Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Limiting access points joining a specific WLC

Hello Cisco Forum Team!

  I am currently installing a new WLC in a VLAN/IP segment that already has WLCs configured and access points registered. I do not want existing ap's on this VLAN to join this new WLC.  Which is the best way to limit ap's joining this new WLC?

I am thinking of some sort of AP authorization list but by IP address instead of MAC address due to the high amount of ap's currently registred on the existing WLCs (approx. 300 ap's).

 

Thanks in advanced for your support!

5 REPLIES
VIP Purple

AP authorization list would

AP authorization list would work but you have to use MAC address & cannot use IP address for that. Once you enable AP authorization you can add AP mac to the list like below using CLI.

 

(5508-1) >config auth-list add mic <AP1 mac>

(5508-1) >config auth-list add mic <AP2 mac>

.

.

(5508-1) >config auth-list add mic <APn mac>

 

HTH

Rasika

**** Pls rate all useful responses ****

New Member

Hello Rasika and thanks for

Hello Rasika and thanks for your reply;

  Yes; I am trying to deny the IP address segment instead of adding each individual access point MAC address to the list.

 

Is there any other approach?

 

Thanks again for your support!

VIP Purple

HiYou need to add permit AP

Hi

You need to add permit AP mac address list to your new controller, so in that way only those AP will get register to new WLC. 

If you want to block this by IP,then you can try block UDP 5246 from AP subnet to new controller managment address if they are in two different subnet.

 

HTH

Rasika

**** Pls rate all useful responses ****

Hall of Fame Super Gold

I do not want existing ap's

I do not want existing ap's on this VLAN to join this new WLC

Make sure this new WLC's Management IP address is not in DHCP Option 43 and you did not configure AP Fallback.  

 

Without any of these settings the AP won't go there unless you manually tell them to.

New Member

Excellent. Thanks for the

Excellent. Thanks for the information.

95
Views
5
Helpful
5
Replies
CreatePlease to create content