Insights · By Ujitha Rodrigo ·
- Reviewed by
- OneAccess Technical Review
- Reviewed
- 4 July 2026
- Tested version
- UniFi Network 8.x interface family
Purpose
This guide explains how to use MAC address filtering in UniFi Network as an additional access-control layer for a small office, guest WiFi, or controlled device network.
MAC filtering can help reduce casual unauthorized access when a WiFi password has been shared too widely, but it is not a replacement for strong WiFi security, VLAN segmentation, firewall policy, or identity-based access control.
Tested context
- Platform family: UniFi Network application and UniFi gateways/access points
- Tested version: UniFi Network 8.x admin interface family
- Access required: administrator access to the UniFi Network console
Menu names can change between UniFi Network releases. If your interface differs, use the official UniFi help pages linked in the references and confirm the setting name before changing production networks.
Prerequisites
- A current backup of the UniFi Network configuration
- Administrator access to the UniFi Network console
- The MAC addresses of devices that should be allowed or blocked
- A maintenance window if the network is used by business-critical devices
- A separate administrator device that will not be accidentally blocked
When MAC filtering is useful
MAC filtering is useful when you need a simple device allow list or block list for a known group of devices. Examples include a small office SSID, a lab network, a temporary contractor network, or a guest environment where the password has been shared too broadly.
It is weaker than authentication-based control because MAC addresses can be copied by a determined attacker. Treat it as a supporting control, not as the main security boundary.
Before you start
Record the current SSID, VLAN, security mode, and client list. If the network supports business devices such as payment terminals, scanners, CCTV, or phones, confirm their MAC addresses before enabling any allow-list policy.
Also decide whether the rule should be an allow list or a block list:
- Allow list: only listed devices can connect. Safer for controlled networks, but easier to lock out legitimate users if the list is incomplete.
- Block list: listed devices are denied. Easier to deploy, but weaker when the WiFi password is already widely shared.
Step-by-step process
1. Open the UniFi Network console
Sign in to the UniFi Network application with an administrator account. Confirm that you are managing the correct site before making changes.
2. Identify the target WiFi network
Open the WiFi or network settings area and select the SSID where the MAC filtering rule should apply. Do not apply a restrictive allow list to a production SSID until every required business device has been identified.
3. Collect device MAC addresses
Use the UniFi client list, device labels, or the device operating system to collect MAC addresses. Give each entry a clear label, such as the user, department, or device role.
Avoid placeholder labels. A future administrator should be able to understand why each device was added.
4. Create the filtering policy
Create the MAC address control list using the UniFi Network interface available in your version. Choose allow-list or block-list behaviour based on the decision made earlier.
If your console supports client groups or policy names, use a descriptive name such as "Office WiFi allowed devices" or "Guest WiFi blocked devices".
5. Apply the policy to the SSID
Apply the policy to the selected SSID only. Avoid applying it globally unless that has been tested and approved.
After saving, test with one known allowed device and one known blocked or unlisted device.
6. Document the change
Record the date, SSID, policy type, device list owner, and rollback steps. Documentation matters because device lists quickly become stale when laptops, phones, and IoT devices are replaced.
Expected result
Allowed devices should connect normally. Blocked or unlisted devices should fail to join the selected WiFi network. The UniFi client list or event log should help confirm whether the policy is being applied.
Troubleshooting
- If a valid device cannot connect, confirm that the MAC address is correct and check whether the device uses private or randomized WiFi MAC addresses.
- If many users are blocked, temporarily disable the policy and recheck the allow list before re-enabling it.
- If the setting is not visible, confirm the UniFi Network version, device model, and whether the feature is available for that network type.
- If wired devices are involved, confirm that the control applies to the correct network path. Wireless and wired access controls may be configured differently.
Security considerations
MAC filtering can be bypassed by MAC spoofing. Use WPA2/WPA3 security, strong passwords, VLAN segmentation, firewall policy, guest isolation, and regular access reviews for stronger protection.
For business networks, review whether the better long-term control is separate SSIDs, per-user authentication, network segmentation, or a managed WiFi design.
Rollback notes
If users are locked out, disable the MAC filtering policy or remove it from the affected SSID. Restore the previous UniFi Network backup if the change cannot be cleanly reversed.
