<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do ACLs on WLCs limit throughput in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/do-acls-on-wlcs-limit-throughput/m-p/1360007#M9111</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have only used ACL's on the WLC in a lab environment and removed it when I put it into production.&amp;nbsp; I would never use it in a production environment.&amp;nbsp; Either place your ACL's on your L3 devices or use a FW if guest traffic is either directed out to the DMZ or if you are using guest anchoring.&amp;nbsp; I never did see any throughput drop, but then again never used ACL's in a production network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html"&gt;http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6366/products_qanda_item09186a00809ba482.shtml"&gt;http://www.cisco.com/en/US/products/ps6366/products_qanda_item09186a00809ba482.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a thread than has some info also:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/message/3005351;jsessionid=7210AE0A26503F13C80A4ACE966D1DCF.node0"&gt;https://supportforums.cisco.com/message/3005351;jsessionid=7210AE0A26503F13C80A4ACE966D1DCF.node0&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 07 Mar 2010 16:01:10 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2010-03-07T16:01:10Z</dc:date>
    <item>
      <title>Do ACLs on WLCs limit throughput</title>
      <link>https://community.cisco.com/t5/wireless/do-acls-on-wlcs-limit-throughput/m-p/1360006#M9110</link>
      <description>&lt;P&gt;My boss wants me to create a WLAN for guests, so I created and VLAN and SSID for them and used a webauth bundle with an accept button.&amp;nbsp; Next I was told the WLAN needs to be limited to DHCP, DNS, HTTP and HTTPS.&amp;nbsp; I created an ACL on the controller and tested it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My throughput is cut by 66% on 802.11a/b/g access points, but seems to have no effect on the 802.11n access points.&amp;nbsp; My normal download is about 22 mb/s on 802.11g, but with ACL applied, it dwindles down to 7mb/s.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I be placing the ACL on the 6509 that is the host chassis for the WLC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any other suggestions?&amp;nbsp; What is everyone else doing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 01:35:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/do-acls-on-wlcs-limit-throughput/m-p/1360006#M9110</guid>
      <dc:creator>tdennehy</dc:creator>
      <dc:date>2021-07-04T01:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: Do ACLs on WLCs limit throughput</title>
      <link>https://community.cisco.com/t5/wireless/do-acls-on-wlcs-limit-throughput/m-p/1360007#M9111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have only used ACL's on the WLC in a lab environment and removed it when I put it into production.&amp;nbsp; I would never use it in a production environment.&amp;nbsp; Either place your ACL's on your L3 devices or use a FW if guest traffic is either directed out to the DMZ or if you are using guest anchoring.&amp;nbsp; I never did see any throughput drop, but then again never used ACL's in a production network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html"&gt;http://www.cisco.com/en/US/docs/wireless/technology/guest_access/technical/reference/4.1/GAccess_41.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6366/products_qanda_item09186a00809ba482.shtml"&gt;http://www.cisco.com/en/US/products/ps6366/products_qanda_item09186a00809ba482.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a thread than has some info also:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/message/3005351;jsessionid=7210AE0A26503F13C80A4ACE966D1DCF.node0"&gt;https://supportforums.cisco.com/message/3005351;jsessionid=7210AE0A26503F13C80A4ACE966D1DCF.node0&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Mar 2010 16:01:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/do-acls-on-wlcs-limit-throughput/m-p/1360007#M9111</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2010-03-07T16:01:10Z</dc:date>
    </item>
  </channel>
</rss>

