Controller GUI Security Settings
Although the settings are not directly related to the feature, it might help you in achieving the desired behavior
with respect to APs provisioned with an LSC.
Figure 82: Possible Cases for Mesh AP MAC Authorization and EAP
• Case 1—Local MAC Authorization and Local EAP Authentication
Add the MAC address of RAP/MAP to the controller MAC filter list.
Example:
(Cisco Controller) >
config macfilter mac-delimiter colon
(Cisco Controller) >
config macfilter add 00:0b:85:60:92:30 0 management
• Case 2—External MAC Authorization and Local EAP authentication
Enter the following command on the WLC:
(Cisco Controller) >
config mesh security rad-mac-filter enable
or
Check only the external MAC filter authorization on the GUI page and follow these guidelines:
◦ Do not add the MAC address of the RAP/MAP to the controller MAC filter list.
◦ Configure the external radius server details on the WLC.
◦ Enter the
config macfilter mac-delimiter colon
command configuration on the WLC.
◦ Add the MAC address of the RAP/MAP in the external radius server in the following format:
User name: 11:22:33:44:55:66 Password : 11:22:33:44:55:66
Cisco Mesh Access Points, Design and Deployment Guide, Release 7.3
OL-27593-01
191
Connecting the Cisco 1500 Series Mesh Access Points to the Network
Locally Significant Certificates for Mesh APs