<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why we have to allow RRM port first in wlc 8.5 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605943#M241641</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;Yes, I also think so.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, based on my understanding, the two commands like the below should work for our purpose without other impact such as losing connection to WLC. Can I say it like this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;deny ip 10.10.10.0/24&amp;nbsp;&lt;/P&gt;&lt;P&gt;permit ip any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.10.10.0/24 is users devices ip address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 May 2022 20:05:08 GMT</pubDate>
    <dc:creator>Leftz</dc:creator>
    <dc:date>2022-05-06T20:05:08Z</dc:date>
    <item>
      <title>Why we have to allow RRM port first in wlc 8.5</title>
      <link>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605914#M241634</link>
      <description>&lt;P&gt;Hi We want to create CPU ACL at wlc 8.5. According to Cisco document to create the CPU ACL, why we have to allow these RRM port FIRST ? Can we just deny some client traffic and allow all for this purpose? Please see the below Cisco statement. Anyone can explain it? Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/access_control_lists.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/access_control_lists.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H2&gt;Applying an Access Control List to the Controller CPU (GUI)&lt;/H2&gt;&lt;H3&gt;&lt;EM&gt;Before you begin&lt;/EM&gt;&lt;/H3&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Before you apply ACL rules, ensure that you have explicitly set the following RRM ports to&amp;nbsp;allow&amp;nbsp;in the CPU ACL&lt;/STRONG&gt;:&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;EM&gt;12124-12125&lt;/EM&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;EM&gt;12134-12135&lt;/EM&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;EM&gt;Also ensure that you add these ACL rules specifically at the top of the ACL list.&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;EM&gt;If you do not set these RRM ports to&amp;nbsp;allow, the ports are blocked by default.&lt;/EM&gt;&lt;/P&gt;&lt;H3&gt;&lt;EM&gt;Procedure&lt;/EM&gt;&lt;/H3&gt;</description>
      <pubDate>Fri, 06 May 2022 18:58:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605914#M241634</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2022-05-06T18:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why we have to allow RRM port first in wlc 8.5</title>
      <link>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605923#M241635</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp; The idea of CPU ACL is to control (permit /deny) traffic send to the WLC itself. In networking this is called the Control plane traffic.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It turns out that the RRM traffic&amp;nbsp; as Control plane traffic and if you block it, WLC will not manage the network in terms of RF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;RRM is the Radio Resource management and is the algorithm responsible to control Channel, Power, etc, etc,.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;When you apply an ACL, you know that theres a implicit deny at the end. So, if you does not explicit permit those ports, they will be blocked with all control plance traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 19:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605923#M241635</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-05-06T19:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why we have to allow RRM port first in wlc 8.5</title>
      <link>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605930#M241638</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;Thanks Flavio for your respond.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;" When you apply an ACL, you know that theres a implicit deny at the end. So, if you does not explicit permit those ports, they will be blocked with all control plance traffic. ..... "&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I know, but if we do not use permit RRM at beginning, we can use permit to allow all at the end.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 19:37:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605930#M241638</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2022-05-06T19:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why we have to allow RRM port first in wlc 8.5</title>
      <link>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605938#M241640</link>
      <description>&lt;P&gt;yes you can and probably will work the same way. What cisco try to do is call the attention to the fact that RRM is control plance cause most people dont know that and may incorretly block it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 19:54:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605938#M241640</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-05-06T19:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why we have to allow RRM port first in wlc 8.5</title>
      <link>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605943#M241641</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;Yes, I also think so.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, based on my understanding, the two commands like the below should work for our purpose without other impact such as losing connection to WLC. Can I say it like this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;deny ip 10.10.10.0/24&amp;nbsp;&lt;/P&gt;&lt;P&gt;permit ip any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.10.10.0/24 is users devices ip address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 20:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605943#M241641</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2022-05-06T20:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why we have to allow RRM port first in wlc 8.5</title>
      <link>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605957#M241643</link>
      <description>&lt;P&gt;Keep in mind thart the network you permit there is the network from where you are going to manage the WLC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Do you manage you WLC from this network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;What about Prime or any management tool you may have? Or syslog server?&lt;/P&gt;&lt;P&gt;User devices sounds to me like wireless client which is not afffected by CPU ACL&lt;/P&gt;&lt;P&gt;furthermore, this means that anything can access your WLC,&amp;nbsp; except user devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;This does not look good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;The normal action here is you to permit the management network and deny everything else.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thats why cisco as to permit those port also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 20:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/why-we-have-to-allow-rrm-port-first-in-wlc-8-5/m-p/4605957#M241643</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-05-06T20:43:02Z</dc:date>
    </item>
  </channel>
</rss>

