<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC time based ACL in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3677353#M207532</link>
    <description>&lt;P&gt;Hi Leo,&lt;/P&gt;
&lt;P&gt;Sorry for the delay, I had no access to the device over the weekend.&lt;/P&gt;
&lt;P&gt;The ACL is literally, deny all IPs/all protocols, inbound&amp;amp;outbound.&lt;/P&gt;
&lt;P&gt;Would it be possible to do it without a core switch? let say all I have is the WLC and the AP.&lt;/P&gt;
&lt;P&gt;It seems I can block the client that connect to the AP from accessing anything any IP/website. But they can still connect to the SSID. If I apply the ACL to the dynamic interface then it rejects it but that won't be time based.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Jul 2018 12:18:08 GMT</pubDate>
    <dc:creator>momo33</dc:creator>
    <dc:date>2018-07-30T12:18:08Z</dc:date>
    <item>
      <title>WLC time based ACL</title>
      <link>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3675507#M207527</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm using 8.5.131 and I can't figure out how to block clients from joining a WLAN for specific time and day.&lt;/P&gt;
&lt;P&gt;I created an ACL that denies everything inbound and outbound. Then I create a local policy and just set the ACl, the time and days and the vlan id. I applied the policy to policy-mapping to the WLAN and saved configuration.&lt;/P&gt;
&lt;P&gt;Any clients can still access it at any time.&lt;/P&gt;
&lt;P&gt;What am I missing?&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 15:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3675507#M207527</guid>
      <dc:creator>momo33</dc:creator>
      <dc:date>2021-07-05T15:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: WLC time based ACL</title>
      <link>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3675535#M207528</link>
      <description>One thing is the logs show:&lt;BR /&gt;*Dot1x_NW_MsgTask_4: Jul 26 12:02:52.249: %HREAP-7-ACL_ENTRY_DONOT_EXIST: hreap.c:9409 Unable to find an ACL by name "xxxxxx".&lt;BR /&gt;The ACL is there and the name matches.</description>
      <pubDate>Thu, 26 Jul 2018 16:07:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3675535#M207528</guid>
      <dc:creator>momo33</dc:creator>
      <dc:date>2018-07-26T16:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: WLC time based ACL</title>
      <link>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3675893#M207529</link>
      <description>The time-based ACL should be applied to the VLAN which also happens to be the default gateway to the dynamic interface.</description>
      <pubDate>Thu, 26 Jul 2018 23:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3675893#M207529</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2018-07-26T23:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: WLC time based ACL</title>
      <link>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3676339#M207530</link>
      <description>&lt;P&gt;Hi Leo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your quick response. I'm not sure I understand what you mean by "ACL should be applied to the VLAN", I got the vlan id set in the local policy matching the VLAN set for the AP and controller.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 15:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3676339#M207530</guid>
      <dc:creator>momo33</dc:creator>
      <dc:date>2018-07-27T15:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: WLC time based ACL</title>
      <link>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3676617#M207531</link>
      <description>Ok, so you're trying to stop people from joining an SSID on certain times of day.  &lt;BR /&gt;So let's say that the SSID is mapped to Dynamic Interface called "WORK".  This Dynamic Interface has a subnet of 1.1.1.0/20 and is being "hosted" by a core switch somewhere. &lt;BR /&gt;Put the time-based ACL on this core switch and apply the ACL to the VLAN that is hosting the 1.1.1.0/20 subnet.&lt;BR /&gt;Another thing, please post the ACL.</description>
      <pubDate>Fri, 27 Jul 2018 23:43:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3676617#M207531</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2018-07-27T23:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: WLC time based ACL</title>
      <link>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3677353#M207532</link>
      <description>&lt;P&gt;Hi Leo,&lt;/P&gt;
&lt;P&gt;Sorry for the delay, I had no access to the device over the weekend.&lt;/P&gt;
&lt;P&gt;The ACL is literally, deny all IPs/all protocols, inbound&amp;amp;outbound.&lt;/P&gt;
&lt;P&gt;Would it be possible to do it without a core switch? let say all I have is the WLC and the AP.&lt;/P&gt;
&lt;P&gt;It seems I can block the client that connect to the AP from accessing anything any IP/website. But they can still connect to the SSID. If I apply the ACL to the dynamic interface then it rejects it but that won't be time based.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 12:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3677353#M207532</guid>
      <dc:creator>momo33</dc:creator>
      <dc:date>2018-07-30T12:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: WLC time based ACL</title>
      <link>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3677373#M207533</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/563195"&gt;@momo33&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Would it be possible to do it without a core switch? let say all I have is the WLC and the AP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Sure.&amp;nbsp; The ACL can be applied to a router.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 12:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3677373#M207533</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2018-07-30T12:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: WLC time based ACL</title>
      <link>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3677398#M207534</link>
      <description>&lt;P&gt;what I meant was: can it be done on the WLC alone? It seems to have everything it needs but it's not performing as configured. Why would I need to apply the ACL anywhere else if I can apply it to a policy and then apply that policy to the SSID?&lt;/P&gt;
&lt;P&gt;Like I said I can block the client from accessing any website but not from connecting to the SSID.&lt;/P&gt;
&lt;P&gt;I'm confused on why there would be all those settings but they are useless without a core switch.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 12:46:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3677398#M207534</guid>
      <dc:creator>momo33</dc:creator>
      <dc:date>2018-07-30T12:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: WLC time based ACL</title>
      <link>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3677403#M207535</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is best to block from the router which is "hosting" the default gateway.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 12:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-time-based-acl/m-p/3677403#M207535</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2018-07-30T12:48:39Z</dc:date>
    </item>
  </channel>
</rss>

