<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC ACL Limit in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573790#M519956</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick response. Can we do TrustSec scalable group tags only on the WLC's without having to do TrustSec on the rest of the network?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Nov 2017 15:07:24 GMT</pubDate>
    <dc:creator>cfnisupport</dc:creator>
    <dc:date>2017-11-13T15:07:24Z</dc:date>
    <item>
      <title>WLC ACL Limit</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573788#M519942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How are large organizations dealing with the 64 ACL and 64 ACE limit on the WLC's? We are deploying ISE and we are early into our deployment and already had an instance where we hit the 64 ACE limit. It is easy to hit this limit, in my opinion, when you're dealing with Active Directory traffic and other 'chatty' type services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One way around this I've found is to not restrict by port, but to just allow all TCP traffic to the destination IP, but that isn't as secure. That doesn't bother me too much, but I'm still concerned about the scale.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have any input? Since the WLC's don't support dACL, I'm really starting to wonder how we scale.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 14:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573788#M519942</guid>
      <dc:creator>cfnisupport</dc:creator>
      <dc:date>2017-11-13T14:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: WLC ACL Limit</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573789#M519947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would recommend deploying TrustSec scalable group tags.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 15:04:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573789#M519947</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-13T15:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: WLC ACL Limit</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573790#M519956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick response. Can we do TrustSec scalable group tags only on the WLC's without having to do TrustSec on the rest of the network?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 15:07:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573790#M519956</guid>
      <dc:creator>cfnisupport</dc:creator>
      <dc:date>2017-11-13T15:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: WLC ACL Limit</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573791#M519959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It needs some network devices (e.g. ASA) between the endpoints and the servers to perform the enforcement.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 15:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573791#M519959</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-13T15:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: WLC ACL Limit</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573792#M519963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would recommend learning more about Trustsec, classification happens on the WLC but enforcement would happen at other points (data center)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://www.youtube.com/watch?v=78-GV7Pz18I&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can certainly start with wireless only but the benefits would also be available on the wired side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 15:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573792#M519963</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-13T15:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: WLC ACL Limit</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573793#M519970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am curious about your wireless policies that have so many ACLs.&amp;nbsp; What are you trying to accomplish with your wireless setup?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 23:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573793#M519970</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-11-13T23:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: WLC ACL Limit</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573794#M519974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're trying to lock down a small group of Windows 10 Surface Pro's down to only what it needs to communicate with on the network, inside and out.&amp;nbsp; Which means locking down to Meraki, our internal servers necessary for the software on the Surfaces, basic network services, and the real killer is making sure the Surface's can communicate with our domain controllers and vice versa.&amp;nbsp; We have 20 domain controllers that these devices could be possibly communicating with at any given point in time.&amp;nbsp; So 20 inbound rules, 20 outbound rules, not locking down to ports, that's 40 rules just to ensure proper domain configuration.&amp;nbsp; &lt;A href="https://community.cisco.com//u1/163273"&gt;cfnisupport&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 13:56:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573794#M519974</guid>
      <dc:creator>jordan.villarreal</dc:creator>
      <dc:date>2017-11-14T13:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: WLC ACL Limit</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573795#M519978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are in healthcare, so we have a ton of devices. Think IVPumps, mobile x-rays, tablets providers use, tablets patients touch, mobile glucose test machines which upload their devices. Heck, even our emergency lights and our wall clocks are all on WiFi. As you can imagine, we can quickly blow past 64x64.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My favorite part about the video Jason posted? Just after a minute in, it states there is nothing to 'bolt on'. But that's not true. We need to bolt on an ASA! &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/wink.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 14:35:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573795#M519978</guid>
      <dc:creator>cfnisupport</dc:creator>
      <dc:date>2017-11-14T14:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: WLC ACL Limit</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573796#M519981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes at the enforcement point you have to bolt on a device capable of enforcement based off the SGT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recommend reaching out to trustsec community about anything further about trustsec, I understand a meeting is being setup. Please work with them further&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Nov 2017 14:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573796#M519981</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-14T14:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: WLC ACL Limit</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573797#M519983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Spent some time with the guys tonight on a webex.&lt;/P&gt;&lt;P&gt;Went through wireless operation with TrustSec and how it could dramatically help with TCAM limits on WLCs.&lt;/P&gt;&lt;P&gt;Available to help further if needed.&lt;/P&gt;&lt;P&gt;Regards, Jonothan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 19:26:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-acl-limit/m-p/3573797#M519983</guid>
      <dc:creator>jeaves@cisco.com</dc:creator>
      <dc:date>2017-11-15T19:26:07Z</dc:date>
    </item>
  </channel>
</rss>

