cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
207
Views
2
Helpful
6
Replies

Equivalent Command for 9800

roo54
Level 1
Level 1

A simple question....If I just knew where to find the answer:

Doing MAC authentication on an 5520 WLC, I can see the MAC addresses accepted by the WLC if I issue the command:

"sho macfilter summary"

Can anyone tell me the equivalent command on a 9800 (yes, I have googled it )

Thanks

Roo

6 Replies 6

marce1000
VIP
VIP

 

 - I don't think your statement is exactly true ; the mentioned command will only list the allowed mac addresses (not authenticating events) ; 'similarly' on the 9800 you follow this document for setup : https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213922-configure-mac-authentication-ssid-on-cis.html
                       Probably the allowed MAC's can be listed in the running config somewhere afterwards , 

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

That's what I was trying to do, list the allowed MAC addresses....

 

 - Yeah , because of the underlying ios-xe being used , my methodology will work , but is more cumbersome to perform , 

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

roo54
Level 1
Level 1

You wrote " Probably the allowed MAC's can be listed in the running config somewhere afterwards ", that was my first thougt, but looking at the running config did not help....I'll dig somemore, but has ANYONE tried to do this? It would be much more reasonable for the MAC addresses to be managed by an ISE, but not in this case, they are managed by the WLC which seems to have hidden them

Thanks

Roo

roo54
Level 1
Level 1

OK, I dug it out myself

the MAC addresses are stored in

Config>Security>AAA>AAA Advanced>MAC Addresses

on the GUI, and if you were hoping to get a CLI command like "sho macfilter summary", I think I'm gonna disapoint you, the nearest I could get was to do "sho runn | beg username", but when you do that the MAC addresses are mixed in amongst the admin users, etc.  I guess they don't really want you managing MAC addresses on the WLC, it should be done on an IOSE or similar, and they aren't going to make it easy for you to do it

Thanks

Roo

Rich R
VIP
VIP

Yes they are saved as usernames of type mac so actually it is quite easy to filter them from running-config with:
show run | inc username ............ mac

Review Cisco Networking products for a $25 gift card