How to do the wireless client access control by MAC address when using SonicPoint VAP

Description

The video on YouTube is available.

This article shows you how to do the wireless client access control by MAC address when using SonicPoint VAP.

Resolution

In this case, the AP (access point) name is VAP,  a mobile phone is connected to the AP.

Image

 

Image

 

  • To do the access control when using VAP, please navigate to SonicPoint  | Virtual Access Point .  Click the edit button of the Virtual Accesss Point you are interested in at Virtual Access Points area | Click tab Advanced | Select Enable MAC Filter List.

Image

 

2. To use global ACL settings, select Use Global ACL Settings. By default, this option is not checked.

To configure the Global ACL Settings, go to SonicPoint > SonicPoints | Click the edit button of the SonicPoint you are interested in at SonicPointNs area | ACL Enforcement can be configured in tab Radio Basic.

Image

3. From the Allow List drop-down menu, select a MAC address group to automatically allow traffic from all devices with MAC address in the group:
  • Create new Mac Address Object Group  The Add Address Object Group window displays.
  • All MAC Addresses

NOTE: It is recommended that the Allow List be set to All MAC Addresses.

  • Default SonicPoint ACL Allow Group
  • Custom MAC Address Object Groups
4. From the Deny List drop-down menu, select a MAC address group from the drop-down menu to automatically deny traffic from all devices with MAC address in the group.
NOTE: The Deny List is enforced before the Allow List.
  • Create new Mac Address Object Group  The Add Address Object Group window displays.
  • No MAC Addresses
  • Default SonicPoint ACL Deny Group

?NOTE: It is recommended that the Deny List be set to Default SonicPoint ACL Deny Group.

  • Custom MAC Address Object Groups

 

To configure the Object Group, please follow below steps:

Step 1: Go to Firewall | Address Objects page. Edit Default ACL Deny Group or add a custom object group at Address Groups area.

 

Step 2: Click the edit button of the group | add/remove the relevant MAC address object of the wireless client.

How to test:

In this case, the mobile client MAC address has been added to the Default SonicPoint ACL Deny Group.

Image

Selected Default SonicPoint ACL Deny Group from the Deny List, Mobile client disconnected from the AP.

Image

 

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?