Configuring the MAC filter list for Internal Wireless

Description

Wireless networking provides native MAC filtering capabilities that prevent wireless clients from authenticating and associating with the wireless security appliance. If you enforce MAC filtering on the WLAN, wireless clients must provide you with the MAC address of their wireless networking card. The SonicOS wireless MAC Filter List allows you to configure a list of clients that are allowed or denied access to your wireless network. Without MAC filtering, any wireless client can join your wireless network if they know the SSID and other security parameters, thus allowing them to “break into” your wireless network.

Deployment Considerations :


Consider the following when deploying the MAC Filter List:

The MAC Filter List can be enabled on the Internal Wireless > MAC Filter List page if a virtual access point (VAP) group is not configured. If a VAP group is configured, the MAC Filter function needs to be enabled on the VAP object.

The virtual access point can configure its MAC Filter List or inherit global settings configured on the Internal Wireless > MAC Filter List page.

Resolution for SonicOS 7.X :

This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.

Log into the SonicWall appliance and follow these instructions to set up your MAC Filter List.

  1. Click Object in the top navigation menu.
  2. Navigate to Match Objects | Addresses .
  3. Click on Address Objects tab.
  4. Click Add to add new address object
  5. Enter the following.
    • Name: The name of the user whose wireless card MAC address you wish to grant access.
    • Zone Assignment: WLAN or an appropriate custom wireless zone.
    • Type: MAC
    • MAC Address: The MAC address of the user's wireless adapter. Enter a dash between each pair of characters.

      EXAMPLE: 00-12-34-56-78-AB.

  6. Click OK to complete creation of the user's MAC address object.

    Image

  7. Click on the Address Groups tab.
  8. Click the edit icon next to the Default ACL Allow Group object.
  9. Select the newly created MAC address object and click the right arrow button to add it as a member of the Default ACL Allow Group
  10. Click OK.

    Image

  11. Repeat the same procedure with the Default ACL Deny Group for any MAC addresses you wish to explicitly deny access.

    NOTE:The Deny List is enforced before the Allow List.

  12. Click Device Tab, Navigate to Internal Wireless | MAC Filter List.
  13. Check Enable MAC Filter List. Select the Default ACL Allow Group in the Allow List and Select the Default ACL Deny Group in the Deny List.
  14. Click Accept to complete the process.

    Image

Resolution for SonicOS 6.5

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.

Log into the SonicWall appliance and follow these instructions to set up your MAC Filter List.

  1. Click Manage in the top navigation menu.
  2. Select Objects | Address Objects.
  3. Click on Address Objects tab.
  4. Click Add a new address object button
  5. Enter the following.
    • Name: The name of the user whose wireless card MAC address you wish to grant access.
    • Zone Assignment: WLAN or an appropriate custom wireless zone.
    • Type: MAC
    • MAC Address: The MAC address of the user's wireless adapter. Enter a dash between each pair of characters.

      EXAMPLE: 00-12-34-56-78-AB.

  6. Click OK to complete creation of the user's MAC address object.

    Image

  7. Click on Address Groups tab.
  8. Click the edit icon next to the Default ACL Allow Group object.
  9. Select the newly created MAC address object and click the right arrow button to add it as a member of the Default ACL Allow Group.
  10. Click OK.

    Image

  11. Repeat the same procedure with the Default ACL Deny Group for any MAC addresses you wish to explicitly deny access.

    NOTE:The Deny List is enforced before the Allow List.

  12. Click Manage Tab, Under Select Wireless | MAC Filter List.
  13. Check Enable MAC Filter List. Select the Default ACL Allow Group in the Allow List and Select the Default ACL Deny Group in the Deny List.
  14. Click Apply changes to this page button to complete the process.
    Image



Resolution for SonicOS 6.2 and Below

The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.

Log into the SonicWall appliance and follow these instructions to set up your MAC Filter List.

SonicOS Enhanced

  1. Navigate to Network | Address Objects.
  2. Click  Add a new address object button and enter the following.
    • Name: The name of the user whose wireless card MAC address you wish to grant access.
    • Zone Assignment: WLAN or an appropriate custom wireless zone.
    • Type: MAC
    • MAC Address: The MAC address of the user's wireless adapter. Enter a dash between each pair of characters.

      EXAMPLE: 00-12-34-56-78-AB.

  3. Click OK to complete creation of the user's MAC address object.
  4. Click Edit icon next to the Default ACL Allow Group object.
  5. Select the newly created MAC address object and click the right arrow button to add it as a member of the Default ACL Allow Group.
  6. Click OK.
  7. Repeat the same procedure with the Default ACL Deny Group for any MAC addresses you wish to explicitly deny access.

    NOTE:  The Deny List is enforced before the Allow List.

  8. Select Wireless | MAC Filter list.
  9. Check Enable MAC Filter List.
  10. Select the Default ACL Allow Group in the Allow List.
  11. Select the Default ACL Deny Group in the Deny List.
  12. Click the Apply changes to this page button to complete the process.

SonicOS Standard

  1. Select Wireless |MAC Filter List.
  2. Click Add to add a MAC address to the MAC Filter List.
  3. Select Allow from the action menu to allow access to the WLAN. To deny access, select block.
  4. Type the MAC address in the MAC address field. Enter a dash between each pair of characters.

    EXAMPLE: 00-12-34-56-78-AB.

  5. Type a name or comment in the comment field. The comment field can be used to identify the source of the MAC address.
  6. Click OK to add the MAC address.

Related Articles

  • SonicWall UTM throws an error : " Invalid Authentication " Error: SN and EPAID Do Not Match
    Read More
  • Firewall logs show frequent probe status changes after upgrade
    Read More
  • SSO Agent 4.0: Installation, Configurations, and troubleshooting
    Read More
not finding your answers?
was this article helpful?