cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1645
Views
0
Helpful
1
Replies

ISE dACL for FlexConnect AP

CSCO10662744_2
Level 1
Level 1

hello all,
I found a similar thread, but it didn't exactly answer my question:
https://supportforums.cisco.com/discussion/12114056/flex-connect-user-acl-aps-locally-switched

Should I configure a regular ACL, or Airespace ACL on ISE, to support FlexConnect mode AP's?

On the FlexConnect AP's (WLC), do I configure a regular ACL, or FlexConnect ACL?
The FlexConnect AP's are running a few SSID's, some are centrally switched, and some are locally switched.

Thanks,
Kevin

 

1 Reply 1

tonyp8581
Level 1
Level 1

It depends which version of WLC,  v 7.4.110 has a bug (Unfortunately, I don't remember the bug Id).  You need to create a regular and FlexConnect using the same name.  With recent version (I'm using 7.6.130), you don't need the regular ACL, just a FlexConnect ACL.  So, to answer your question, with FlexConnect, you must use FlexConnect ACL.

Good links:

http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010001110.html

 

http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/116143-config-cise-posture-00.html