<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC and dACLs in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893849#M7876</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; ISE ACLs are the better way to go versus VLAN change. Most clients will not support CoA and will sit and spin.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Apr 2012 21:02:29 GMT</pubDate>
    <dc:creator>George Stefanick</dc:creator>
    <dc:date>2012-04-13T21:02:29Z</dc:date>
    <item>
      <title>WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893844#M7871</link>
      <description>&lt;P&gt;Does anyone know if dACLs on a WLC controller using the latest code require a pre-configuration of the ACLs on the controller? All documentation seems to indicate the ACLs must be created first on the controller and the policy engine (ISE or ACS) push down the name of the ACL to be used.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893844#M7871</guid>
      <dc:creator>Jim Thomas</dc:creator>
      <dc:date>2021-07-04T04:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893845#M7872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The wlc doesn't support dACLs but you would use the wlc acl's. Q&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Fella&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 19:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893845#M7872</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-04-13T19:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893846#M7873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Jim, long time no see!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the WLC, this is correct.&amp;nbsp; You have to preconfigure the ACL on the WLC, and ISE will send the name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 19:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893846#M7873</guid>
      <dc:creator>Stephen Rodriguez</dc:creator>
      <dc:date>2012-04-13T19:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893847#M7874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To piggy back in ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE supports 2 ACLs (downloadable or named). The WLC supports NAMED ACLS. The name should be identical in the ISE policy manger and the WLC. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 20:57:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893847#M7874</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-04-13T20:57:16Z</dc:date>
    </item>
    <item>
      <title>WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893848#M7875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys, stephen that helps out, just needed the confirmation since I'm light on the wireless.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 20:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893848#M7875</guid>
      <dc:creator>Jim Thomas</dc:creator>
      <dc:date>2012-04-13T20:58:40Z</dc:date>
    </item>
    <item>
      <title>WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893849#M7876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; ISE ACLs are the better way to go versus VLAN change. Most clients will not support CoA and will sit and spin.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 21:02:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893849#M7876</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-04-13T21:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893850#M7877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vlan changes on the wireless has not caused me any issues. I have used it on ACS and now on ISE. On the wired side it can be an issue as you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Fella&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 21:41:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893850#M7877</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-04-13T21:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893851#M7878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the device is not 100% profiled and later becomes profiled as other probes determine what the  device is and the device needs to move to another VLAN a Coa happens.  it's then that the supplicant woll sit and spin.  Anyconnect client for example will recognize that no traffic is passing  after a certain period of time and will reip. Other supplicants for example window zero config don't do that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 22:05:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893851#M7878</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-04-13T22:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893852#M7879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's how I have mine setup though, but it's my lab that I do the testing.  I have one SSID and then multiple profiles with vlan, session timer and QoS attributes depending on what AD group the user matches. I haven't tested other supplicants beside a windows 7 and XP client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Fella&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 22:10:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893852#M7879</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-04-13T22:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893853#M7880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;George,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still prefer to match an SSID to an OU and either accept or deny. The named acl and dACL I think is a nice idea, but you have to account for all the users on that given subnet.  I think after playing around with ISE an seeing what really works in real life and what is painful will help determine what is the best way I deploy in certain situations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Fella&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 22:16:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893853#M7880</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-04-13T22:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893854#M7881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm curious, can you be more specific when you say you match a ssid to a ou. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree each deployment wil have a unique deployment requirements. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 22:31:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893854#M7881</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-04-13T22:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893855#M7882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I create a policy that say is the user using "employee" SSID and is part of the "wireless employee" OU... And some others (device group, device location, EAP type, etc). So if a domain user tries to access the "employee" SSID using his or her domain credential and is not part of the "wireless employee" OU, ACS or ISE will send a reject to the WLC.  That username is also accounted for in the failed attempts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Fella&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 22:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893855#M7882</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-04-13T22:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893856#M7883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe not a totally relevant question to this post but does an autonomous ap (AP-1142N) support dACL from ACS? I'm not using any WLC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Putte&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 10:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893856#M7883</guid>
      <dc:creator>snyggsomfan</dc:creator>
      <dc:date>2012-05-30T10:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: WLC and dACLs</title>
      <link>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893857#M7884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Scott, did this ever happend to you or anyone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3716531#3716531" rel="nofollow"&gt;https://supportforums.cisco.com/message/3716531#3716531&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 16:04:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-and-dacls/m-p/1893857#M7884</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2012-08-24T16:04:35Z</dc:date>
    </item>
  </channel>
</rss>

