cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1355
Views
5
Helpful
2
Replies

ACL on 9800-CL

mhapsekar.suyog
Level 1
Level 1

Hello,

We have deployed 9800-CL Wireless controller in the AWS cloud. As we know it supports only local switching in the cloud hence the guest user subnet is configured in the LAN.

 

Guest user is getting successfully authenticated on the internal captive portal on the WLC and able to access the internet.

 

To stop guest user from accessing company's internal resources, we have applied 'internet only' ACL (which blocks guest subnet from accessing internal network) in the VLAN tab of the flex profile however users are still able to access the internal network.

 

May I know if we are applying the ACL at right place? or should this ACL be under policy_ACL tab in the flex profile?


As I understand policy_acl tab in Flex profile is only for webauth ACLs?

 

Regards,

2 Replies 2

Rich R
VIP
VIP
Guest users should be on a separate VLAN that does not have any access at all to internal resources!
You should not be relying on an ACL to protect you!

RosesTin
Level 1
Level 1

Although the VLAN part of the flex profile allows you to assign an ACL it doesn't push it to the AP itself. For that you'll need to use the Policy ACL tab. Just select the appropriate ACL in there, with nothing else and it'll get added to the AP.

 

With Flexconnect you can also still assign the ACL to the Policy Profile associated to the WLAN. In this case you'd still need to push the ACL to the AP as a Policy ACL.

Review Cisco Networking for a $25 gift card