<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: P2P Blocking with ACL in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5193500#M275477</link>
    <description>&lt;P&gt;90% of solution know what is not work&lt;/P&gt;
&lt;P&gt;Client to client in same WLAN in same AP&lt;/P&gt;
&lt;P&gt;Client to client in differ WLAN in same AP&lt;/P&gt;
&lt;P&gt;Client to client in same WLAN in differ AP&lt;/P&gt;
&lt;P&gt;Client to client in differ WLAN in differ AP&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Thu, 12 Sep 2024 04:37:16 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-09-12T04:37:16Z</dc:date>
    <item>
      <title>P2P Blocking with ACL</title>
      <link>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5192879#M275417</link>
      <description>&lt;P&gt;I am having hard time with this issue going back and forth with TAC.it seems this is not going to work.So i though i paste it here to get more input please. of course there is a lot of various conversation regarding P2P blocking with ACL and here is mine:&lt;/P&gt;&lt;P&gt;C9800 17.9.5 AP 91K - wireless client mode FLex Mode local switching . and since P2P blocking only works with clients on same AP then I am trying to implement it with ACL:&lt;/P&gt;&lt;P&gt;Here is the recent changes I made based on TAC advise and still does not work:&lt;/P&gt;&lt;P&gt;Extended IP access list RES-P2P-BLOCK&lt;BR /&gt;10 permit udp any any eq bootpc&lt;BR /&gt;20 permit udp any any eq bootps&lt;BR /&gt;30 permit ip 172.30.0.0 0.0.255.255 host 172.30.0.1&lt;BR /&gt;40 permit ip host 172.30.0.1 172.30.0.0 0.0.255.255&lt;BR /&gt;50 deny ip 172.30.0.0 0.0.255.255 172.30.0.0 0.0.255.255&lt;BR /&gt;60 permit ip any any&lt;/P&gt;&lt;P&gt;applied the ACL on Flex profile "Policy ACL" tab and "VLAN" tab in both direction vlan 22.&lt;/P&gt;&lt;P&gt;result: it blocks P2P if clients are on the same AP and allows if different APs ( opposite behavior when use P2P drop in WLAN )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: Based on TAC and some comments on some post in the communityI did not apply it on Policy profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 21:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5192879#M275417</guid>
      <dc:creator>Najib Akbari</dc:creator>
      <dc:date>2024-09-10T21:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Blocking with ACL</title>
      <link>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5193275#M275463</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213945-understand-flexconnect-on-9800-wireless.html#toc-hId-1437898928" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213945-understand-flexconnect-on-9800-wireless.html#toc-hId-1437898928&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check flexcon acl local&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 14:19:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5193275#M275463</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-09-11T14:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Blocking with ACL</title>
      <link>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5193466#M275470</link>
      <description>&lt;P&gt;Actually initially I followed that Doc and did not work . here is my finding with TAC back and forth today's response :&lt;/P&gt;&lt;P&gt;He said since now ACL works when clients on different APs not same AP then add P2P drop on policy profile to cover that part, basically he says combine ACL with P2P Block and said no other solution available. i responded back and said this defininelty has no login unless its a bug or something because imagine what if later on i want to give access to certain client then guess what happens if they are the same AP?! it will be blocked by P2P drop! then asked him to escalated and he said he will and he will let me know ........&lt;/P&gt;&lt;P&gt;in&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 22:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5193466#M275470</guid>
      <dc:creator>Najib Akbari</dc:creator>
      <dc:date>2024-09-11T22:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Blocking with ACL</title>
      <link>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5193500#M275477</link>
      <description>&lt;P&gt;90% of solution know what is not work&lt;/P&gt;
&lt;P&gt;Client to client in same WLAN in same AP&lt;/P&gt;
&lt;P&gt;Client to client in differ WLAN in same AP&lt;/P&gt;
&lt;P&gt;Client to client in same WLAN in differ AP&lt;/P&gt;
&lt;P&gt;Client to client in differ WLAN in differ AP&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 04:37:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5193500#M275477</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-09-12T04:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Blocking with ACL</title>
      <link>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5193981#M275556</link>
      <description>&lt;P&gt;here is the summary of my interaction with TAC on this for the community to see:&lt;/P&gt;&lt;P&gt;- on Flex Mode Local switching P2P Blocking only works when clients are on same AP ( Applied on SSID&lt;BR /&gt;P2P Blocking Action - &amp;gt; Drop )&lt;BR /&gt;- for the above limitation the work around is ACL applied on Flex Profile "Policy ACL" and "VLAN" Tab ( and not policy profile access policies tab)&lt;BR /&gt;- so for the end 2 end P2P communication to be blocked both ACL and "P2P Blocking Action - &amp;gt; Drop" are required&lt;/P&gt;&lt;P&gt;I told TAC this is not an acceptable solution, it does not work for me and it does not scale. for example if later on I want specific client to be able to communicate with another specific client and allowed on ACL ACE then if both are on same AP then not feasible and being blocked! TAC escalated and came back and said that is the limitation and might change in future......&lt;/P&gt;&lt;P&gt;Note: all this notes are based on TAC advice and Im not sure of its accuracy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 18:37:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/p2p-blocking-with-acl/m-p/5193981#M275556</guid>
      <dc:creator>Najib Akbari</dc:creator>
      <dc:date>2024-09-12T18:37:25Z</dc:date>
    </item>
  </channel>
</rss>

