Skip to main content

Client Access Control

Last updated: November 12, 2024

T
Written by Tony Jian
Updated over 11 months ago

EnGenius Wi-Fi Access Points (APs) have Client Access Control feature to manage which devices can connect to the network. This helps maintain network security, prevent unauthorized access, and manage network resources effectively.

There are three access control rules - Blocklist, Allowlist, and VIP List - available for different scenarios, though Blocklist and Whitelist cannot be used simultaneously. Go to Configure > Client Access Control > Rules > Generalto choose which rule to be applied in your network.

Blocklist

The Blocklist allows you to block clients on a specific SSID or across all SSIDs. Devices on the Blocklist cannot connect to the AP, even if they have the network credentials.

Allowlist

The Allowlist is strict way to manage your network. Only device's MAC address is on the Allowlist will be allowed to access APs, otherwise all other clients will be denied.

Note: Devices in Allowlist still need to pass the authentication process, such as WPA, captive portal or 802.1X if the network has enable those checks.

VIP List

Lot of network devices such as printers, phones, cameras, or IoT devices may not have interfaces for user to input credentials that required by the network. The VIP List provides an way helps to get those devices on line by ignoring the security checks of the network.

Note: Devices been put into VIP list can still be accessed by other clients even L2 isolation function is enabled.

How to Configure

There are 3 ways to configure Client Access Control.

Configure in Client Access Control directly

Set Default ACL rule for Blocklist or Allowlist. Once selected, only one of them will be applied to SSID. Client's MAC address can be Added to or Deleted from a SSID or All SSIDs. A client can only be added in one of the rules.

Configure in SSID settings

Go to Configure > Access Point > SSID > Access Control.

Showing Blocklist or Allowlist here is based on Default ACL Rule in Configure > Client Access Control > Rules > General. You can Add, Delete, or Reset for ACL lists of the SSID based on client's MAC address.

Configure in Client List

Go to Manage > Clients > Wireless Client and mouse over on a client to add it to one of ACL rule of the connected SSID. Once it was added to one rule, other rules will be available to be changed to or select Normal to delete from added rule. If a client was added to one rule of the SSID, it will be automatically deleted from other rules.

Did this answer your question?