<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Preauth ACL in WLC 9800 Behaviour in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/preauth-acl-in-wlc-9800-behaviour/m-p/4862102#M257455</link>
    <description>&lt;P&gt;Follow this guide for the ACL on the 9800&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html#toc-hId-881505252" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html#toc-hId-881505252&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Deny to ISE, DNS, and permit to www&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jun 2023 01:00:17 GMT</pubDate>
    <dc:creator>Haydn Andrews</dc:creator>
    <dc:date>2023-06-26T01:00:17Z</dc:date>
    <item>
      <title>Preauth ACL in WLC 9800 Behaviour</title>
      <link>https://community.cisco.com/t5/wireless/preauth-acl-in-wlc-9800-behaviour/m-p/4862095#M257454</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I need to configure a preauth ACL for webauth " CWA ". In fact, i am migrating from a WLC 2500 to WLC 9800, and the confusion is in the permit/deny enries, on the 2500, they say :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"this ACL is referenced in the access-accept of the ISE and defines what traffic should be redirected (denied by the ACL) and what traffic should not be redirected (permitted by the ACL)"&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;on the other hand, when reading the config guide of the 9800, they say :&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"This redirect ACL is not a security ACL but a punt ACL that defines what traffic goes to the CPU (on permits) for further treatment (like redirection) and what traffic stays on the data plane (on deny) and avoids redirection."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;what i understand is that the logic is inversed on the new plateform, i am right ? should i reverse all the entries found on the preauth acl of the 2500 ?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 00:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/preauth-acl-in-wlc-9800-behaviour/m-p/4862095#M257454</guid>
      <dc:creator>ramziabdelhak</dc:creator>
      <dc:date>2023-06-26T00:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth ACL in WLC 9800 Behaviour</title>
      <link>https://community.cisco.com/t5/wireless/preauth-acl-in-wlc-9800-behaviour/m-p/4862102#M257455</link>
      <description>&lt;P&gt;Follow this guide for the ACL on the 9800&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html#toc-hId-881505252" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html#toc-hId-881505252&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Deny to ISE, DNS, and permit to www&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 01:00:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/preauth-acl-in-wlc-9800-behaviour/m-p/4862102#M257455</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2023-06-26T01:00:17Z</dc:date>
    </item>
  </channel>
</rss>

