<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco WLC Flexconnect DACL with ISE not working in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693567#M246420</link>
    <description>&lt;P&gt;Yes, i know about the bug. Is there any solution to restrict or deny some IPs for WIFI users.&lt;/P&gt;&lt;P&gt;WLC controller IOS-XE C9800.&lt;/P&gt;&lt;P&gt;ISE 2.7&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 07:59:53 GMT</pubDate>
    <dc:creator>islam.kamal</dc:creator>
    <dc:date>2022-09-26T07:59:53Z</dc:date>
    <item>
      <title>Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693357#M246409</link>
      <description>&lt;P&gt;I have an integration between Cisco ISE and WLC 9800. All AP with flexconnect mode, am trying to restrict access for some internal applications using ISE.&lt;/P&gt;&lt;P&gt;I created the ACL on WLC "extended ACL".&lt;/P&gt;&lt;P&gt;On ISE "profile authorization", i tried with the following:-&lt;/P&gt;&lt;P&gt;1- Airspace ACL "using created WLC ACL" not working.&lt;/P&gt;&lt;P&gt;2-ACL "filter In" not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any solution to push the ACL from ISE to WIFI users who connect to WIFI using flexconnect APs, kindly share the solution.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2022 18:29:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693357#M246409</guid>
      <dc:creator>islam.kamal</dc:creator>
      <dc:date>2022-09-25T18:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693545#M246416</link>
      <description>&lt;P&gt;Any advise,please.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 06:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693545#M246416</guid>
      <dc:creator>islam.kamal</dc:creator>
      <dc:date>2022-09-26T06:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693563#M246418</link>
      <description>&lt;P&gt;9800 doesn't officially support support DACL's yet. Please refer the enhancement bug&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You might be able to get it working since controller itself is running IOS-XE code, but however it is not officially supported and caused behavior which might impact other primary functions of WLC.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 07:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693563#M246418</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-09-26T07:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693567#M246420</link>
      <description>&lt;P&gt;Yes, i know about the bug. Is there any solution to restrict or deny some IPs for WIFI users.&lt;/P&gt;&lt;P&gt;WLC controller IOS-XE C9800.&lt;/P&gt;&lt;P&gt;ISE 2.7&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 07:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693567#M246420</guid>
      <dc:creator>islam.kamal</dc:creator>
      <dc:date>2022-09-26T07:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693575#M246422</link>
      <description>&lt;P&gt;You must create the ACL in WLC, and then make sure that is pushed to AP's via making required configuration changes in Flex profiles.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html#anc23:~:text=of%20the%20rules.-,Flexconnect%20Local%20Switching%20Access%20Points%20ONLY,-What%20if%20you" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html#anc23:~:text=of%20the%20rules.-,Flexconnect%20Local%20Switching%20Access%20Points%20ONLY,-What%20if%20you&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Flex Profile &amp;gt;&amp;gt; Policy ACL&lt;/P&gt;
&lt;P&gt;Also Make sure that you are running Cisco recommended IOS-XE codes as some older and short-lived codes have limitations with regards to Radius implementation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Refer the below post which is very helpful as well.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/wireless/wlc-c9800-airspace-acl-does-not-get-applied/td-p/4539334" target="_blank"&gt;Solved: WLC C9800 AirSpace ACL does not get applied - Cisco Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 08:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693575#M246422</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-09-26T08:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693588#M246423</link>
      <description>&lt;P&gt;Yes, now the issue how can i call the ACLwhich created on WLC by ISE.&lt;/P&gt;&lt;P&gt;Also the ACL to deny some application, not for redirect "i have to do a check mark for central web"&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 08:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693588#M246423</guid>
      <dc:creator>islam.kamal</dc:creator>
      <dc:date>2022-09-26T08:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693634#M246429</link>
      <description>&lt;P&gt;Hi Kamal,&lt;/P&gt;
&lt;P&gt;Below are radius attributes supported by 9800's. Configure them in you Cisco ISE Authorization profile.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Tunnel-Private-Group-ID = 1 &amp;lt;VLAN ID or name&amp;gt;&lt;/LI&gt;
&lt;LI&gt;Tunnel-Type = 1:13&lt;/LI&gt;
&lt;LI&gt;Tunnel-Medium-Type = 1:6&lt;/LI&gt;
&lt;LI&gt;Airespace:Airespace-Interface-Name = &amp;lt;name of vlan or vlan goup on WLC)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Airespace-ACL-Name = &amp;lt;ACL name configured in the WLC)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Highlighted is the one you should be focusing on. As mentioned before please make sure that you push the ACL to AP by configuring the Flex profile.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 09:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693634#M246429</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-09-26T09:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693651#M246431</link>
      <description>&lt;P&gt;Thanks Arshad, but still unable to apply the ACL and user has all permit access.I attached the configuration based on your recommendation.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 10:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693651#M246431</guid>
      <dc:creator>islam.kamal</dc:creator>
      <dc:date>2022-09-26T10:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693656#M246432</link>
      <description>&lt;P&gt;Appreciate your support, the WLC ACL in place and ISE use the same ACL "airespace ACL name".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 10:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693656#M246432</guid>
      <dc:creator>islam.kamal</dc:creator>
      <dc:date>2022-09-26T10:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693723#M246438</link>
      <description>&lt;P&gt;any idea&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 13:21:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693723#M246438</guid>
      <dc:creator>islam.kamal</dc:creator>
      <dc:date>2022-09-26T13:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco WLC Flexconnect DACL with ISE not working</title>
      <link>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693728#M246439</link>
      <description>&lt;P&gt;Hi Islam,&lt;/P&gt;
&lt;P&gt;Yes, ACL name and the Airspace ACL name must be same. You can do a radioactive trace from 9800 WLC to see what parameters ISE is sending and how the client is reacting to it. Alternatively, you can also do a PCAP to confirm radius messages are sent with the required parameters.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 13:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cisco-wlc-flexconnect-dacl-with-ise-not-working/m-p/4693728#M246439</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-09-26T13:41:35Z</dc:date>
    </item>
  </channel>
</rss>

