastructure or third parties.