<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks George ,For the number in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709221#M115271</link>
    <description>&lt;P&gt;Thanks George ,&lt;/P&gt;&lt;P&gt;For the number 66 acl lines&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;&lt;STRONG&gt;" I do however use an acl on the controller to block WLC management traffic ."&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;Why and what is the benefit&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 26 Jul 2015 03:24:41 GMT</pubDate>
    <dc:creator>susim</dc:creator>
    <dc:date>2015-07-26T03:24:41Z</dc:date>
    <item>
      <title>Wlc and acl</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709215#M115265</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ACL in Wireless Controller vs Acl&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the &amp;nbsp;recommended practice, &amp;nbsp;applying acl on interface vlan or &amp;nbsp;acl inside the WLC&lt;/P&gt;&lt;P&gt;what are the merits and demerits on applying acl in WLC over&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 10:37:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709215#M115265</guid>
      <dc:creator>susim</dc:creator>
      <dc:date>2021-07-05T10:37:39Z</dc:date>
    </item>
    <item>
      <title>What is the  recommended</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709216#M115266</link>
      <description>&lt;PRE&gt;
&lt;SPAN style="font-size: 14.3999996185303px;"&gt;What is the  recommended practice,  applying acl on interface vlan or  acl inside the WLC&lt;/SPAN&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;The recommended "best practice" is to stick the ACL nearest to the core switch AND keep ACL away from the WLC. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2015 06:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709216#M115266</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2015-07-23T06:03:29Z</dc:date>
    </item>
    <item>
      <title>Thanks leo The recommended</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709217#M115267</link>
      <description>&lt;P&gt;Thanks leo&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;The recommended "best practice" is to stick the ACL nearest to the core switch AND keep ACL away from the WLC. &amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that is the case , what is the purpose of &amp;nbsp;acl in WLC&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2015 22:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709217#M115267</guid>
      <dc:creator>susim</dc:creator>
      <dc:date>2015-07-25T22:03:38Z</dc:date>
    </item>
    <item>
      <title>My 2 cents .. Keep the acl as</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709218#M115268</link>
      <description>&lt;P&gt;My 2 cents .. Keep the acl as close to the edge as possible so the traffic doesn't drive across the network just to get dropped.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However the ACL on the WLC beyond normal reasoning. In some cases you need to have an acl in both directions to allow traffic to pass. You also have a hard limitation of 66 acl lines or some number close to it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case I avoid the acls on the controller and place on the upstream switch the controller plugs into. I do however use an acl on the controller to block WLC management traffic ..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2015 22:13:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709218#M115268</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2015-07-25T22:13:01Z</dc:date>
    </item>
    <item>
      <title>If that is the case , what is</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709219#M115269</link>
      <description>&lt;PRE&gt;
&lt;SPAN style="font-size: 14.3999996185303px;"&gt;If that is the case , what is the purpose of  acl in WLC&lt;/SPAN&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;ACL function in the WLC is an OPTIONAL feature. &amp;nbsp;It has it's uses but due to the limitation of what the WLC ACL can/can't do it's really difficult to justify sticking an ACL in the WLC. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jul 2015 01:24:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709219#M115269</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2015-07-26T01:24:06Z</dc:date>
    </item>
    <item>
      <title>Hi,core---distribution-</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709220#M115270</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;core---distribution--access&lt;/P&gt;&lt;P&gt;f i keep wlc at access layer , would it be bad idea ? . (wlc and access point are in same subnet) .ssid's are differnet vlan at the same access layer .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would it be better if i keep in core . ?&lt;/P&gt;&lt;P&gt;Can you give just an overview how &amp;nbsp;a client associate to a AP and &amp;nbsp;WLC , and how the traffic flows to the distribution layer .&lt;/P&gt;&lt;P&gt;The below&amp;nbsp;&amp;nbsp;one would be a dump question .&amp;nbsp;if the best practice is to drop the traffic at the nearest , the nearest place must be at WLC ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jul 2015 03:06:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709220#M115270</guid>
      <dc:creator>susim</dc:creator>
      <dc:date>2015-07-26T03:06:21Z</dc:date>
    </item>
    <item>
      <title>Thanks George ,For the number</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709221#M115271</link>
      <description>&lt;P&gt;Thanks George ,&lt;/P&gt;&lt;P&gt;For the number 66 acl lines&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;&lt;STRONG&gt;" I do however use an acl on the controller to block WLC management traffic ."&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;Why and what is the benefit&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jul 2015 03:24:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709221#M115271</guid>
      <dc:creator>susim</dc:creator>
      <dc:date>2015-07-26T03:24:41Z</dc:date>
    </item>
    <item>
      <title>f i keep wlc at access layer</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709222#M115272</link>
      <description>&lt;PRE&gt;
&lt;SPAN style="font-size: 14.399998664856px;"&gt;f i keep wlc at access layer , would it be bad idea ?&lt;/SPAN&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;SPAN style="font-size: 14.399998664856px;"&gt;Very bad idea. &amp;nbsp;WLC is designed to be in a core network. &amp;nbsp;WLC is also suitable for distro but it is very, very rare to find a WLC in the access layer. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jul 2015 04:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709222#M115272</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2015-07-26T04:30:38Z</dc:date>
    </item>
    <item>
      <title>HiThanks Leo , Is it ok</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709223#M115273</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thanks Leo , Is it ok placing the AP &amp;nbsp;and controller in the same vlan ?.&lt;/P&gt;&lt;P&gt;What would be the benefit and drawbacks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2015 04:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709223#M115273</guid>
      <dc:creator>susim</dc:creator>
      <dc:date>2015-07-28T04:21:55Z</dc:date>
    </item>
    <item>
      <title>Is it ok placing the AP  and</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709224#M115274</link>
      <description>&lt;PRE style="font-size: 14.3999996185303px;"&gt;
 Is it ok placing the AP  and controller in the same vlan ?.

What would be the benefit and drawbacks &lt;/PRE&gt;

&lt;P&gt;Depends on the size and shape of the network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For lab purposes, this is fine.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're going to connect multiple sites or buildings over a Layer 3 network, the WLC should "live" in the core network.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2015 05:24:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709224#M115274</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2015-07-28T05:24:29Z</dc:date>
    </item>
    <item>
      <title>Hi, Here is setup wlc ip 10.0</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709225#M115275</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is setup&amp;nbsp;&lt;/P&gt;&lt;P&gt;wlc ip 10.0.50.10 /24&lt;BR /&gt;ap 10.0.50.x (same subnet)&lt;/P&gt;&lt;P&gt;client &amp;nbsp;-10.0.x.x /24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the client is redirected to ISE once they conneced &amp;nbsp;for authentication .&lt;BR /&gt;ofcourse client cannot browse unless they authenticated&amp;nbsp;&lt;BR /&gt;the problem is before authentication the client can see the port is opened or not .&lt;BR /&gt;How can i solve this issue . putting an acl on the wlc will solve this issue or there is something i am missing .&amp;nbsp;&lt;/P&gt;&lt;P&gt;on the client vlan i have an access list .&amp;nbsp;&lt;BR /&gt;but no access list on ap and wlc vlan&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2015 00:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-acl/m-p/2709225#M115275</guid>
      <dc:creator>susim</dc:creator>
      <dc:date>2015-08-02T00:57:20Z</dc:date>
    </item>
  </channel>
</rss>

