<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACL - WLC Webauth functionality in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/acl-wlc-webauth-functionality/m-p/2050001#M44784</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have Wireless Guest access implemented in the site using WLC webauth functionality. The IP address pool used for guest access is having access to internal devices other than internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are implementing access-list in the gateway of the guest users to restrict their access only to internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but after implementing the ACL, Guest authentication web page is not being recieved by clients and they are not able to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the ACL used in the gateway. Please suggest if any other ports or protocols need to be allowed. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; IP access-list extended PNU_GUEST_ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10 permit ip &amp;lt;Guest subnet&amp;gt; &amp;lt;WLC-subnet&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;15 permit ip &amp;lt;Guest subent&amp;gt; &amp;lt;WCS-subnet&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;20 permit ip &amp;lt;Guest subnet&amp;gt; &amp;lt;proxy-ip&amp;gt; &amp;lt;proxy port&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;30 permit tcp &amp;lt;Guest subnet&amp;gt; &amp;lt;DNS IP&amp;gt; &amp;lt;port 53&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;40 permit ip &amp;lt;Guest subnet&amp;gt; host 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;50 permit ip &amp;lt;Guest subnet&amp;gt; &amp;lt;DHCP IP&amp;gt; &amp;lt;port 67&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;60 permit ip any &amp;lt;Guest subnet&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;70 deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access-list is applied in "IN Direction" on the gateway interface of guests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Madhan kumar G&lt;/P&gt;</description>
    <pubDate>Sun, 04 Jul 2021 05:44:41 GMT</pubDate>
    <dc:creator>madhankumar.g</dc:creator>
    <dc:date>2021-07-04T05:44:41Z</dc:date>
    <item>
      <title>ACL - WLC Webauth functionality</title>
      <link>https://community.cisco.com/t5/wireless/acl-wlc-webauth-functionality/m-p/2050001#M44784</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have Wireless Guest access implemented in the site using WLC webauth functionality. The IP address pool used for guest access is having access to internal devices other than internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are implementing access-list in the gateway of the guest users to restrict their access only to internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but after implementing the ACL, Guest authentication web page is not being recieved by clients and they are not able to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the ACL used in the gateway. Please suggest if any other ports or protocols need to be allowed. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; IP access-list extended PNU_GUEST_ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10 permit ip &amp;lt;Guest subnet&amp;gt; &amp;lt;WLC-subnet&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;15 permit ip &amp;lt;Guest subent&amp;gt; &amp;lt;WCS-subnet&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;20 permit ip &amp;lt;Guest subnet&amp;gt; &amp;lt;proxy-ip&amp;gt; &amp;lt;proxy port&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;30 permit tcp &amp;lt;Guest subnet&amp;gt; &amp;lt;DNS IP&amp;gt; &amp;lt;port 53&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;40 permit ip &amp;lt;Guest subnet&amp;gt; host 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;50 permit ip &amp;lt;Guest subnet&amp;gt; &amp;lt;DHCP IP&amp;gt; &amp;lt;port 67&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;60 permit ip any &amp;lt;Guest subnet&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;70 deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access-list is applied in "IN Direction" on the gateway interface of guests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Madhan kumar G&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 05:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acl-wlc-webauth-functionality/m-p/2050001#M44784</guid>
      <dc:creator>madhankumar.g</dc:creator>
      <dc:date>2021-07-04T05:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACL - WLC Webauth functionality</title>
      <link>https://community.cisco.com/t5/wireless/acl-wlc-webauth-functionality/m-p/2050002#M44785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well you can create a pre auth acl which allows DNS, DHCP, permit any to the WLC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Sep 2012 14:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acl-wlc-webauth-functionality/m-p/2050002#M44785</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-09-30T14:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: ACL - WLC Webauth functionality</title>
      <link>https://community.cisco.com/t5/wireless/acl-wlc-webauth-functionality/m-p/2050003#M44786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Scott. Your suggestion really helped. I have created pre auth ACLs and achieved positive results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Madhan kumar G&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:29:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acl-wlc-webauth-functionality/m-p/2050003#M44786</guid>
      <dc:creator>madhankumar.g</dc:creator>
      <dc:date>2012-10-01T14:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: ACL - WLC Webauth functionality</title>
      <link>https://community.cisco.com/t5/wireless/acl-wlc-webauth-functionality/m-p/2050004#M44787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to hear... Thanks for using the rating system also! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2012 14:50:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acl-wlc-webauth-functionality/m-p/2050004#M44787</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-10-01T14:50:08Z</dc:date>
    </item>
  </channel>
</rss>

