<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic under the WLAN config, you in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578494#M175774</link>
    <description>&lt;P&gt;under the WLAN config, you can set the Peer to Peer action to disable, drop, or forward upstream.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
    <pubDate>Sat, 27 Dec 2014 14:24:31 GMT</pubDate>
    <dc:creator>Stephen Rodriguez</dc:creator>
    <dc:date>2014-12-27T14:24:31Z</dc:date>
    <item>
      <title>peer-to-peer blocking / SGT / upstream behavior</title>
      <link>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578493#M175773</link>
      <description>&lt;P&gt;Is there a way to take a WLC 5508, enable peer-to-peer blocking functionality and send the traffic up stream to be ran through an ACL and then sent back down to the WLC 5508 back into the same WLAN?&amp;nbsp; A switch typically won't forward traffic out the port it came in on right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know this sounds crazy but I want to use ISE to apply a Security Group Tag to hosts and then use a higher powered switch to filter traffic rather than doing it on the WLC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is for hosts on the same WLAN to have or not have access to each other based on Authentication / SGT.&amp;nbsp; For instance if Joe authenticates all of Joe's device can talk to each other.&amp;nbsp; If Mary authenticates all of Mary's devices can talk as well.&amp;nbsp; However, based on security group tagging and SGACLs Mary's devices cannot talk to Joe's.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:11:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578493#M175773</guid>
      <dc:creator>schaef350</dc:creator>
      <dc:date>2021-07-05T09:11:17Z</dc:date>
    </item>
    <item>
      <title>under the WLAN config, you</title>
      <link>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578494#M175774</link>
      <description>&lt;P&gt;under the WLAN config, you can set the Peer to Peer action to disable, drop, or forward upstream.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Sat, 27 Dec 2014 14:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578494#M175774</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2014-12-27T14:24:31Z</dc:date>
    </item>
    <item>
      <title>Thanks for the quick response</title>
      <link>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578495#M175775</link>
      <description>&lt;P&gt;Thanks for the quick response Steve.&amp;nbsp; However, I am already aware of that setting.&amp;nbsp; My question focuses more the the switching that will happen once the traffic is pushed up stream.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"A switch typically won't forward traffic out the port it came in on right?"&lt;/P&gt;&lt;P&gt;This is based on what I have read in the peer-to-peer blocking section of the docs here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-0/configuration/guide/c70/c70wlan.html#wp1209597&lt;/P&gt;&lt;P&gt;"In controller software releases prior to 4.2, peer-to-peer blocking is applied globally to all clients on all WLANs and causes traffic between two clients on the same VLAN to be transferred to the upstream VLAN rather than being bridged by the controller. This behavior usually results in traffic being dropped at the upstream switch because switches do not forward packets out the same port on which they are received."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Dec 2014 14:57:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578495#M175775</guid>
      <dc:creator>schaef350</dc:creator>
      <dc:date>2014-12-27T14:57:55Z</dc:date>
    </item>
    <item>
      <title>hi, i think the peer-to-peer</title>
      <link>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578496#M175776</link>
      <description>&lt;P&gt;hi, i think the peer-to-peer blocking option forward upstream will achieve this. it ll forward to the default gateway of the vlan where you can apply the ACL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;am not 100% sure about this but you can give it a shot.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jan 2015 22:28:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578496#M175776</guid>
      <dc:creator>Viten Patel</dc:creator>
      <dc:date>2015-01-17T22:28:13Z</dc:date>
    </item>
    <item>
      <title>Hey have you figure it out</title>
      <link>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578497#M175777</link>
      <description>&lt;P&gt;To make things work you need to enable 2 commands in the SVI so you can forward traffic in the same interface&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 22:54:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/2578497#M175777</guid>
      <dc:creator>payala</dc:creator>
      <dc:date>2016-03-02T22:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Hey have you figure it out</title>
      <link>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/3394553#M175778</link>
      <description>There's the two commands must be enable in the SVI&lt;BR /&gt; ip local-proxy-arp&lt;BR /&gt; ip route-cache same-interface&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Jun 2018 19:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/3394553#M175778</guid>
      <dc:creator>telematique</dc:creator>
      <dc:date>2018-06-05T19:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Hey have you figure it out</title>
      <link>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/4488345#M234640</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/60555"&gt;@telematique&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same Problem with Cisco C9800 Wifi Controller...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to apply the two commands ... ?&lt;/P&gt;&lt;P&gt;On the Switch ? Or on WLC ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use Cisco SG300 Switch and C9800 Wifi Controller with C9120 AP's...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSID ist Flexconnect Local Switching.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is possible ?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 07:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/4488345#M234640</guid>
      <dc:creator>florian.hanig1</dc:creator>
      <dc:date>2021-10-19T07:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Hey have you figure it out</title>
      <link>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/4489470#M234718</link>
      <description>&lt;P&gt;I don't know if it possible on a SG300 switch but you need to configure this on the SVI of the router that fronting your wlc.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 20:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peer-to-peer-blocking-sgt-upstream-behavior/m-p/4489470#M234718</guid>
      <dc:creator>telematique</dc:creator>
      <dc:date>2021-10-20T20:30:33Z</dc:date>
    </item>
  </channel>
</rss>

