AC.L2-3.1.16Wireless Access Authorization
Authorize wireless access prior to allowing such connections.
[a]
wireless access points are identified; and[b]
wireless access is authorized prior to allowing such connections.
Corporate WLAN allow-list; guest SSID has no enclave route
Implementation
AO coverage. Addresses both Wireless Access Authorization objectives.
Authorize prior to connect. Corporate SSID requires device certificate or 802.1X user/machine auth via ISE. Unknown devices land on guest or quarantine with no enclave routes.
Inventory. Authorized wireless clients are those with issued certs or approved BYOD profiles. Rogue AP detection enabled on the WLC.
Maintenance. Quarterly purge of stale device certificates. After office moves, re-validate SSID → VLAN mapping.
Accepted gap. Contractor day-pass Wi-Fi cannot use corp certs. Guests get internet-only VLAN; CUI laptops stay on corp SSID.
What the evidence looks like
- ISE/WLC policy showing auth required before corp VLAN
- Guest VLAN route table (no enclave)
- Certificate inventory / purge ticket
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.