<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Airespace ACL - Flexconnect AP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730634#M489095</link>
    <description>&lt;P&gt;As long as that ACL exists under FlexConnect ACLs on the WLC, then airespace ACL should work.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Oct 2018 11:30:22 GMT</pubDate>
    <dc:creator>anthonylofreso</dc:creator>
    <dc:date>2018-10-23T11:30:22Z</dc:date>
    <item>
      <title>Airespace ACL - Flexconnect AP</title>
      <link>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730611#M489090</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have an ISE 2.2 patch 10 full distributed deployment in which I am using Airespace-ACLs for wireless clients. It is works successfully except when client connect to a Flexconnect AP. &lt;BR /&gt; &lt;BR /&gt;Do you know if is&amp;nbsp;there any limitation to use airspace-acls with Flexconnect AP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 10:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730611#M489090</guid>
      <dc:creator>victguti</dc:creator>
      <dc:date>2018-10-23T10:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Airespace ACL - Flexconnect AP</title>
      <link>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730634#M489095</link>
      <description>&lt;P&gt;As long as that ACL exists under FlexConnect ACLs on the WLC, then airespace ACL should work.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 11:30:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730634#M489095</guid>
      <dc:creator>anthonylofreso</dc:creator>
      <dc:date>2018-10-23T11:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Airespace ACL - Flexconnect AP</title>
      <link>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730646#M489112</link>
      <description>&lt;P&gt;For a long time I dealt only with regular ACL's and ISE was returning them via the Access-Accept.&amp;nbsp; And then I had to work with Flex ACL's.&amp;nbsp; Well for starters, they look different because there is no direction associated with them (inbound/outbound).&amp;nbsp; You have to create them under FlexACL and not regular ACL.&amp;nbsp; But in ISE you can refer to them by the regular means.&amp;nbsp; However, I have found that when I used them for Guest Portal URL redirection, that ISE didn't need to (or have to) return this named Flex ACL at all.&amp;nbsp; The ACL is hard-coded into the part of the WLC config that deals with Central Web Auth.&amp;nbsp; As soon as the session is in CWA then the WLC applies the ACL as configured in the WLC - it has nothing to do with Radius anymore (even though this is a MAB auth flow!).&amp;nbsp; And then the other oddity I found (and have yet to resolve) is how to send the Flex ACL to tell the WLC that it has to apply a different Flex ACL because the guest is now authenticated.&amp;nbsp; It just refuses to accept the named Flex ACL I send it.&amp;nbsp; I never got it to work (Cisco WLC 8.5.something)&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 12:03:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730646#M489112</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-10-23T12:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Airespace ACL - Flexconnect AP</title>
      <link>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730656#M489133</link>
      <description>&lt;P&gt;Nice. Learned something new today.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 12:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730656#M489133</guid>
      <dc:creator>anthonylofreso</dc:creator>
      <dc:date>2018-10-23T12:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Airespace ACL - Flexconnect AP</title>
      <link>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730696#M489151</link>
      <description>&lt;P&gt;I think you still need to apply the ACL from my experience, but the key with FlexConnect is you need to push out the ACLs to the APs using your FlexConnect groups.&amp;nbsp; You push them out as policy ACLs.&amp;nbsp; Also for ACLs that you want to apply to apply to restrict traffic you need to push them out as well before they can get applied.&amp;nbsp; Look at the ACL tab in the FlexConnect group and push them out, but don't apply them to any interface.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 12:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730696#M489151</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-10-23T12:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Airespace ACL - Flexconnect AP</title>
      <link>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730796#M489169</link>
      <description>&lt;P&gt;I face the same issue, FlexConnect ACL should push through FlexConnect groups,&amp;nbsp;but the&amp;nbsp;ACL send to AP which in turn applied to user is different from the original ACL created in Controller. Seems its related to a bug affecting flexconnect ACL (its not the case in central switch) and there is a hotfix OS code for the same. CISCO also planned to release stable version of OS including this fix&amp;nbsp;in first week of Nov-2018&lt;/P&gt;
&lt;P&gt;Kindly raise a TAC to get more information on the same&lt;/P&gt;</description>
      <pubDate>Tue, 23 Oct 2018 16:09:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3730796#M489169</guid>
      <dc:creator>rajcisco</dc:creator>
      <dc:date>2018-10-23T16:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Airespace ACL - Flexconnect AP</title>
      <link>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3733246#M489189</link>
      <description>&lt;P&gt;Adding to the others, please also check out the Appendix B of&amp;nbsp;&lt;A href="https://community.cisco.com/docs/DOC-68172" target="_blank"&gt;How To: Universal Wireless Controller (WLC) Configuration for ISE&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 00:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/airespace-acl-flexconnect-ap/m-p/3733246#M489189</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-10-26T00:20:38Z</dc:date>
    </item>
  </channel>
</rss>

