<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC C9800 AirSpace ACL does not get applied in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4543240#M237817</link>
    <description>&lt;P&gt;got resolved with switching to the Common Tasks /&amp;nbsp;Airespace ACL Name check-box enablement instead of&amp;nbsp;cisco-av-pair = AireSpace-ACL-Name=blah-blah.&lt;/P&gt;&lt;P&gt;Effectively, it gets treated on WLC as Filter-ID &amp;amp; shown under Monitoring / Wireless / Clients / &amp;lt;client&amp;gt; / General / Security Information / Server Policies|Resultant Policies&lt;/P&gt;&lt;P&gt;thanks to all&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Feb 2022 10:45:26 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2022-02-01T10:45:26Z</dc:date>
    <item>
      <title>WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539334#M237591</link>
      <description>&lt;P&gt;Hello Community&lt;/P&gt;&lt;P&gt;i've amazing misbehavour with scenario where i need to restrict vast majority of clients of locally switched SSID toward sensitive subnet while allowing specific clients to access this subnet. for this to work i've configured ACL denying IP to this subnet &amp;amp; allowing everything else on the WLC &amp;amp; configured 2 AuthZ policies on ISE: 1st match restriction &amp;amp; apply result with ACL-name ; 2nd match specific clients attributes &amp;amp; doesnt apply any restrictions. The issue i met the ACL never gets applied to 1st case client session...&lt;BR /&gt;i was trying Filter-ID attribute, i was trying AirSpaceACL checkbox in AuthZ profile with always the same result - ACL doesnt get applied.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have AuthZ method list name configured on the WLC also coded as Method-List AV pair in the the AuthZ profile &amp;amp; all the prerequisites met for the scenario to work but...&lt;/P&gt;&lt;P&gt;I've opened TAC case running since 1w+ already w/o any progress with all verifications from TAC side implemented that's why i decided to ask community if anyone ever met such n issue.&lt;/P&gt;&lt;P&gt;WLC runs&amp;nbsp;17.3.3, ISE 2.7 patch 6, APs r in flexconnect mode &amp;amp; SSID is locally switched. Any idea pls?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 14:56:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539334#M237591</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2022-01-26T14:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539362#M237595</link>
      <description>&lt;P&gt;Have you opened the TAC case with the ISE team or the wireless team.&amp;nbsp; You are better off making sure they both have a look.&amp;nbsp; I haven't tried a dACL using FlexConnect, but wouldn't it be easier to have two vlan's and then use rules to place a device on on or the other vlan?&amp;nbsp; Any way's, when I do any testing, I always have to play with rules to ensure a rules catches what I need.&amp;nbsp; Maybe what the controller is sending back isn't being read by ISE.&amp;nbsp; Thats when you might have to look for a different way to identify these devices.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 15:17:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539362#M237595</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2022-01-26T15:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539379#M237599</link>
      <description>&lt;P&gt;Hi Scott&lt;/P&gt;&lt;P&gt;TAC case is only in wireless team. The same is working on the AIR-OS w/o any problem.&lt;/P&gt;&lt;P&gt;we dont use dACL in this scenario &amp;amp; creation of separate SSID/VLAN is not n option.&lt;/P&gt;&lt;P&gt;Not sure about what WLC tells ISE during AuthZ phase, but debug on WLC shows ISE communicates AVs properly, &amp;amp; at the end WLC just omits any references to what it was doing with ACL &amp;amp; mumbling something about AuthZ Method-List it received.&lt;/P&gt;&lt;P&gt;2022/01/20 09:18:31.000165 {wncd_x_R0-0}{2}: [auth-mgr-feat_wireless] [18316]: (info): [5076.af47.945b:capwap_90000027]&amp;nbsp; - authc_list: DOT1x_auth_ISE&lt;/P&gt;&lt;P&gt;2022/01/20 09:18:31.000167 {wncd_x_R0-0}{2}: [auth-mgr-feat_wireless] [18316]: (info): [5076.af47.945b:capwap_90000027]&amp;nbsp; - authz_list: Not present under wlan configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2022/01/20 09:19:12.879716 {wncd_x_R0-0}{2}: [auth-mgr] [18316]: (info): [5076.af47.945b:capwap_90000027] User profile is to be applied. Authz mlist is not present, Authc mlist DOT1x_auth_ISE ,session push flag is unset&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 15:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539379#M237599</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2022-01-26T15:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539391#M237602</link>
      <description>&lt;P&gt;I wouldn't ever compare AireOS and IOS... things are just not the same and thats from my experience.&amp;nbsp; From what you stated, that tells me that the rules work for AireOS, so shouldn't be an issue (?) with the 9800's but you never know.&amp;nbsp; Sorry but I haven't had to apply any acl's for our SSID's, but it would be interesting to find out what the solution is.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 15:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539391#M237602</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2022-01-26T15:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539403#M237604</link>
      <description>&lt;P&gt;of course, IOS-XE is not n AIR-OS that's particularly dACL r not recommended on the IOS-XE at all &amp;amp; for AirSpace ACL to work one needs to configure AuthZ method-list AV in the AuthZ-profile on ISE etc etc etc. what i wanted to say that whatever dynamic ACL application approach one chooses in AIR-OS case it will work if properly (meaning considering all prerequisites) configured on the WLC &amp;amp; ISE. it's totally not the case for IOS-XE for wireless...&lt;BR /&gt;surely will keep tread updated with Cisco TAC's findings...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 15:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539403#M237604</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2022-01-26T15:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539519#M237619</link>
      <description>&lt;P&gt;Can you post your Flex profile? Did you push the ACL to the AP?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2022-01-26 211747.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/142280i67F2E5A72A88F8D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-01-26 211747.png" alt="Screenshot 2022-01-26 211747.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I would also like to know whether you have enabled central authentication under Policy profile or local authentication directly from AP? (NAD's are WLC or AP's in WLC?)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also note only exteneded ACL's are supported by Flex AP's. Also you can do a RA trace for a client while connecting to this SSID to see whether the Radius server is sending required parameters.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 17:25:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539519#M237619</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-01-26T17:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539554#M237627</link>
      <description>&lt;P&gt;Hi Arshad&lt;/P&gt;&lt;P&gt;pls find screens attached. from my perspective everything looks like it has to be, can u confirm?&lt;/P&gt;&lt;P&gt;Also, yes, we use extended ACLs (standard only works with SRC).&lt;/P&gt;&lt;P&gt;&amp;amp; yes we did RA-trace with TAC. WLC receives needed attributes:&lt;/P&gt;&lt;P&gt;,,,&lt;BR /&gt;2022/01/20 09:19:12.878948 {wncd_x_R0-0}{2}: [radius] [18316]: (info): RADIUS: Cisco AVpair [1] 34 "Method-List=DOT1x_author_ISE"&lt;BR /&gt;2022/01/20 09:19:12.878957 {wncd_x_R0-0}{2}: [radius] [18316]: (info): RADIUS: Cisco AVpair [1] 40 "AireSpace-ACL-Name=acl-No-Office-2-LAB"&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;But there is no ACL in&amp;nbsp;Applied attributes.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 17:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539554#M237627</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2022-01-26T17:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539751#M237638</link>
      <description>&lt;P&gt;Did you check on the AP whether the ACL is there? Login to the AP via CLI and "show ip access-list" verify the ACL you pushed is there in the AP?&lt;/P&gt;
&lt;P&gt;Also make sure that you save the tags on the AP.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 23:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4539751#M237638</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-01-26T23:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4540048#M237644</link>
      <description>&lt;P&gt;yes, ACLs r on APs. how can i check tags on AP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UPD. tags r also there (thanks to&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt; hint)&lt;/P&gt;&lt;P&gt;br andy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 18:04:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4540048#M237644</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2022-01-31T18:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4542341#M237738</link>
      <description>&lt;P&gt;“ap name &amp;lt;APname&amp;gt; write tag-config” saves the tags.&lt;/P&gt;
&lt;P&gt;From 17.6.1 tag persistency is introduced:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-6/config-guide/b_wl_17_6_cg/m_ap_tag_persistency.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-6/config-guide/b_wl_17_6_cg/m_ap_tag_persistency.html&lt;/A&gt;&amp;nbsp;That also includes info about show ap tag summary.&lt;/P&gt;
&lt;P&gt;Have you tried testing on a newer release like 17.6? There were a number of radius feature enhancements (to improve feature parity with AireOS) that went in between 17.3 and 17.6 which is why we're using 17.6 - our design simply didn't work on 17.3 as some commands appear in the config but are not implemented at all in the code.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jan 2022 16:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4542341#M237738</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-01-30T16:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4543240#M237817</link>
      <description>&lt;P&gt;got resolved with switching to the Common Tasks /&amp;nbsp;Airespace ACL Name check-box enablement instead of&amp;nbsp;cisco-av-pair = AireSpace-ACL-Name=blah-blah.&lt;/P&gt;&lt;P&gt;Effectively, it gets treated on WLC as Filter-ID &amp;amp; shown under Monitoring / Wireless / Clients / &amp;lt;client&amp;gt; / General / Security Information / Server Policies|Resultant Policies&lt;/P&gt;&lt;P&gt;thanks to all&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 10:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4543240#M237817</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2022-02-01T10:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4766673#M251051</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Actually I have successfully tested using "Airespace ACL" and "Filter-ID" separately, referencing ACL configured on WLC-9800.&amp;nbsp;Despite Cisco 9800 is IOS-XE, "Airespace ACL" also worked in my use case.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Note : Cisco WLC-9800 doesn't support dACL.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 11:35:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/4766673#M251051</guid>
      <dc:creator>RAMKURAGAYALA</dc:creator>
      <dc:date>2023-02-01T11:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: WLC C9800 AirSpace ACL does not get applied</title>
      <link>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/5366300#M288388</link>
      <description>&lt;P&gt;Download ACL is supported from IOS XE 17.10.1.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-10/release-notes/rn-17-10-9800.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-10/release-notes/rn-17-10-9800.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 11:47:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/m-p/5366300#M288388</guid>
      <dc:creator>hshimomu</dc:creator>
      <dc:date>2026-01-30T11:47:35Z</dc:date>
    </item>
  </channel>
</rss>

