<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS Based ACL, CWA  and guest anchor controller ? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/dns-based-acl-cwa-and-guest-anchor-controller/m-p/2490342#M26935</link>
    <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;I am currently trying to use DNS Based ACL in our WLC test setup, but I am having some trouple.&lt;/P&gt;&lt;P&gt;When i try it out on our Guest Anchor setup with CWA and ISE it does not work.&lt;/P&gt;&lt;P&gt;Is there a limitation to DNS based ACLs I have missed here ?&lt;/P&gt;&lt;P&gt;Any good debug commands are also apreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a quick explanation of the setup.&lt;/P&gt;&lt;P&gt;One Guest Anchor controller with the guest WLAN attached, and a normal IP ACL that permits access to the ISE CWA page.&lt;/P&gt;&lt;P&gt;On the same ACL on the Anchor WLC I have added some URLs to permit access to fx. facebook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The WLAN and ACL are excatly the same on the Non-Guest-anchor controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i connect a client to a AP connected to the Non-guest-anchor controller, I get an IP in the right VLAN on the Anchor controller, and I am able to access the CWA page on ISE. - I can also see on both controllers, that the client has been applyed with the dns based acl by CWA / ISE.&lt;/P&gt;&lt;P&gt;But when i try to access Facebook I get a ssl error page.&lt;/P&gt;&lt;P&gt;If i connect the client to a AP connected to the Guest-anchor controller everything works.&lt;/P&gt;&lt;P&gt;I get the CWA page and am able to access Facebook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Thomas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS:&lt;/P&gt;&lt;P&gt;Maybe im hitting a variant of bugID:&amp;nbsp;&lt;SPAN style="color: rgb(52, 52, 52); font-family: arial; font-size: 11px; line-height: 15.999600410461426px;"&gt;CSCul20184&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 07:29:46 GMT</pubDate>
    <dc:creator>Thomas Obbekaer Thomsen</dc:creator>
    <dc:date>2021-07-05T07:29:46Z</dc:date>
    <item>
      <title>DNS Based ACL, CWA  and guest anchor controller ?</title>
      <link>https://community.cisco.com/t5/wireless/dns-based-acl-cwa-and-guest-anchor-controller/m-p/2490342#M26935</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;I am currently trying to use DNS Based ACL in our WLC test setup, but I am having some trouple.&lt;/P&gt;&lt;P&gt;When i try it out on our Guest Anchor setup with CWA and ISE it does not work.&lt;/P&gt;&lt;P&gt;Is there a limitation to DNS based ACLs I have missed here ?&lt;/P&gt;&lt;P&gt;Any good debug commands are also apreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a quick explanation of the setup.&lt;/P&gt;&lt;P&gt;One Guest Anchor controller with the guest WLAN attached, and a normal IP ACL that permits access to the ISE CWA page.&lt;/P&gt;&lt;P&gt;On the same ACL on the Anchor WLC I have added some URLs to permit access to fx. facebook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The WLAN and ACL are excatly the same on the Non-Guest-anchor controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i connect a client to a AP connected to the Non-guest-anchor controller, I get an IP in the right VLAN on the Anchor controller, and I am able to access the CWA page on ISE. - I can also see on both controllers, that the client has been applyed with the dns based acl by CWA / ISE.&lt;/P&gt;&lt;P&gt;But when i try to access Facebook I get a ssl error page.&lt;/P&gt;&lt;P&gt;If i connect the client to a AP connected to the Guest-anchor controller everything works.&lt;/P&gt;&lt;P&gt;I get the CWA page and am able to access Facebook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Thomas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS:&lt;/P&gt;&lt;P&gt;Maybe im hitting a variant of bugID:&amp;nbsp;&lt;SPAN style="color: rgb(52, 52, 52); font-family: arial; font-size: 11px; line-height: 15.999600410461426px;"&gt;CSCul20184&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 07:29:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dns-based-acl-cwa-and-guest-anchor-controller/m-p/2490342#M26935</guid>
      <dc:creator>Thomas Obbekaer Thomsen</dc:creator>
      <dc:date>2021-07-05T07:29:46Z</dc:date>
    </item>
  </channel>
</rss>

