cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
685
Views
0
Helpful
1
Replies

WLAN acl help

Kurt Warner
Level 1
Level 1

ok what i am trying to do is set up an acl that will allow my wirless guest to get to the internet but have no access to my internal network.  I gave them access to my dhcp server and dns server . Pulls a DHCP but say it can not connect to the DNS server,  What am i missing ?

1 Reply 1

Nicolas Darchis
Cisco Employee
Cisco Employee

You only authorize when the source port is DNS. It's wrong.

Client sending request :

source port = dynamic

destination port = dns ports on DNS server

server replying to client :

source port=DNS port on DNS server

destination = same dynamic unpredictable port as mentioned above

so you should authorize "from any to DNS server ip and dns port" and "from DNS server ip and port to any"

Review Cisco Networking for a $25 gift card