<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What to allow through firewall for AFC on WLC 9800? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5245737#M279665</link>
    <description>&lt;P&gt;You need to allow access to&amp;nbsp;&lt;A href="https://dnaservices.cisco.com" target="_blank"&gt;dnaservices.cisco.com&amp;nbsp;&lt;/A&gt;port 443 and&amp;nbsp;&lt;A href="http://commercial.ocsp.identrust.com" target="_blank"&gt;commercial.ocsp.identrust.com&amp;nbsp;&lt;/A&gt;port 80.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2025 16:14:44 GMT</pubDate>
    <dc:creator>rmuccifo</dc:creator>
    <dc:date>2025-01-10T16:14:44Z</dc:date>
    <item>
      <title>What to allow through firewall for AFC on WLC 9800?</title>
      <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205234#M276346</link>
      <description>&lt;P&gt;I'm trying to get AFC working on my 9800-40 but it doesn't seem to be able to communicate with the Cisco back end.&amp;nbsp; What URLs or IPs do we need to allow through the firewall to allow this to work?&amp;nbsp; I don't think our management vlan has any outside internet access at this time so I'd have to request anything individually.&lt;BR /&gt;&lt;BR /&gt;The controller has been upgraded to 17.12.xxx for a few weeks and the AFC screen just says "No Valid Token"&amp;nbsp; According to the documentation, all hardware implementations of the 9800 should automatically register and only the cloud versions of the 9800 have to be specifically registered.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 14:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205234#M276346</guid>
      <dc:creator>Stonent</dc:creator>
      <dc:date>2024-10-08T14:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: What to allow through firewall for AFC on WLC 9800?</title>
      <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205245#M276347</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/92507"&gt;@Stonent&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;As per the prerequisites for AFC, yes, you need to give internet access to the WLC. You need to permit HTTPS traffic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FlavioMiranda_0-1728400656964.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/230841i13F6DA08276630AA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="FlavioMiranda_0-1728400656964.jpeg" alt="FlavioMiranda_0-1728400656964.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-14/config-guide/b_wl_17_14_cg/m_afc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-14/config-guide/b_wl_17_14_cg/m_afc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;SECTION id="inf-afc__d49819e370" class="section"&gt;
&lt;H3 class="title sectiontitle"&gt;Prerequisites&lt;/H3&gt;
&lt;UL class="ul"&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Ensure that there is cloud connectivity from the controller to the cloud, with a DNS entry in place. AFC operates through either the management port or data ports.&lt;/P&gt;
&lt;P class="p"&gt;The AFC request is sent only when the controller is onboarded with cloud. This is automatic for hardware platforms like 9800-80, 9800-40 and 9800-L. For cloud controller, you have to manually enter a one-time password (OTP). See &lt;EM class="ph i"&gt;Onboarding the Cloud Controller&lt;/EM&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Before sending an AFC request, check whether the AFC service can be requested by using the &lt;SPAN class="ph uicontrol"&gt;show wireless afc ap&lt;/SPAN&gt; command. If command output shows &lt;EM class="ph i"&gt;yes&lt;/EM&gt; or &lt;EM class="ph i"&gt;up&lt;/EM&gt; status for all the parameters of an AP, then request is sent out.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Standard APs must register with the AFC system by providing the following parameters:&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Geographic coordinates (latitude and longitude)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Antenna height above ground level and tolerance as uncertainty height&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;FCC identification number&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;P class="p"&gt;Manufacturer’s unique serial number&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/SECTION&gt;</description>
      <pubDate>Tue, 08 Oct 2024 15:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205245#M276347</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-10-08T15:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: What to allow through firewall for AFC on WLC 9800?</title>
      <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205254#M276348</link>
      <description>&lt;P&gt;TCP Port 443&amp;nbsp;must be open for the AFC.&lt;/P&gt;
&lt;P&gt;Have you verified connectivity using "show cloud-services summary" &amp;amp; "Show wireless afc statistics" ?&lt;/P&gt;
&lt;P&gt;Jagan Chowdam&lt;/P&gt;
&lt;P&gt;/**Pls rate useful responses**/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 15:36:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205254#M276348</guid>
      <dc:creator>jagan.chowdam</dc:creator>
      <dc:date>2024-10-08T15:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: What to allow through firewall for AFC on WLC 9800?</title>
      <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205259#M276349</link>
      <description>&lt;P&gt;I do not have the 6GHz AP online right now.&amp;nbsp; It's been given to the contractor for installation on our building.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;show cloud-services summary&lt;BR /&gt;Cloudm Onboarding Status&lt;BR /&gt;------------------------&lt;/P&gt;&lt;P&gt;State : Onboarded&lt;BR /&gt;URL : &lt;A href="https://dnaservices.cisco.com/api/tethering/v1/enrollment/enroll/byname/C9800" target="_blank"&gt;https://dnaservices.cisco.com/api/tethering/v1/enrollment/enroll/byname/C9800&lt;/A&gt;&lt;/P&gt;&lt;P&gt;No valid token&lt;/P&gt;&lt;P&gt;Show wireless afc statistics&lt;BR /&gt;Total number of 6GHz APs : 0&lt;BR /&gt;Number of APs requiring AFC service : 0&lt;BR /&gt;Messages sent to AFC : 0&lt;BR /&gt;Successful messages received from AFC : 0&lt;BR /&gt;Errored AFC messages : 0&lt;BR /&gt;AFC messages pending : 0&lt;BR /&gt;Minimum response time (ms) : 0&lt;BR /&gt;Maximum response time (ms) : 0&lt;BR /&gt;Average response time (ms) : 0&lt;BR /&gt;Health check query : Idle&lt;BR /&gt;Health check status : No valid token&lt;BR /&gt;Health check timestamp : 10/08/2024 10:41:41&lt;BR /&gt;Number of times health check went down : 0&lt;/P&gt;&lt;P&gt;Health check event history&lt;BR /&gt;Timestamp #Times Event State RC Context&lt;BR /&gt;---------------------------- -------- ----------------------- ------------------------------ --- -----------------------------&lt;BR /&gt;10/08/2024 10:41:41.57430 70158 Scheduled 0 Timer: 30s&lt;BR /&gt;10/08/2024 10:41:41.57418 70159 Not sent No token 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 15:42:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205259#M276349</guid>
      <dc:creator>Stonent</dc:creator>
      <dc:date>2024-10-08T15:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: What to allow through firewall for AFC on WLC 9800?</title>
      <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205317#M276352</link>
      <description>&lt;P&gt;AFC is a cloud-based service that connects with Cisco's AFC Service Provider to manage spectrum sharing and assign channels and power levels for access points operating in the 6GHz band.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For indoor APs,&amp;nbsp; AFC is OFF by default, where as outdoor APs AFC is ON.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to enable AFC in RF Profiles. You also require a GPS/GNSS enabled AP for AFC to work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you take care of these, AFC attachment is automatic as long as Port 443 is opened.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The prerequisites mentioned in&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;post are crucial.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jagan Chowdam&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 17:45:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205317#M276352</guid>
      <dc:creator>jagan.chowdam</dc:creator>
      <dc:date>2024-10-08T17:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: What to allow through firewall for AFC on WLC 9800?</title>
      <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205379#M276357</link>
      <description>&lt;P&gt;Well that's my thing.&amp;nbsp; I need to know specifically which DNS entries or IPs it needs to access. That's what I'm asking more than anything else.&amp;nbsp; That's what my firewall group is going to require to allow it through.&amp;nbsp; I've already done the other prerequisites.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 19:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5205379#M276357</guid>
      <dc:creator>Stonent</dc:creator>
      <dc:date>2024-10-08T19:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: What to allow through firewall for AFC on WLC 9800?</title>
      <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5245737#M279665</link>
      <description>&lt;P&gt;You need to allow access to&amp;nbsp;&lt;A href="https://dnaservices.cisco.com" target="_blank"&gt;dnaservices.cisco.com&amp;nbsp;&lt;/A&gt;port 443 and&amp;nbsp;&lt;A href="http://commercial.ocsp.identrust.com" target="_blank"&gt;commercial.ocsp.identrust.com&amp;nbsp;&lt;/A&gt;port 80.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 16:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5245737#M279665</guid>
      <dc:creator>rmuccifo</dc:creator>
      <dc:date>2025-01-10T16:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: What to allow through firewall for AFC on WLC 9800?</title>
      <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5271078#M281598</link>
      <description>&lt;P&gt;We're having an issue with 9800-80 in SSO HA running 17.12.4 and AFC as well. We permitted the addresses and ports &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/409609"&gt;@rmuccifo&lt;/a&gt; provided above with no luck. AFC Health Statistics &amp;gt; Health check status says "Device not onboarded". That seems to imply we need to go through the onboarding with the OTP, etc. after all. Is that true, or is this indicating a connectivity issue?&lt;/P&gt;&lt;P&gt;Also, the config guide mentions "AFC operates through either the management port or data ports" but does not elaborate on how to configure this. Which is the default, or how can I verify which his being used? I need it to be the Wireless Management Interface (the shared VIP).&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 20:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5271078#M281598</guid>
      <dc:creator>eglinsky2012</dc:creator>
      <dc:date>2025-03-13T20:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: What to allow through firewall for AFC on WLC 9800?</title>
      <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5271253#M281614</link>
      <description>&lt;P&gt;You don't need to do the onboarding with OTP with a 9800-80, that will be done automatically, assuming controller is able to reach&amp;nbsp;&lt;A href="https://dnaservices.cisco.com/" target="_blank" rel="nofollow noopener noreferrer"&gt;dnaservices.cisco.com.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The controller will automatically try to reach the cloud through management or data port, there's no specific configuration required.&lt;/P&gt;
&lt;P&gt;You can see which VRF is being used using "show cloud-services detail". It will switch between management VRF and forwarding VRF automatically until it is able to reach the cloud.&lt;/P&gt;
&lt;P&gt;If device is not onboarded, or you see "No valid token" under "show cloud-services detail" it means there's some connectivity problem. Also, make sure that proxy is configured if your network requires that for https traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 09:47:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5271253#M281614</guid>
      <dc:creator>rmuccifo</dc:creator>
      <dc:date>2025-03-14T09:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: What to allow through firewall for AFC on WLC 9800?</title>
      <link>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5272572#M281711</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/409609"&gt;@rmuccifo&lt;/a&gt;Thank you for that info. After more troubleshooting, our firewall was not allowing the traffic to &lt;A href="http://commercial.ocsp.identrust.com" target="_blank" rel="nofollow noopener noreferrer"&gt;commercial.ocsp.identrust.com&lt;/A&gt; due to the OCSP application (a form of certificate checking) being used. Once we allowed that on the outbound firewall policy, I was able to use ""show cloud-services detail" to verify that the state is now Onboarded.&lt;/P&gt;&lt;P&gt;The documentation should be updated to reflect the correct URLs, ports, and the OCSP application that need to be allowed: &lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_afc.html#config-dna-service" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_afc.html#config-dna-service&lt;/A&gt; As well as clarify that physical controllers do not need to be onboarded manually.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 15:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/what-to-allow-through-firewall-for-afc-on-wlc-9800/m-p/5272572#M281711</guid>
      <dc:creator>eglinsky2012</dc:creator>
      <dc:date>2025-03-18T15:38:09Z</dc:date>
    </item>
  </channel>
</rss>

