<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC 5508 -7.4.100 mDNS Bonjour snooping in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240071#M43869</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have 7.4 installed and configured for Bonjour Snooping. All is working, but working too well. We have a large campus that house 2 schools and each school is complaining that they can see the other schools AppleTV devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have played around with a few different scenarios to see if I can localize the bonjour traffic. &lt;/P&gt;&lt;P&gt;I guess I am looking to create a logical split for bonjour devices amoung the schools.&lt;/P&gt;&lt;P&gt;Apple came to the school and informed us that the IPAD has a limit of 64 devices that can be seen via the bonjour. At some point we will have over 100 AppleTV added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so we have 3 wlc 5508's with 7.4.100&lt;/P&gt;&lt;P&gt;we have 2 SSIDs that span the whole campus&lt;/P&gt;&lt;P&gt;using AP groups to segment the floors in buildings&lt;/P&gt;&lt;P&gt;So the schools are logically split with AP groups&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I have tried&lt;/P&gt;&lt;P&gt;I created few mDNS profiles and assigned the services for Apple TV - let's call them school1 and school2&lt;/P&gt;&lt;P&gt;I assign the mDNS profiles to the interfaces dedicated each school&lt;/P&gt;&lt;P&gt;enable snooping on the WLAN with profile of none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The end result is that devices from both schools can be seen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to create new ssid for apple TVs and a new ssid for 1 schools teachers&lt;/P&gt;&lt;P&gt;I followed the vlan select example&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_tech_note09186a0080bb1d7c.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_tech_note09186a0080bb1d7c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;end result is that devices from both schools can be seen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried the mDNS without multicast enabled just like the video shows to no avail - I assume maybe my AP groups might be more complicated then the example of just 2 vlans&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/community/netpro/wireless-mobility/begin-wireless/blog/2013/01/01/wireless-lan-controller-wlc-release-74--bonjour-gateway-configuration-example" target="_blank"&gt;https://supportforums.cisco.com/community/netpro/wireless-mobility/begin-wireless/blog/2013/01/01/wireless-lan-controller-wlc-release-74--bonjour-gateway-configuration-example&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried combinations of things, but I must be missing something&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the webinar, Cisco said it will use filtering to restrict which&amp;nbsp; clients can see which services (Apple TV's, etc). What will Cisco use to&amp;nbsp; filter Bonjour requests?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;according to this article&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.pcadvisor.co.uk/news/network-wifi/3376119/cisco-answers-user-questions-about-upcoming-apple-bonjour-gateway/#ixzz2SIDqFH49" target="_blank"&gt;http://www.pcadvisor.co.uk/news/network-wifi/3376119/cisco-answers-user-questions-about-upcoming-apple-bonjour-gateway/#ixzz2SIDqFH49&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The filtering options are: · Per WLAN/SSID · Per VLAN or AP&amp;nbsp; Group · Per Interface Group (which is a group of VLANs pooled together).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A Bonjour service policy can be created and applied on any one of&amp;nbsp; the above criteria. In the future, we will support per-user Bonjour&amp;nbsp; service policies which will come as a RADIUS attribute from the AAA &lt;A href="http://www.networkworld.com/topics/server.html" rel="nofollow" target="_blank"&gt;server&lt;/A&gt;.&lt;/P&gt;&lt;P style="overflow: hidden; color: #000000; background-color: #ffffff; text-align: left; text-decoration: none; border: medium none;"&gt;&lt;BR /&gt;Read more: &lt;A href="http://www.pcadvisor.co.uk/news/network-wifi/3376119/cisco-answers-user-questions-about-upcoming-apple-bonjour-gateway/#ixzz2SZqMYpdh" style="color: #003399;" target="_blank"&gt;http://www.pcadvisor.co.uk/news/network-wifi/3376119/cisco-answers-user-questions-about-upcoming-apple-bonjour-gateway/#ixzz2SZqMYpdh&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any insight would be appreciated&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 07:02:07 GMT</pubDate>
    <dc:creator>Andrew MacTaggart</dc:creator>
    <dc:date>2021-07-04T07:02:07Z</dc:date>
    <item>
      <title>WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240071#M43869</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have 7.4 installed and configured for Bonjour Snooping. All is working, but working too well. We have a large campus that house 2 schools and each school is complaining that they can see the other schools AppleTV devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have played around with a few different scenarios to see if I can localize the bonjour traffic. &lt;/P&gt;&lt;P&gt;I guess I am looking to create a logical split for bonjour devices amoung the schools.&lt;/P&gt;&lt;P&gt;Apple came to the school and informed us that the IPAD has a limit of 64 devices that can be seen via the bonjour. At some point we will have over 100 AppleTV added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so we have 3 wlc 5508's with 7.4.100&lt;/P&gt;&lt;P&gt;we have 2 SSIDs that span the whole campus&lt;/P&gt;&lt;P&gt;using AP groups to segment the floors in buildings&lt;/P&gt;&lt;P&gt;So the schools are logically split with AP groups&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I have tried&lt;/P&gt;&lt;P&gt;I created few mDNS profiles and assigned the services for Apple TV - let's call them school1 and school2&lt;/P&gt;&lt;P&gt;I assign the mDNS profiles to the interfaces dedicated each school&lt;/P&gt;&lt;P&gt;enable snooping on the WLAN with profile of none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The end result is that devices from both schools can be seen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to create new ssid for apple TVs and a new ssid for 1 schools teachers&lt;/P&gt;&lt;P&gt;I followed the vlan select example&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_tech_note09186a0080bb1d7c.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/wireless/ps4570/products_tech_note09186a0080bb1d7c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;end result is that devices from both schools can be seen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried the mDNS without multicast enabled just like the video shows to no avail - I assume maybe my AP groups might be more complicated then the example of just 2 vlans&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/community/netpro/wireless-mobility/begin-wireless/blog/2013/01/01/wireless-lan-controller-wlc-release-74--bonjour-gateway-configuration-example" target="_blank"&gt;https://supportforums.cisco.com/community/netpro/wireless-mobility/begin-wireless/blog/2013/01/01/wireless-lan-controller-wlc-release-74--bonjour-gateway-configuration-example&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried combinations of things, but I must be missing something&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the webinar, Cisco said it will use filtering to restrict which&amp;nbsp; clients can see which services (Apple TV's, etc). What will Cisco use to&amp;nbsp; filter Bonjour requests?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;according to this article&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.pcadvisor.co.uk/news/network-wifi/3376119/cisco-answers-user-questions-about-upcoming-apple-bonjour-gateway/#ixzz2SIDqFH49" target="_blank"&gt;http://www.pcadvisor.co.uk/news/network-wifi/3376119/cisco-answers-user-questions-about-upcoming-apple-bonjour-gateway/#ixzz2SIDqFH49&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The filtering options are: · Per WLAN/SSID · Per VLAN or AP&amp;nbsp; Group · Per Interface Group (which is a group of VLANs pooled together).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A Bonjour service policy can be created and applied on any one of&amp;nbsp; the above criteria. In the future, we will support per-user Bonjour&amp;nbsp; service policies which will come as a RADIUS attribute from the AAA &lt;A href="http://www.networkworld.com/topics/server.html" rel="nofollow" target="_blank"&gt;server&lt;/A&gt;.&lt;/P&gt;&lt;P style="overflow: hidden; color: #000000; background-color: #ffffff; text-align: left; text-decoration: none; border: medium none;"&gt;&lt;BR /&gt;Read more: &lt;A href="http://www.pcadvisor.co.uk/news/network-wifi/3376119/cisco-answers-user-questions-about-upcoming-apple-bonjour-gateway/#ixzz2SZqMYpdh" style="color: #003399;" target="_blank"&gt;http://www.pcadvisor.co.uk/news/network-wifi/3376119/cisco-answers-user-questions-about-upcoming-apple-bonjour-gateway/#ixzz2SZqMYpdh&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any insight would be appreciated&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 07:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240071#M43869</guid>
      <dc:creator>Andrew MacTaggart</dc:creator>
      <dc:date>2021-07-04T07:02:07Z</dc:date>
    </item>
    <item>
      <title>WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240072#M43870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found this ,"With Release 7.4, you can do this by tying the multicast DNS services&amp;nbsp; (mDNS) to the interface or interface group and then placing the user&amp;nbsp; (e.g., student or teacher) into that correct interface/interface group&amp;nbsp; using AAA Override. To apply the profile for an interface group, in the&amp;nbsp; GUI go to Interface Groups &amp;gt; Edit and use the mDNS Profile field."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 05:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240072#M43870</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2013-05-07T05:51:44Z</dc:date>
    </item>
    <item>
      <title>WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240073#M43871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would I need to apply the AAA overide for AP groups or only with Interface Groups or only if I am assigning the vlan with ACS 5.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's worth a try&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;A&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 06:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240073#M43871</guid>
      <dc:creator>Andrew MacTaggart</dc:creator>
      <dc:date>2013-05-07T06:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240074#M43872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I set AAA override on both WLANs and had the guys clear the bonjour cache on IPADS and made the AppleTV sleep.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To no avail, they still see AppleTVs from school 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached some images of what is configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AP Group 1 of many- school 1 does not have these interfaces but does have a different mDNS profile&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/6/4/138468-apgroup.jpeg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/6/4/138469-intgroup.jpeg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/8/4/138485-mdnsprofile.jpeg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/8/4/138486-wlanaaa.jpeg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/8/4/138487-wlanappletv.jpeg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/8/4/138488-wlanmdns.jpeg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/8/4/138489-wlanteacher.jpeg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/9/4/138490-wlanteacheraaa.jpeg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/9/4/138491-wlanteachermdns.jpeg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 07:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240074#M43872</guid>
      <dc:creator>Andrew MacTaggart</dc:creator>
      <dc:date>2013-05-07T07:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240075#M43873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So how is everything setup? Centralized WLC deployment? Layer 2 extended or is the schools separated by layer 3? Apple TV's and iPads on the same subnet? Just trying to understand the connectivity.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 11:53:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240075#M43873</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-05-07T11:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240076#M43874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently we are testing before deployment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Centralized WLCs&lt;/P&gt;&lt;P&gt;layer 3 separation between schools&lt;/P&gt;&lt;P&gt;Apple TVs and clients on different subnets[although have both scenarios] &lt;/P&gt;&lt;P&gt;AP groups assign the interface[subnet] to a group of APs usually by floor&lt;/P&gt;&lt;P&gt;The latest setup&lt;/P&gt;&lt;P&gt;added the AAA overide&lt;/P&gt;&lt;P&gt;created subnet just for appletvs assigned mDNS profile to the interface, created a WLAN just for appleTVs&lt;/P&gt;&lt;P&gt;Created a interface group for Teachers assigned mDNS profile to the interface group, Created WLAN for Teachers, added mcast interface, enabled mDNS snooping with profile and without[NONE] option&lt;/P&gt;&lt;P&gt;Used AP group to assign both WLANs to selected schools 2 APs.&lt;/P&gt;&lt;P&gt;In School 1 AppleTV and IPAD connect to same subnet, Same WLAN, Same AP Group, Same AP.&lt;/P&gt;&lt;P&gt;In School 2 AppleTV on own subnet and IPAD etc.. on their own subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem is school 2 client sees school 1's AppleTV&lt;/P&gt;&lt;P&gt;The Schools are planning to deploy 150 to 200 AppleTVs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 12:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240076#M43874</guid>
      <dc:creator>Andrew MacTaggart</dc:creator>
      <dc:date>2013-05-07T12:38:43Z</dc:date>
    </item>
    <item>
      <title>WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240077#M43875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The centralized WLC is what's the main hurdle since all the traffic is tunneled back to the WLC.&amp;nbsp; The main feature ov v7.4 and mDNS is to allow bonjour to traverse layer 3.&amp;nbsp; This is what's causing you nightmares:)&amp;nbsp; Current'y there is no way to filter what clients can see what Apple TV device, but hopefully in the future since Aruba's Clearpasss can do that.&amp;nbsp; You really have to sit back an look at how to design your bonjour network.&amp;nbsp; Placing clients and Apple TV's in the same subnet might work better for you and disabling mDNS.&amp;nbsp; Or you might only allow certain subnet's (AP Groups) for client and Apple TV's to communicate, by blocking bonjour. This is hard if your clients connect to an AP and adjacent floor in which that subnet would be blocked by an acl.&amp;nbsp; Using mDNS on the WLC just allows you to not be on the same subnet, but in a large deployment of Apple TV's this can be an issue.&amp;nbsp; So maybe think how you can group devices together that will work for you now and in the future and maybe see how you can block bonjour from being seem by all subnet's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 13:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240077#M43875</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-05-07T13:22:29Z</dc:date>
    </item>
    <item>
      <title>WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240078#M43876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scott -- Could you not use a ACL on the WLC to shape this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 13:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240078#M43876</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-05-07T13:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240079#M43877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can, but I hate the ACL's in the WLC:)&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 13:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240079#M43877</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-05-07T13:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240080#M43878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You hate ACLs on the WLC -- I agree with you they are a challenge. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, it is an option to help this fella out .. I mean the other fella (not you Scott).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 13:43:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240080#M43878</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-05-07T13:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240081#M43879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Haha... True statement and maybe others who have not felt with ACL might find it better.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 13:46:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240081#M43879</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-05-07T13:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240082#M43880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;LOL ... Going through ISE has improved my ACL experience ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 13:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240082#M43880</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-05-07T13:50:32Z</dc:date>
    </item>
    <item>
      <title>WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240083#M43881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are the ACLs for the controller&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 10px 20px; padding-left: 10px; font-size: medium; font-family: 'Myriad Set'; vertical-align: baseline; quotes: ''; overflow: auto; color: #000000;"&gt;acl create BlockBonjour &lt;BR /&gt;acl apply BlockBonjour &lt;BR /&gt;acl counter start&lt;BR /&gt;acl rule add BlockBonjour 1 &lt;BR /&gt;acl rule add BlockBonjour 2 &lt;BR /&gt;acl rule action BlockBonjour 1 deny &lt;BR /&gt;acl rule action BlockBonjour 2 permit &lt;BR /&gt;acl rule destination address BlockBonjour 1 224.0.0.251 255.255.255.255 &lt;BR /&gt;acl rule destination address BlockBonjour 2 0.0.0.0 0.0.0.0 &lt;BR /&gt;acl rule destination port range BlockBonjour 1 0 65535 &lt;BR /&gt;acl rule destination port range BlockBonjour 2 0 65535 &lt;BR /&gt;acl rule source address BlockBonjour 1 0.0.0.0 0.0.0.0 &lt;BR /&gt;acl rule source address BlockBonjour 2 0.0.0.0 0.0.0.0 &lt;BR /&gt;acl rule source port range BlockBonjour 1 0 65535 &lt;BR /&gt;acl rule source port range BlockBonjour 2 0 65535 &lt;BR /&gt;acl rule direction BlockBonjour 1&amp;nbsp; In&amp;nbsp; &lt;BR /&gt;acl rule direction BlockBonjour 2 Any&amp;nbsp; &lt;BR /&gt;acl rule dscp BlockBonjour 1&amp;nbsp; Any&amp;nbsp; &lt;BR /&gt;acl rule dscp BlockBonjour 2&amp;nbsp; Any&amp;nbsp; &lt;BR /&gt;acl rule protocol BlockBonjour 1&amp;nbsp; Any&amp;nbsp; &lt;BR /&gt;acl rule protocol BlockBonjour 2&amp;nbsp; Any&amp;nbsp; &lt;BR /&gt;acl apply BlockBonjour &lt;P&gt;&lt;/P&gt;ipv6 acl create BlockAllIPv6 &lt;BR /&gt;ipv6 acl apply BlockAllIPv6 &lt;BR /&gt;ipv6 acl rule add BlockAllIPv6 1 &lt;BR /&gt;ipv6 acl rule action BlockAllIPv6 1 deny &lt;BR /&gt;ipv6 acl rule destination address BlockAllIPv6 1 :: 0 &lt;BR /&gt;ipv6 acl rule destination port range BlockAllIPv6 1 0 65535 &lt;BR /&gt;ipv6 acl rule source address BlockAllIPv6 1 :: 0 &lt;BR /&gt;ipv6 acl rule source port range BlockAllIPv6 1 0 65535 &lt;BR /&gt;ipv6 acl rule direction BlockAllIPv6 1 Any&amp;nbsp; &lt;BR /&gt;ipv6 acl rule dscp BlockAllIPv6 1&amp;nbsp; Any&amp;nbsp; &lt;BR /&gt;ipv6 acl rule protocol BlockAllIPv6 1 Any &lt;BR /&gt;ipv6 acl apply BlockAllIPv6&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 10px 20px; padding-left: 10px; font-size: medium; font-family: 'Myriad Set'; vertical-align: baseline; quotes: ''; overflow: auto; color: #000000;"&gt;Apply to wlan:&amp;nbsp; The wlan index is used in this case, the first wlan created on controller&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 10px 20px; padding-left: 10px; font-size: medium; font-family: 'Myriad Set'; vertical-align: baseline; quotes: ''; overflow: auto; color: #000000;"&gt;&lt;BLOCKQUOTE class="jive-quote" style="margin: 10px 20px; padding-left: 10px; font-style: inherit; font-family: 'Myriad Set'; vertical-align: baseline; quotes: ''; background-color: #ffffff; overflow: auto; color: #000000; background-position: repeat repeat;"&gt; wlan acl 1 BlockBonjour&lt;BR /&gt;wlan ipv6 acl 1 BlockAllIPv6&lt;/BLOCKQUOTE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 17:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240083#M43881</guid>
      <dc:creator>ericgarnel</dc:creator>
      <dc:date>2013-05-07T17:03:13Z</dc:date>
    </item>
    <item>
      <title>WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240084#M43882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eric "VIP" Endorsed! Good post! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 14:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240084#M43882</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-05-08T14:54:12Z</dc:date>
    </item>
    <item>
      <title>WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240085#M43883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 15:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240085#M43883</guid>
      <dc:creator>ericgarnel</dc:creator>
      <dc:date>2013-05-08T15:27:32Z</dc:date>
    </item>
    <item>
      <title>WLC 5508 -7.4.100 mDNS Bonjour snooping</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240086#M43885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fyi, WLC ACL can't generally control all Multicast address traffic, only selective Multicast like Bonjour can be controlled using ACL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 00:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-7-4-100-mdns-bonjour-snooping/m-p/2240086#M43885</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2013-05-16T00:50:43Z</dc:date>
    </item>
  </channel>
</rss>

