cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
335
Views
0
Helpful
2
Replies

ACL

I am applying an ACL on the controller, and permitting only myself and the other Admin access to the Controller GUI and denying everyone else. However, when we have someone put the IP in the URL, they are still able to see the LAN Controller GUI. What am I doing wrong?

2 Replies 2

Freerk Terpstra
Level 7
Level 7

Hi Johanthan,

That depends on the place where your are putting the ACL and how the ACL looks like. If filtering on external firewalls or routers is out of the picture, my recommendation is to use an "CPU ACL" on the WLC to protected access to the management-plane. Keep in mind that not only your management traffic is crossing the CPU of the WLC, also CAPWAP traffic from and to the access-points needs to be allowed for example. Because of this most people just filter on TCP 22/80/443 and allow everything else. Be cautious implementing this because there is a chance that you lock yourself out :-)

Please rate useful posts... :-)

mohanak
Cisco Employee
Cisco Employee

There are CPU ACLs which can filter traffic destined for the Management Interface.

http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/71978-acl-wlc.html#cpuacl

Review Cisco Networking for a $25 gift card