Skip to content

How to Enable MAC Filtering on UniFi Network

Cover image for article: how-to-enable-mac-filtering-on-unifi-network

Insights · By Ujitha Rodrigo ·

Reviewed by
OneAccess Technical Review
Reviewed
4 July 2026
Tested version
UniFi Network 8.x interface family

Purpose

This guide explains how to use MAC address filtering in UniFi Network as an additional access-control layer for a small office, guest WiFi, or controlled device network.

MAC filtering can help reduce casual unauthorized access when a WiFi password has been shared too widely, but it is not a replacement for strong WiFi security, VLAN segmentation, firewall policy, or identity-based access control.

Tested context

  • Platform family: UniFi Network application and UniFi gateways/access points
  • Tested version: UniFi Network 8.x admin interface family
  • Access required: administrator access to the UniFi Network console

Menu names can change between UniFi Network releases. If your interface differs, use the official UniFi help pages linked in the references and confirm the setting name before changing production networks.

Prerequisites

  • A current backup of the UniFi Network configuration
  • Administrator access to the UniFi Network console
  • The MAC addresses of devices that should be allowed or blocked
  • A maintenance window if the network is used by business-critical devices
  • A separate administrator device that will not be accidentally blocked

When MAC filtering is useful

MAC filtering is useful when you need a simple device allow list or block list for a known group of devices. Examples include a small office SSID, a lab network, a temporary contractor network, or a guest environment where the password has been shared too broadly.

It is weaker than authentication-based control because MAC addresses can be copied by a determined attacker. Treat it as a supporting control, not as the main security boundary.

Before you start

Record the current SSID, VLAN, security mode, and client list. If the network supports business devices such as payment terminals, scanners, CCTV, or phones, confirm their MAC addresses before enabling any allow-list policy.

Also decide whether the rule should be an allow list or a block list:

  • Allow list: only listed devices can connect. Safer for controlled networks, but easier to lock out legitimate users if the list is incomplete.
  • Block list: listed devices are denied. Easier to deploy, but weaker when the WiFi password is already widely shared.

Step-by-step process

1. Open the UniFi Network console

Sign in to the UniFi Network application with an administrator account. Confirm that you are managing the correct site before making changes.

2. Identify the target WiFi network

Open the WiFi or network settings area and select the SSID where the MAC filtering rule should apply. Do not apply a restrictive allow list to a production SSID until every required business device has been identified.

3. Collect device MAC addresses

Use the UniFi client list, device labels, or the device operating system to collect MAC addresses. Give each entry a clear label, such as the user, department, or device role.

Avoid placeholder labels. A future administrator should be able to understand why each device was added.

4. Create the filtering policy

Create the MAC address control list using the UniFi Network interface available in your version. Choose allow-list or block-list behaviour based on the decision made earlier.

If your console supports client groups or policy names, use a descriptive name such as "Office WiFi allowed devices" or "Guest WiFi blocked devices".

5. Apply the policy to the SSID

Apply the policy to the selected SSID only. Avoid applying it globally unless that has been tested and approved.

After saving, test with one known allowed device and one known blocked or unlisted device.

6. Document the change

Record the date, SSID, policy type, device list owner, and rollback steps. Documentation matters because device lists quickly become stale when laptops, phones, and IoT devices are replaced.

Expected result

Allowed devices should connect normally. Blocked or unlisted devices should fail to join the selected WiFi network. The UniFi client list or event log should help confirm whether the policy is being applied.

Troubleshooting

  • If a valid device cannot connect, confirm that the MAC address is correct and check whether the device uses private or randomized WiFi MAC addresses.
  • If many users are blocked, temporarily disable the policy and recheck the allow list before re-enabling it.
  • If the setting is not visible, confirm the UniFi Network version, device model, and whether the feature is available for that network type.
  • If wired devices are involved, confirm that the control applies to the correct network path. Wireless and wired access controls may be configured differently.

Security considerations

MAC filtering can be bypassed by MAC spoofing. Use WPA2/WPA3 security, strong passwords, VLAN segmentation, firewall policy, guest isolation, and regular access reviews for stronger protection.

For business networks, review whether the better long-term control is separate SSIDs, per-user authentication, network segmentation, or a managed WiFi design.

Rollback notes

If users are locked out, disable the MAC filtering policy or remove it from the affected SSID. Restore the previous UniFi Network backup if the change cannot be cleanly reversed.

Related OneAccess resources

References

#unifi#unifi-technical-tips#unifi-support-sri-lanka#unifi-help#unifi-tech-tips

Stay in the loop

Get our Articles in your inbox.

Occasional notes from the OneAccess team. No marketing, no spam.