<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vlan/ACL question in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/vlan-acl-question/m-p/1923902#M163911</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your ap are in local mode you won't Ned ti change the port as the traffic is ingress/egress at the WLC. So long as VLAN 3 is allowed there it will be fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the ACL, I'd put it on the Layer 3 interface of the switch/router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Mar 2012 00:35:42 GMT</pubDate>
    <dc:creator>Stephen Rodriguez</dc:creator>
    <dc:date>2012-03-29T00:35:42Z</dc:date>
    <item>
      <title>Vlan/ACL question</title>
      <link>https://community.cisco.com/t5/wireless/vlan-acl-question/m-p/1923901#M163910</link>
      <description>&lt;P&gt;I am in the process of getting my guest access set up on my network and I have a couple of questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) On my L3 switch I currently have the switch port with the command line of &lt;EM&gt;switchport access vlan 2&lt;/EM&gt; for my current wireless network. I am looking to add vlan 3 for the guest wireless access. Should I add/change that line to &lt;EM&gt;switchport trunk allow vlan 2,3&lt;/EM&gt; for each port I have my APs plugged into?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) I am having issues with my ACLs. All I want my guest vlan to do is go to the internet, nothing more. Is it better to place this ACL on the WCL, L3 switch or ASA? When I try it on the WLC, even when I deny ICMP both ways, I am still able to ping and I do have the ACL applied to the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:53:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/vlan-acl-question/m-p/1923901#M163910</guid>
      <dc:creator>jpgleason</dc:creator>
      <dc:date>2021-07-04T04:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan/ACL question</title>
      <link>https://community.cisco.com/t5/wireless/vlan-acl-question/m-p/1923902#M163911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your ap are in local mode you won't Ned ti change the port as the traffic is ingress/egress at the WLC. So long as VLAN 3 is allowed there it will be fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the ACL, I'd put it on the Layer 3 interface of the switch/router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2012 00:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/vlan-acl-question/m-p/1923902#M163911</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-03-29T00:35:42Z</dc:date>
    </item>
  </channel>
</rss>

