<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Applying ACL on WLC for admin logon and AP's only in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4714570#M247783</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I intend to apply ACL on WLC to achieve following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Only admin should be able to logon into WLC from his IP&lt;/P&gt;&lt;P&gt;- Only AP's should be able to join WLC from their specific IP pool 10.202.x.x/24 (no other IP pool should be allowed from where AP can join WLC).&lt;/P&gt;&lt;P&gt;- Existing traffic flow shouldn't get disturbed. This may include end users internet/usual lan access, snmp monitoring etc.&lt;/P&gt;&lt;P&gt;Any help shall be highly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 05:05:45 GMT</pubDate>
    <dc:creator>usman_safdar</dc:creator>
    <dc:date>2022-11-02T05:05:45Z</dc:date>
    <item>
      <title>Applying ACL on WLC for admin logon and AP's only</title>
      <link>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4714570#M247783</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I intend to apply ACL on WLC to achieve following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Only admin should be able to logon into WLC from his IP&lt;/P&gt;&lt;P&gt;- Only AP's should be able to join WLC from their specific IP pool 10.202.x.x/24 (no other IP pool should be allowed from where AP can join WLC).&lt;/P&gt;&lt;P&gt;- Existing traffic flow shouldn't get disturbed. This may include end users internet/usual lan access, snmp monitoring etc.&lt;/P&gt;&lt;P&gt;Any help shall be highly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 05:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4714570#M247783</guid>
      <dc:creator>usman_safdar</dc:creator>
      <dc:date>2022-11-02T05:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Applying ACL on WLC for admin logon and AP's only</title>
      <link>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4714574#M247784</link>
      <description>&lt;P&gt;- Only admin should be able to logon into WLC from his IP&amp;nbsp; - This you may configured WLC GUI, I also prefer to have ACL where WLC Layer 3 interface connected.&lt;/P&gt;
&lt;P&gt;- Only AP's should be able to join WLC from their specific IP pool 10.202.x.x/24 (no other IP pool should be allowed from where AP can join WLC).&amp;nbsp; - Same as Above ACL on the Interface, or&amp;nbsp; add only Option 43 for that pool, Make sure AP connected port belongs to the same VLAN in the access port.&lt;/P&gt;
&lt;P&gt;- Existing traffic flow shouldn't get disturbed. This may include end users' internet/usual can access, SNMP monitoring etc.&amp;nbsp; - You can also use ACL, but suggest having FW in the network is always a good option (ACL hard to manage).&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 05:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4714574#M247784</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-11-02T05:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: Applying ACL on WLC for admin logon and AP's only</title>
      <link>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4715050#M247820</link>
      <description>&lt;P&gt;What is the WLC model you have?&lt;/P&gt;
&lt;P&gt;Do you have a dedicated management (service) port configured?&lt;/P&gt;
&lt;P&gt;Do you have an upstream firewall?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 17:30:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4715050#M247820</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-11-02T17:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Applying ACL on WLC for admin logon and AP's only</title>
      <link>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4715394#M247839</link>
      <description>&lt;P&gt;2504&lt;/P&gt;&lt;P&gt;not dedicated (its a trunk port used for 2 more vlans as well)&lt;/P&gt;&lt;P&gt;yes we have for a particular vlan (rest of the vlans are not routed vlans, being used for internet only)&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 08:17:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4715394#M247839</guid>
      <dc:creator>usman_safdar</dc:creator>
      <dc:date>2022-11-03T08:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Applying ACL on WLC for admin logon and AP's only</title>
      <link>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4715586#M247845</link>
      <description>&lt;P&gt;You need to use CPU ACL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.wiresandwi.fi/blog/wlc-cpu-acl" target="_blank"&gt;Cisco WLC CPU ACL — WIRES AND WI.FI&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/access_control_lists.html" target="_blank"&gt;Cisco Wireless Controller Configuration Guide, Release 8.5 - Access Control Lists [Cisco Wireless LAN Controller Software] - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Make sure that you read the nuances before configuring, otherwise you may end up locking the WLC.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 11:14:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/applying-acl-on-wlc-for-admin-logon-and-ap-s-only/m-p/4715586#M247845</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-11-03T11:14:48Z</dc:date>
    </item>
  </channel>
</rss>

