cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1198
Views
0
Helpful
3
Replies

9800 ACL implementation per SSID or per User session

nareh84
Level 3
Level 3

hi,

 

currently we have 9800 vwlc integrated with ISE. the requirement is that when mobile connects to SSID ((flexconnect SSID with Layer2 WPA2 and 802.1x), it can access only internet and should connect to internal resources except for dns and dhcp purpose.

 

i tried following but nothing is working.

 

1.configured acl (for testing acl is permit ip any any) on 9800vwlc and called this ACL using airspace-acl as well as filter id but after i apply it to authorization policy, user is not able to connect to SSID .

2. configured acl (for testing acl is permit ip any any) on 9800 and configure WLAN ACL (Configuration > Policy > Policy Profile > Access Policies (tab)> WLAN ACL) and point it to ACL configured on same WLC. and i am getting incorrect ACL error.

 

is it possible to configure ACL per SSID or per user session when user is authenticated via 802.1x.

 

Regards

 

Naray

 

3 Replies 3

Rich R
VIP
VIP

What version of code are you using?

 

WLAN ACL is working fine for us on 17.5.1 - applied to the policy profile - WLAN IPv4 ACL on Access Policies tab on the GUI.

 

On CLI:
wireless profile policy <policyname>
 ipv4 acl <acl-name>

hi,

 

version is 17.03.01

Rich R
VIP
VIP

Can't remember if we tried it on 17.3.1.

You could try 17.5.1 or at least 17.3.3.

Review Cisco Networking for a $25 gift card