<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic guest access list in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917241#M180903</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to identifiy your interfaces in the WLC as inbound and outbound. I just did a number id ACLs on the WLC for ISE and I had the same problem. Once I added the inbound and outbound life was good. Give that a shot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 18 Mar 2012 18:10:03 GMT</pubDate>
    <dc:creator>George Stefanick</dc:creator>
    <dc:date>2012-03-18T18:10:03Z</dc:date>
    <item>
      <title>guest access list</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917239#M180901</link>
      <description>&lt;P&gt;i have controller 5508 &lt;/P&gt;&lt;P&gt;i configure vlan 10 for guest and name guest-inter&lt;/P&gt;&lt;P&gt;ip 10.0.10.2/24&lt;/P&gt;&lt;P&gt;default gateway 10.0.10.254 ( ip address fo core switch)&lt;/P&gt;&lt;P&gt;dhcp server ( 10.20.10.10/24) ( ip dhcp server is the same ip for DNS server )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i create ssid name gest and choose interface guest-inter and choose web authentication &lt;/P&gt;&lt;P&gt;also there is blue coast proxy for internet 10.30.10.10/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i need guest user to access internet only &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what the access list need to apply for guest in the WLC to permite internet only &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i configured the access list in the controller and applied in the guest-inter interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- permit any any&amp;nbsp; udp&amp;nbsp; (source port dns)&amp;nbsp; ( destination port&amp;nbsp; any)&amp;nbsp;&amp;nbsp;&amp;nbsp; (direction any )&lt;/P&gt;&lt;P&gt;2-permite any any udp&amp;nbsp;&amp;nbsp; ( any )&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ( dns)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (any)&lt;/P&gt;&lt;P&gt;3- permite any&amp;nbsp; 10.20.10.10&amp;nbsp;&amp;nbsp; ip&amp;nbsp;&amp;nbsp; any&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any &lt;/P&gt;&lt;P&gt;4-permite&amp;nbsp; 10.20.10.10&amp;nbsp;&amp;nbsp; any&amp;nbsp; ip&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any &lt;/P&gt;&lt;P&gt;﻿5-permite any 10.30.10.10&amp;nbsp;&amp;nbsp; ip&amp;nbsp;&amp;nbsp;&amp;nbsp; any&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any &lt;/P&gt;&lt;P&gt;6- permite 10.30.10.10&amp;nbsp; any&amp;nbsp; ip&amp;nbsp;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp; any&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i put user name and password for guest and disply page access sucessful and stop &lt;/P&gt;&lt;P&gt;after that i can not access internet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please advice me &lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917239#M180901</guid>
      <dc:creator>mohammad abdul jawad</dc:creator>
      <dc:date>2021-07-04T04:48:33Z</dc:date>
    </item>
    <item>
      <title>guest access list</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917240#M180902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would rather put an ACL to block the inside access, as given below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit ip&amp;nbsp; any 10.30.10.10 ( here you can give a mask of 255.255.255.255 and specificallly the proxy port)&lt;/P&gt;&lt;P&gt;permit ip&amp;nbsp; any 10.20.10.10/24 ( ( here you can give a mask of 255.255.255.255 and the DNS port )&lt;/P&gt;&lt;P&gt;deny ip&amp;nbsp; 10.0.10.2/24 &lt;INSIDE_NETWORK&gt;&lt;/INSIDE_NETWORK&gt;&lt;/P&gt;&lt;P&gt;permit ip any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the image that you are using in the WLC, if the build is above 7.0.116.0 enable "WebAuth Proxy Redirection Mode" from the Controller page&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;NikhiL&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Mar 2012 04:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917240#M180902</guid>
      <dc:creator>nikhilcherian</dc:creator>
      <dc:date>2012-03-17T04:49:15Z</dc:date>
    </item>
    <item>
      <title>guest access list</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917241#M180903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to identifiy your interfaces in the WLC as inbound and outbound. I just did a number id ACLs on the WLC for ISE and I had the same problem. Once I added the inbound and outbound life was good. Give that a shot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Mar 2012 18:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917241#M180903</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-03-18T18:10:03Z</dc:date>
    </item>
    <item>
      <title>guest access list</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917242#M180904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; width: 1px; height: 1px; overflow: hidden; top: 0px; left: -10000px;"&gt;﻿&lt;/DIV&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;worked&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;by the same&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;things&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;you mentioned&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;but unfortunately&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the same thing ther is no changing .&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="hps"&gt;Please&lt;/SPAN&gt; if you have practical technical document for guest access-list send to me &lt;/P&gt;&lt;P&gt;or advice me .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2012 00:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917242#M180904</guid>
      <dc:creator>mohammad abdul jawad</dc:creator>
      <dc:date>2012-03-19T00:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: guest access list</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917243#M180905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Whatever you allow out, you need to explicitly allow back in as well. Unlike applying the acl to a svi where you only need one way. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said. I'd put the acl on the gateway svi instead if on the WLC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2012 00:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917243#M180905</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-03-19T00:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: guest access list</title>
      <link>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917244#M180906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I applied the access list in two directions, even before the possible but i&amp;nbsp; forget to mentioned in my previous letter&lt;BR /&gt;&lt;SPAN class="hps"&gt;I&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;will try to&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;apply in the layer 3 core switch and i will tell you the result .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2012 07:06:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-access-list/m-p/1917244#M180906</guid>
      <dc:creator>mohammad abdul jawad</dc:creator>
      <dc:date>2012-03-19T07:06:15Z</dc:date>
    </item>
  </channel>
</rss>

