<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You can use FlexConnect in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598045#M161428</link>
    <description>&lt;P&gt;You can use FlexConnect groups for this, this feature can be found under the &lt;EM&gt;wireless&lt;/EM&gt; tab from the main menu. First configure your FlexConnect ACL and then assign it to the correct WLAN ID in the FlexConnect group. Don't forget to assign your AP's to the new created FlexConnect group(s).&lt;/P&gt;</description>
    <pubDate>Thu, 18 Dec 2014 20:22:54 GMT</pubDate>
    <dc:creator>Freerk Terpstra</dc:creator>
    <dc:date>2014-12-18T20:22:54Z</dc:date>
    <item>
      <title>ACL mapping in flexconnect</title>
      <link>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598044#M161427</link>
      <description>wireless lan controller</description>
      <pubDate>Mon, 05 Jul 2021 09:08:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598044#M161427</guid>
      <dc:creator>Jorge Conceicao</dc:creator>
      <dc:date>2021-07-05T09:08:35Z</dc:date>
    </item>
    <item>
      <title>You can use FlexConnect</title>
      <link>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598045#M161428</link>
      <description>&lt;P&gt;You can use FlexConnect groups for this, this feature can be found under the &lt;EM&gt;wireless&lt;/EM&gt; tab from the main menu. First configure your FlexConnect ACL and then assign it to the correct WLAN ID in the FlexConnect group. Don't forget to assign your AP's to the new created FlexConnect group(s).&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2014 20:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598045#M161428</guid>
      <dc:creator>Freerk Terpstra</dc:creator>
      <dc:date>2014-12-18T20:22:54Z</dc:date>
    </item>
    <item>
      <title>Hi FreerkThx for your answer</title>
      <link>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598046#M161429</link>
      <description>&lt;P&gt;Hi Freerk&lt;/P&gt;&lt;P&gt;Thx for your answer but u can only assign flexconnect acl to vlan ID&amp;nbsp;not wlan ID, thats the problem I have.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 09:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598046#M161429</guid>
      <dc:creator>Jorge Conceicao</dc:creator>
      <dc:date>2014-12-19T09:22:44Z</dc:date>
    </item>
    <item>
      <title>Hi Jorge,I tested your</title>
      <link>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598047#M161430</link>
      <description>&lt;P&gt;Hi Jorge,&lt;BR /&gt;&lt;BR /&gt;I tested your configuration and I see what your problem is. My proposed solution only works for centrally switches WLAN ID's, which is useless in this case and also a little strange (you should think that when you create a WLAN - ACL mapping under a FlexConnect group, it would be pushed to the AP instead of doing it on the WLC..). I guess that the internal working for filtering on the AP has to been changed before this can be done, because right now an ACL is being applied to the physical (sub)interface.&lt;BR /&gt;&lt;BR /&gt;I'm afraid that there is no other solution besides using different VLAN's, which is the better solution anyway.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Dec 2014 15:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598047#M161430</guid>
      <dc:creator>Freerk Terpstra</dc:creator>
      <dc:date>2014-12-20T15:16:01Z</dc:date>
    </item>
    <item>
      <title>I don't see that you will be</title>
      <link>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598048#M161431</link>
      <description>&lt;P&gt;I don't see that you will be able to apply ACL on WLAN, You can only apply VLAN.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2015 01:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598048#M161431</guid>
      <dc:creator>Abhishek Abhishek</dc:creator>
      <dc:date>2015-02-20T01:58:44Z</dc:date>
    </item>
    <item>
      <title>Jorge Check the following</title>
      <link>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598049#M161432</link>
      <description>&lt;P&gt;&lt;SPAN class="fullname" itemprop="author"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/jorgeconceicaocomptapt" title="View user profile."&gt;Jorge Check the following&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Restrictions for FlexConnect ACLs&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; FlexConnect ACLs can be applied only to FlexConnect access points. The configurations applied are per AP and per VLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; You can configure up to 512 ACLs on a controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Non-FlexConnect ACLs that are configured on the controller cannot be applied to a FlexConnect AP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; FlexConnect ACLs do not support direction per rule. Unlike normal ACLs, Flexconnect ACLs cannot be configured with a direction. An ACL as a whole needs to be applied to an interface as ingress or egress.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; You can define up to 512 FlexConnect ACLs, each with up to 64 rules (or filters). Each rule has parameters that affect its action. When a packet matches all the parameters pertaining to a rule, the action set pertaining to that rule is applied to the packet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACLs in your network might have to be modified because Control and Provisioning of Wireless Access Points (CAPWAP) use ports that are different from the ones used by the Lightweight Access Point Protocol (LWAPP).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; All ACLs have an implicit deny all rule as the last rule. If a packet does not match any of the rules, it is dropped by the corresponding access point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACLs mapping on the VLANs that are created on an AP using WLAN-VLAN mapping, should be performed on a per-AP basis only. VLANs can be created on a FlexConnect group for AAA override. These VLANs will not have any mapping for a WLAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACLs for VLANs that are created on a FlexConnect group should be mapped only on the FlexConnect group. If the same VLAN is present on the corresponding AP as well as the FlexConnect group, AP VLAN will take priority. This means that if no ACL is mapped on the AP, the VLAN will not have any ACL, even if the ACL is mapped to the VLAN on the FlexConnect group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: This will give you clear idea How and what kind of ACL can be applied in flex connect mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ref: http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010001110.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 20:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acl-mapping-in-flexconnect/m-p/2598049#M161432</guid>
      <dc:creator>gohussai</dc:creator>
      <dc:date>2015-03-19T20:39:32Z</dc:date>
    </item>
  </channel>
</rss>

