The local DB mac-authentication will not work for fallback case. We do have a cnMaestro Association ACL which can be used for the same. Just use the mac-authentication policy as cnMaestro in the WLAN configuration and then have a cnMaestro or onboard guest portal for fallback. This should work for you and will not require any external RADIUS server, etc .Onboard guest portal on the device has a localĀ Guest Account option which we can use it for single common user-name password for all your guest clients if you prefer that way.