02-04-2021 11:40 PM - edited 07-05-2021 01:11 PM
Hi Guys,
i recently setup a vWLC.
The Mgmt Interface with Access to Web-Gui and CLI is VLAN 99 (Net 10.0.99.0/24, Gateway 10.0.99.1)
I have another VLAN 10 (Net 10.0.10.0/24, Gateway 10.0.10.1).
So i just configured my Firewall to permit Data from VLAN 10 to 99.
For other Devices like Switches, which are in MGMT Vlan, it work.
But I cant access to vWLC Web-Gui or CLI, if I'm in VLAN 10.
I think its a routing issue on vWLC Side...
The vWLC has 2 Interfaces an one interface is the vlan 10 interface.
If I remove vlan 10 interface from vWLC, the acesss works from VLAN10 to 99.
So what can I do to do this ?
02-05-2021 12:13 AM
Hi Florian,
You may be experiencing routing asymmetry as your client will go from VLAN 10 -> VLAN 99 -> WLC but when the WLC sees the source IP of VLAN 10, it will get confused as it has an interface in that subnet and try to go WLC -> VLAN10
On the vWLC, issue the command config network mgmt-via-dynamic-interface enable then access the GUI via its VLAN 10 interface.
Cheers,
Ric
02-05-2021 02:35 AM
Yes, that works...
But i want to enable the WLC mgmt only for special clients in vlan 10...
02-05-2021 03:52 AM
Then the 'easiest' way would be to reserve the IP of those clients and create a CPU ACL on the WLC to allow only those clients access to the interface.
Warning though, CPU ACLs can be a bit of a headache and you may end up locking yourself out of the WLC if doing remote work.
Personally I would try and resolve this by re-jigging your VLAN/Subnet setup.
Cheers
Ric
02-05-2021 08:32 AM
I agree with Ric... be very careful when you are messing around with the CPU acl. This can be done, but your better off testing in a lab environment where you can just reload the controller if you get locked out.
02-05-2021 11:00 AM
Can anyone please share the commands to permit only Net 10.0.99.0/24 and a Single IP: 10.0.9.5 to the Web-Gui.. ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide