cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
395
Views
1
Helpful
4
Replies

WLC9800 - Application Visibility & QoS setup + monitoring

eeebbunee
Level 3
Level 3

Hello Professionals,

I'm trying to start wireless traffic control, what I want to implement is 'Drop packets for specific URL access'.

First trial was 'URL filtering'. I configured and typed 
*.indeed.com
www.indeed.com
It seems working good, and I applied this rule for all of my WLANs. However, it sometimes works, sometimes don't.
When try nslookup from test PC to indeed.com, it redirects the IP address what I configured, but still I was able to reach.
I could've cleared caches from browsers, but I don't think it is enough.

Second trial was 'AVC + QoS' configuration.
I have created 'custom application' from Application Visibility. From my custom category I was able to see BLOCK_INDEED which I made.
I also created QoS policy-map and choose WLAN interface, but was uncertain which category should I choose cause there are three different custom category. (custom-category, custom1-category, custom2-category)

eeebbunee_0-1753980348858.png

So I chose one of each, and applied to test WLAN. from test WLAN, policy also mapped.

eeebbunee_1-1753980525383.png

It seems QoS is not implementing. Which step that I missed?

 

Appreciate your time.

 

4 Replies 4

There are two topics here which is not related 

1- Url filter can I see how you config it.

2- QoS i will check it

MHM

 

Hello! 

URL filter was my first trial, and it is currently disabled to see QoS running.
Though, I'm sending URL filters. This rule was applied to my policy - Post-auth.

eeebbunee_0-1753985904558.png

I also have tested few more URLs such as Teamviewer, Anydesk, but Anydesk blocking goes well unlike Teamviewer website accessing. It just let me in to Teamviewer.com or google search - Teamviewer and click the website.


Since URL filtering showed me different results for multiple times testing, so I would like to turn on both features - URL filteres, QoS policy map. Besides, it would be great if I could see the packet drop logs/stats..

Thank you very much.

Hello,

I realized that I have to choose 'Protocol' not 'Category' from QoS policy-map.
I was able to find BLOCK_INDEED from available protocol. However, still I am able to reach indeed.com even though I made QoS to drop.

 

Post-auth' meaning this url filter is filter url after client authc

But url filter is in real dns-based ACL

It work only if DNS answer to client request with A record if DNS answer with CNAME alias it not work.

So it can for non work url is that DNS send CNAME not A record.

MHM

Review Cisco Networking for a $25 gift card