08-19-2020 02:16 AM - edited 07-05-2021 12:25 PM
Hello,
We have deployed 9800-CL Wireless controller in the AWS cloud. As we know it supports only local switching in the cloud hence the guest user subnet is configured in the LAN.
Guest user is getting successfully authenticated on the internal captive portal on the WLC and able to access the internet.
To stop guest user from accessing company's internal resources, we have applied 'internet only' ACL (which blocks guest subnet from accessing internal network) in the VLAN tab of the flex profile however users are still able to access the internal network.
May I know if we are applying the ACL at right place? or should this ACL be under policy_ACL tab in the flex profile?
As I understand policy_acl tab in Flex profile is only for webauth ACLs?
Regards,
08-20-2020 09:44 AM
08-26-2020 04:02 AM
Although the VLAN part of the flex profile allows you to assign an ACL it doesn't push it to the AP itself. For that you'll need to use the Policy ACL tab. Just select the appropriate ACL in there, with nothing else and it'll get added to the AP.
With Flexconnect you can also still assign the ACL to the Policy Profile associated to the WLAN. In this case you'd still need to push the ACL to the AP as a Policy ACL.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide