MAC Spoofing Prevention in Wireless

Hello List,

I have recently been involved in a security test of a wireless
environment using Aruba controllers and a captive portal. As an
obvious attack vector I tried spoofing the MAC (and IP) addresses of
valid authenticated users but it didn't grant me access. I've been
told that MAC spoofing prevention is one of the feature of the Aruba
wireless controllers.

I've Googled a bit but haven't come across a good explanation. How
does MAC spoofing detection work on wireless networks? What
information does a controller utilize on lower layers to detect that a
packet is coming from a spoofed MAC?


