<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Catalyst 9800/ISE - ACL in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5249355#M279937</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a Catalyst 9800-80 running version 17.9.6 and Cisco ISE 3.1. I want to configure wireless clients connected to an SSID using iPSK/MAB to dynamically change their VLAN and reference an ACL that resides on the 9800.&lt;/P&gt;&lt;P&gt;I understand that dACL support is only available starting with version 17.10, so I cannot use that feature at this time. While I have successfully configured the dynamic VLAN functionality using an authorization profile, I would like guidance on how to handle the ACL configuration under these constraints.&lt;/P&gt;&lt;P&gt;Thank you for your assistance!&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jan 2025 03:07:06 GMT</pubDate>
    <dc:creator>Luna99923</dc:creator>
    <dc:date>2025-01-20T03:07:06Z</dc:date>
    <item>
      <title>Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5249355#M279937</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a Catalyst 9800-80 running version 17.9.6 and Cisco ISE 3.1. I want to configure wireless clients connected to an SSID using iPSK/MAB to dynamically change their VLAN and reference an ACL that resides on the 9800.&lt;/P&gt;&lt;P&gt;I understand that dACL support is only available starting with version 17.10, so I cannot use that feature at this time. While I have successfully configured the dynamic VLAN functionality using an authorization profile, I would like guidance on how to handle the ACL configuration under these constraints.&lt;/P&gt;&lt;P&gt;Thank you for your assistance!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 03:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5249355#M279937</guid>
      <dc:creator>Luna99923</dc:creator>
      <dc:date>2025-01-20T03:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5249370#M279938</link>
      <description>&lt;P&gt;you can configure dACL, the aproach is different before and after 17.10&lt;/P&gt;
&lt;P&gt;In Cisco IOS-XE 17.8 and earlier releases, you had to configure the name in Cisco ISE and define the ACL individually in each of the controllers, so when you configure ISE, just push ACL name and define your ACLs locally on controller.&lt;/P&gt;
&lt;P&gt;In newer version you can push entire ACL on WLC instead of just name, no need to define ACL entries locally on controller&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 03:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5249370#M279938</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2025-01-20T03:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5249383#M279941</link>
      <description>&lt;P&gt;It rare to push both dynamic vlan and dacl.&lt;/P&gt;
&lt;P&gt;If you config ise to push dynamic vlan then use ACL in wlan to control traffic no need to push it from ISE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The dacl is mainly used for redirect traffic of cwa.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 04:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5249383#M279941</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-20T04:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5249506#M279949</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1032978"&gt;@Luna99923&lt;/a&gt;&amp;nbsp;As mentioned above You can defined on the ISE and push to controllers.You can refer to following links&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/99121-vlan-acs-ad-config.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/99121-vlan-acs-ad-config.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 10:38:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5249506#M279949</guid>
      <dc:creator>srimal99</dc:creator>
      <dc:date>2025-01-20T10:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5250239#M279990</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Does anyone know if the following still applies to 9800 WLCs? &amp;nbsp;I pulled the following from:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/71978-acl-wlc.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/71978-acl-wlc.html&lt;/A&gt;&lt;/P&gt;&lt;H2&gt;Considerations When ACLs are Configured in WLCs&lt;/H2&gt;&lt;P&gt;ALCs in WLCs work differently than in routers. These are a few things to remember when you configure ACLs in WLCs:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The most common mistake is to select IP when you intend to deny or allow IP packets. Because you select what is inside the IP packet, you deny or allow IP-in-IP packets.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Controller ACLs cannot block WLC virtual IP address, and hence DHCP packets for wireless clients.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Controller ACLs cannot block multicast traffic received from wired networks that is destined to wireless clients. Controller ACLs are processed for multicast traffic initiated from wireless clients, destined to wired networks or other wireless clients on the same controller.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Unlike a router, the ACL controls traffic in both directions when applied to an interface, but it does not perform stateful firewalling. If you forget to open a hole in the ACL for return traffic, this causes a problem.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Controller ACLs only block IP packets. You cannot block Layer 2 ACLs or Layer 3 packets that are not IP.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Controller ACLs do not use inverse masks like the routers. Here, 255 means match that octet of the IP address exactly.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;ACLs on the controller are done in software and impact forwarding performance.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 21 Jan 2025 14:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5250239#M279990</guid>
      <dc:creator>Luna99923</dc:creator>
      <dc:date>2025-01-21T14:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5250282#M279993</link>
      <description>&lt;P&gt;That's a very old document for AireOS so I'd not assume any of it necessarily still applies to 9800.&lt;/P&gt;
&lt;P&gt;See the config guide&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_conf_ipv4_acl_ewlc.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_conf_ipv4_acl_ewlc.html&lt;/A&gt;&amp;nbsp;which discusses how they apply on 9800.&lt;/P&gt;
&lt;P&gt;For dACLs also see&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/221941-configure-troubleshoot-downloadable-ac.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/221941-configure-troubleshoot-downloadable-ac.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 15:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5250282#M279993</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-01-21T15:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5250304#M279994</link>
      <description>&lt;P&gt;Again why you looking for dACL and dynamic VLAN in same ssid? What is your requirements??&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 16:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5250304#M279994</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-21T16:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5312731#M284972</link>
      <description>&lt;P&gt;&lt;!-- StartFragment  --&gt;&lt;/P&gt;&lt;P&gt;In order to use an ACL name, in the ISE authorization profile, should I select &lt;STRONG&gt;Airespace ACL Name&lt;/STRONG&gt; or use a specific AV pair? Additionally, on the WLC, is there any mandatory configuration apart from creating an ACL with the same name as defined in ISE?&lt;!-- EndFragment  --&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 06:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5312731#M284972</guid>
      <dc:creator>bakaholic39</dc:creator>
      <dc:date>2025-07-23T06:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5313293#M285010</link>
      <description>&lt;P&gt;use Airespace ACL Name under common tasks&lt;/P&gt;
&lt;P&gt;on 9800 make sure ACL name is exactly same as defined on ISE (case sensitive) that's all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 04:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5313293#M285010</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2025-07-24T04:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5313313#M285011</link>
      <description>&lt;P&gt;Thanks for replying, do you have any insights on SD-Access wireless?&amp;nbsp;Can this method be used to enforce ACLs for clients in an SD-Access Wireless environment?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 05:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5313313#M285011</guid>
      <dc:creator>bakaholic39</dc:creator>
      <dc:date>2025-07-24T05:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5313921#M285020</link>
      <description>&lt;P&gt;in SDA the access control is typically based on SGTs where you assign SGT values to source and destination based on IP, VLAN, ports etc and create matrix to allow or deny access between them. Are you using SDA or traditional wireless ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 03:55:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5313921#M285020</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2025-07-25T03:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5313938#M285021</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have both, and I’m wondering, rather than configuring complex SGTs or SGACLs, can traditional way like Airespace ACL Name still work with SDA wireless.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 04:57:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5313938#M285021</guid>
      <dc:creator>bakaholic39</dc:creator>
      <dc:date>2025-07-25T04:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800/ISE - ACL</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5314448#M285027</link>
      <description>&lt;P&gt;it does not align with architectural principles and benefits of SDA's group-based policy and automation capabilities, but it will work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jul 2025 03:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-ise-acl/m-p/5314448#M285027</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2025-07-27T03:26:03Z</dc:date>
    </item>
  </channel>
</rss>

