<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic wism2 mgmt via wireless in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756723#M29082</link>
    <description>&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have 2 WLCs deployed in a centralized architecture, i have disable management via wireless for both WLCs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparently it only works for the one where client is connected to. If a&amp;nbsp; client is associated to WLC1 they will not be able to https/ssh but still can ssh/https to other WLC. After browsing through have mixed answers that it is how cisco WLC works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i would want to know how can i disable manamgent access to both WLCs regardless of client association. Is there a way other than introducing ACL/ACEs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would expect this feature to disable mgmt access over wireless to both WLCs but disappointed as it is open for any client to attack/logon other WLC.&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 03:50:04 GMT</pubDate>
    <dc:creator>amar_5664</dc:creator>
    <dc:date>2021-07-04T03:50:04Z</dc:date>
    <item>
      <title>wism2 mgmt via wireless</title>
      <link>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756723#M29082</link>
      <description>&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have 2 WLCs deployed in a centralized architecture, i have disable management via wireless for both WLCs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparently it only works for the one where client is connected to. If a&amp;nbsp; client is associated to WLC1 they will not be able to https/ssh but still can ssh/https to other WLC. After browsing through have mixed answers that it is how cisco WLC works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i would want to know how can i disable manamgent access to both WLCs regardless of client association. Is there a way other than introducing ACL/ACEs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would expect this feature to disable mgmt access over wireless to both WLCs but disappointed as it is open for any client to attack/logon other WLC.&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 03:50:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756723#M29082</guid>
      <dc:creator>amar_5664</dc:creator>
      <dc:date>2021-07-04T03:50:04Z</dc:date>
    </item>
    <item>
      <title>wism2 mgmt via wireless</title>
      <link>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756724#M29083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yea, I blogged about this... You arent suppose to ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;&lt;A name="mgmt"&gt;Q. With the Management via&amp;nbsp; Wireless feature enabled on wireless LAN controllers (WLCs) in a&amp;nbsp; mobility group, I can only access one WLC from that mobility group, but&amp;nbsp; not all. Why?&lt;/A&gt;&lt;/H3&gt;&lt;P&gt;&lt;A name="mgmt"&gt; &lt;BR /&gt; &lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;P&gt;&lt;STRONG&gt;A.&lt;/STRONG&gt; This is an expected behavior. When enabled, the Management&amp;nbsp; via Wireless feature allows a wireless client to reach or manage only&amp;nbsp; the WLC to which its associated access point is registered. The client&amp;nbsp; cannot manage other WLCs, even though these WLCs are in same mobility&amp;nbsp; groups. This is implemented for security, and recently was tightened&amp;nbsp; down to just the one WLC in order to limit exposure.&lt;/P&gt;&lt;P&gt;The Cisco WLAN Solution Management over Wireless feature allows Cisco&amp;nbsp; WLAN Solution operators to monitor and configure local WLCs using a&amp;nbsp; wireless client. This feature is supported for all management tasks,&amp;nbsp; except uploads to and downloads from (transfers to and from) the WLC.&lt;/P&gt;&lt;P&gt;This can be enabled through the WLC CLI with the &lt;STRONG&gt;config network mgmt-via-wireless enable&lt;/STRONG&gt; command.&lt;/P&gt;&lt;P&gt;On the GUI, click &lt;STRONG&gt;Management&lt;/STRONG&gt;; from the left-hand side click &lt;STRONG&gt;Mgmt Via Wireless&lt;/STRONG&gt;, and check the box &lt;STRONG&gt;Enable Controller Management to be accessible from Wireless Clients&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;When you enable this option, you can expose the data.&amp;nbsp; Ensure that you have enabled a proper authentication and encryption&amp;nbsp; scheme.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By blog post:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.my80211.com/home/2011/3/6/wlc-management-via-wireless-did-you-know.html"&gt;http://www.my80211.com/home/2011/3/6/wlc-management-via-wireless-did-you-know.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a bug that hasnt been fixed based on all the info I researched a bit ago. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this point, there isnt much you can do with and ACL or such that I can think of.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 03:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756724#M29083</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2011-09-28T03:07:06Z</dc:date>
    </item>
    <item>
      <title>wism2 mgmt via wireless</title>
      <link>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756725#M29084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it does help but i had no intention to repeat what you mentioned... mine is a question and concern directed to Cisco deveopers &lt;/P&gt;&lt;P&gt;mate what do you mean i am not suppose to... i am not bound to requestion something that is unanswered ... lol .. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyways thanks for your help... please share the love if we find an acceptable response/solution from Cisco.... will be raising with my Cisco AM and respond on your blog champ....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 04:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756725#M29084</guid>
      <dc:creator>amar_5664</dc:creator>
      <dc:date>2011-09-28T04:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: wism2 mgmt via wireless</title>
      <link>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756726#M29085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow, you mis read what I posted ... "&lt;/P&gt;&lt;P&gt;mate what do you mean i am not suppose to... i am not bound to requesting something that is unanswered"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am stating this is a BUG. Did you read what I posted above. The issue you are having is not suppose to be that way ... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And thanks for the "champ" comment ...&amp;nbsp; ungrateful people &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gezzzzzz &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 04:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756726#M29085</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2011-09-28T04:31:47Z</dc:date>
    </item>
    <item>
      <title>wism2 mgmt via wireless</title>
      <link>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756727#M29086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; my baddd... apologies champ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;too many things going on same time!!! i do appreciate your responses ... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 04:34:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756727#M29086</guid>
      <dc:creator>amar_5664</dc:creator>
      <dc:date>2011-09-28T04:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: wism2 mgmt via wireless</title>
      <link>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756728#M29087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;LOL!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hey George, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What the heck are you still awake for???&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 04:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756728#M29087</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2011-09-28T04:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: wism2 mgmt via wireless</title>
      <link>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756729#M29088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yea, I know I need to hit the sack soon ... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 05:11:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wism2-mgmt-via-wireless/m-p/1756729#M29088</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2011-09-28T05:11:22Z</dc:date>
    </item>
  </channel>
</rss>

