cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
657
Views
0
Helpful
5
Replies

Cisco vWLC Web-Access from different VLAN

florian.hanig1
Level 1
Level 1

Hi Guys,

 

i recently setup a vWLC.

 

The Mgmt Interface with Access to Web-Gui and CLI is VLAN 99 (Net 10.0.99.0/24, Gateway 10.0.99.1)

I have another VLAN 10 (Net 10.0.10.0/24, Gateway 10.0.10.1).

 

So i just configured my Firewall to permit Data from VLAN 10 to 99.

For other Devices like Switches, which are in MGMT Vlan, it work.

 

But I cant access to vWLC Web-Gui or CLI, if I'm in VLAN 10.

I think its a routing issue on vWLC Side...

 

The vWLC has 2 Interfaces an one interface is the vlan 10 interface.

If I remove vlan 10 interface from vWLC, the acesss works from VLAN10 to 99.

 

So what can I do to do this ?

5 Replies 5

Ric Beeching
Level 7
Level 7

Hi Florian,

 

You may be experiencing routing asymmetry as your client will go from VLAN 10 -> VLAN 99 -> WLC but when the WLC sees the source IP of VLAN 10, it will get confused as it has an interface in that subnet and try to go WLC -> VLAN10

 

On the vWLC, issue the command config network mgmt-via-dynamic-interface enable then access the GUI via its VLAN 10 interface.

 

Cheers,

Ric

-----------------------------
Please rate helpful / correct posts

Yes, that works...

 

But i want to enable the WLC mgmt only for special clients in vlan 10...

 

Then the 'easiest' way would be to reserve the IP of those clients and create a CPU ACL on the WLC to allow only those clients access to the interface.

 

Warning though, CPU ACLs can be a bit of a headache and you may end up locking yourself out of the WLC if doing remote work.

 

Personally I would try and resolve this by re-jigging your VLAN/Subnet setup.

 

Cheers

Ric

-----------------------------
Please rate helpful / correct posts

I agree with Ric... be very careful when you are messing around with the CPU acl.  This can be done, but your better off testing in a lab environment where you can just reload the controller if you get locked out. 

-Scott
*** Please rate helpful posts ***

Can anyone please share the commands to permit only Net 10.0.99.0/24 and a Single IP: 10.0.9.5 to the Web-Gui.. ?

 

Review Cisco Networking products for a $25 gift card