cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2726
Views
0
Helpful
5
Replies

ACL mapping in flexconnect

Jorge Conceicao
Level 1
Level 1

Hi

Anyone can help me plz? I have a WLC 8.0 and i'm using flexconnect local switching.

I have 3 SSID's with diferent kind of security but all in same vlan. To apply acl's i can only apply to vlan Id, but i have differents acl's for each SSID.

Anyone can know a solution?

BR

5 Replies 5

Freerk Terpstra
Level 7
Level 7

You can use FlexConnect groups for this, this feature can be found under the wireless tab from the main menu. First configure your FlexConnect ACL and then assign it to the correct WLAN ID in the FlexConnect group. Don't forget to assign your AP's to the new created FlexConnect group(s).

Hi Freerk

Thx for your answer but u can only assign flexconnect acl to vlan ID not wlan ID, thats the problem I have.

Hi Jorge,

I tested your configuration and I see what your problem is. My proposed solution only works for centrally switches WLAN ID's, which is useless in this case and also a little strange (you should think that when you create a WLAN - ACL mapping under a FlexConnect group, it would be pushed to the AP instead of doing it on the WLC..). I guess that the internal working for filtering on the AP has to been changed before this can be done, because right now an ACL is being applied to the physical (sub)interface.

I'm afraid that there is no other solution besides using different VLAN's, which is the better solution anyway.

Abhishek Abhishek
Cisco Employee
Cisco Employee

I don't see that you will be able to apply ACL on WLAN, You can only apply VLAN.

gohussai
Level 4
Level 4

 

Restrictions for FlexConnect ACLs

    FlexConnect ACLs can be applied only to FlexConnect access points. The configurations applied are per AP and per VLAN.

    You can configure up to 512 ACLs on a controller.

    Non-FlexConnect ACLs that are configured on the controller cannot be applied to a FlexConnect AP.

    FlexConnect ACLs do not support direction per rule. Unlike normal ACLs, Flexconnect ACLs cannot be configured with a direction. An ACL as a whole needs to be applied to an interface as ingress or egress.

    You can define up to 512 FlexConnect ACLs, each with up to 64 rules (or filters). Each rule has parameters that affect its action. When a packet matches all the parameters pertaining to a rule, the action set pertaining to that rule is applied to the packet.

    ACLs in your network might have to be modified because Control and Provisioning of Wireless Access Points (CAPWAP) use ports that are different from the ones used by the Lightweight Access Point Protocol (LWAPP).

    All ACLs have an implicit deny all rule as the last rule. If a packet does not match any of the rules, it is dropped by the corresponding access point.

    ACLs mapping on the VLANs that are created on an AP using WLAN-VLAN mapping, should be performed on a per-AP basis only. VLANs can be created on a FlexConnect group for AAA override. These VLANs will not have any mapping for a WLAN.

    ACLs for VLANs that are created on a FlexConnect group should be mapped only on the FlexConnect group. If the same VLAN is present on the corresponding AP as well as the FlexConnect group, AP VLAN will take priority. This means that if no ACL is mapped on the AP, the VLAN will not have any ACL, even if the ACL is mapped to the VLAN on the FlexConnect group.

 

Note: This will give you clear idea How and what kind of ACL can be applied in flex connect mode.

 

 

Ref: http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010001110.html

 

Review Cisco Networking for a $25 gift card