I have an aironet 1141 with multiple vlans configured, all with wpa2 but I need to put mac filter on only one vlan, so I follow this manual:
Basically is mac a ACL and applied to sub interface.
So, I can associate to the AP, but no one can transmit or receive .
If i remove the ACL all works fine.
access-list 700 permit <maclist> 0000.0000.0000
access-list 700 deny 0000.0000.0000 ffff.ffff.ffff
encapsulation dot1Q 130
no ip route-cache
bridge-group 130 subscriber-loop-control
bridge-group 130 input-address-list 700
bridge-group 130 output-address-list 700
bridge-group 130 port-protected
bridge-group 130 block-unknown-source
no bridge-group 130 source-learning
no bridge-group 130 unicast-flooding
bridge-group 130 spanning-disabled
In the output-address-list you should use another ACL with the same allowed mac list plus ffff.ffff.ffff 0.0.0.0 to forward packets with destination mac address as broadcast.
try and let me know how it goes