cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
200
Views
0
Helpful
1
Replies

Complex ACL on a WLC2504

BSmith2277
Level 1
Level 1

I want to create an ACL that if a wireless client is in a certain IP Address range, then they are directed to a particular interface on the WLC.

If the wireless client is not in that range, then they are directed to a different interface on the WLC.

If this is possible, what would those ACLs look like?

 

Bryan Smith

 

1 Reply 1

Leo Laohoo
Hall of Fame
Hall of Fame
I want to create an ACL that if a wireless client is in a certain IP Address range, then they are directed to a particular interface on the WLC.

If the wireless client is not in that range, then they are directed to a different interface on the WLC.

I can assure you the WLC will never be able to do something like that.  WLC's ACL "function" is very ... basic.  

 

Besides ... it doesn't make sense.  The IP address of a client depends entirely upon the SSID they've authenticated to.  

 

Let's say you have three SSIDs:  A, B and C.  

 

SSID A is attached to Dynamic Interface A with an IP address of 10.0.1.0/24 (10.0.1.1 as default gateway). 

 

SSID B is attached to Dynamic Interface B with an IP address of 192.168.0.0/24 (192.168.0.253 as default gateway).  

 

SSID C is attached to Dynamic Interface C with an IP address of 172.16.0.0/24 (172.16.0.1 as default gateway).  

 

NOTE:  Depending on the model of your WLC, you can assign each Dynamic Interface a particular port of the WLC (like the 5508).  However, when you do this, you rule out redundancy.  

 

So if a user authenticates to SSID B, the user gets a valid IP address and all traffic for SSID B goes down to the WLC port assigned to the Dynamic interface.  

 

If a user authenticates to SSID A, the user gets a valid IP address and all traffic for SSID A goes down to the WLC port assigned to the Dynamic interface.  

 

It works, but you don't need ACL.

Review Cisco Networking for a $25 gift card