Home > Wireless LAN > Group Policies and Blacklisting > Applying Policies by Device Type

Applying Policies by Device Type

If a network admin is using group policies in Dashboard or wants to block/whitelist certain types of devices, MR access points support applying custom policies per device type on an individual SSID. This article outlines how to block, whitelist, or apply custom policies to wireless clients based on the device type.

Configuration

To configure policies by device type:

  1. In Dashboard, navigate to Wireless > Configure > Access Control.
  2. Select the desired SSID from the dropdown at the top.
  3. Set Assign group policies by device to enabled.
  4. Add and set policies as desired, selecting a Device type and assigning the corresponding Group policy.
    Note: To assign a policy to all devices that associate with the SSID, list all available device types and assign the corresponding policy. See the image below for an example configuration, that will block all device types from accessing the network:

Additional Considerations

The following sections outline some additional considerations to be kept in mind when assigning group policies by device type.

Client Identification

The access point will use the User-Agent string field of an HTTP GET request packet to determine the operating system of the client when it first associates, and allow or deny access accordingly. This can be observed in a packet capture, and may be helpful to gather for troubleshooting if a client doesn't appear to have the appropriate policy applied. In the image below, the User-Agent string shows the client is using Windows NT 6.1 as its OS. As such, any policy applied to Windows would affect this client:

Removing Applied Policies

When a client first associates to the SSID, if its device type matches one configured with a policy, the policy will be applied directly to the client's entry in Dashboard. This will cause the policy to apply automatically whenever they associate with that SSID.

To remove an automatically-assigned policy from a client, navigate to the Client Details page for that device, and change the Policy options as needed.

Note: If the SSID remains configured to apply a policy to that device type, then the policy will automatically re-apply when the client next associates to the SSID.

You must to post a comment.
Last modified
15:19, 19 Jul 2017

Tags

This page has no custom tags.

Classifications

This page has no classifications.

Article ID

ID: 1627

Contact Support

Most questions can be answered by reviewing our documentation, but if you need more help, Cisco Meraki Support is ready to work with you.

Open a Case