08-06-2024 06:28 AM
Hello
We are planning to use Captive Portal for our guest Wi-Fi and have one inconvenience
The documentation says that the virtual controller doesn't support ACLs for names instead of IP addresses, but documentation hasn't been updated for several years, so I wonder if it's still relevant ?
Maybe there are some modern ways in virtual WLC to manage pre-authentication ACL with names instead of large IPs list ( Many servers for SSO with a third-party provider ) ?
Will be appreciate for any updates
Solved! Go to Solution.
08-06-2024 02:59 PM
The virtual 9800-CL supports this.
8.5 code is EOL, would look at either moving to a 9800 WLC if APs support or 8.10
08-08-2024 07:56 AM
The 8.10 documentation is at https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/access_control_lists.html#dns-based-acls but that still won't help you with vWLC which will not support it.
I agree with @Haydn Andrews that your best option is to upgrade to 9800-CL which is a much more full-featured virtualised WLC and then you will be able to do this.
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_dns_based_acls.html
08-06-2024 06:38 AM
- Not sure what controller platform(s) you are using ; either 9800 or aireos based ?
I found from https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-8/b_cisco_mobility_express_8_8.pdf
>...Starting release 8.7, one can configure DNSPre-Auth ACLs as well asIPv4 based pre-auth ACLs on a WLAN.
A maximum of 20 URL rules per ACL are supported and size of each URL is maximum of 255 characters.
Wildcards are supported in the URL as well.
Not sure if this is applicable to the Captive Portal context as well ,
M.
08-06-2024 07:10 AM
We use Standalone Controllers ( Virtual one on 8.5 software )
The documentation for the latest version says that this isn't available for virtual platforms ( It can be seen on the screenshot )
Looks like it's only really available for hardware platforms, one of which you mentioned above
However, I would be grateful for tips if there is another way without a hardware upgrade
08-06-2024 02:59 PM
The virtual 9800-CL supports this.
8.5 code is EOL, would look at either moving to a 9800 WLC if APs support or 8.10
08-08-2024 07:56 AM
The 8.10 documentation is at https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/access_control_lists.html#dns-based-acls but that still won't help you with vWLC which will not support it.
I agree with @Haydn Andrews that your best option is to upgrade to 9800-CL which is a much more full-featured virtualised WLC and then you will be able to do this.
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_dns_based_acls.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide