Skip to content
ControlVerdict
AC.L2-3.1.16addresses
AC.L2-3.1.16Wireless Access Authorization
Authorize wireless access prior to allowing such connections.
  • [a]

    wireless access points are identified; and
  • [b]

    wireless access is authorized prior to allowing such connections.

View full control

Corporate WLAN allow-list; guest SSID has no enclave route

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Wireless Access Authorization objectives.

Authorize prior to connect. Corporate SSID requires device certificate or 802.1X user/machine auth via ISE. Unknown devices land on guest or quarantine with no enclave routes.

Inventory. Authorized wireless clients are those with issued certs or approved BYOD profiles. Rogue AP detection enabled on the WLC.

Maintenance. Quarterly purge of stale device certificates. After office moves, re-validate SSID → VLAN mapping.

Accepted gap. Contractor day-pass Wi-Fi cannot use corp certs. Guests get internet-only VLAN; CUI laptops stay on corp SSID.

What the evidence looks like

  • ISE/WLC policy showing auth required before corp VLAN
  • Guest VLAN route table (no enclave)
  • Certificate inventory / purge ticket

Environment

Office + lab Wi-Fi; Cisco ISE-class NAC optional.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.