This topic describes AP MAC authorization.
AP MAC authorization is a security feature that:
-
ensures only authorized APs can associate with the controller,
-
requires registration of the AP's Ethernet MAC address, and
-
it is configured locally on the controller or on an external RADIUS server.
With the Cisco IOS-XE 17.18 release, APs support MAC address authorization using different delimiter formats to enhance the controller’s support, which previously did not accept any delimiter.
IOS AAA config mac-delimiter and subscriber mac-filtering security-mode <> under AAA group server RADIUS is enabled for this feature for wireless AP join cases.
To authenticate an AP using its MAC address:
Set the mac-filter flag to yes. This setting configures AAA to send the username with the specified delimiter and sets the MAC filter flag.
Configure AAA server groups that include the IP addresses of the selected server hosts. This configuration allows you to group existing server hosts, select a subset of the configured server hosts, and use them for a particular service.
By arranging server groups and configuring them using the global server-host list, you can manage services with a more structured and secure approach.