cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
573
Views
3
Helpful
9
Replies

WLC 9800 ACL only internet

Leo TI
Level 1
Level 1

I have a guest WLAN; the issue is with the ACL as it does not restrict access to internal networks. I am testing with a ping to the IP 172.22.10.X. If I remove the first three permits, I lose access to the guest page to enter the credentials.

ip access-list extended SOLO-INTERNET
permit udp any any eq domain
permit tcp any any eq domain
permit udp any eq bootpc any eq bootps
deny ip any 10.0.0.0 0.255.255.255
deny ip any 172.16.0.0 0.15.255.255
deny ip any 192.168.0.0 0.0.255.255
permit ip any any
exit

LeoTI_0-1702135013144.png

LeoTI_1-1702135237453.png

 

 

1 Accepted Solution

Accepted Solutions

this ACL use for web auth WLAN it called pre-auth ACL not for PSK WLAN 
the IP ACL use for WLAN find in policy profile-> Access Policies 

MHM 

View solution in original post

9 Replies 9

Hi
can I ask the issue with radius auth is solve?

LeoTI_0-1702135705569.png

Is web page guest 

no I ask for previous post there was issue between wlc and radius, is it solved?
MHM

It didn't get resolved; in the end, I used a WLAN with PSK

this ACL is CoA ACL ?
MHM

CoA? I don't think so, the users are local, and it works fine. The issue is with the ACL.

this ACL use for web auth WLAN it called pre-auth ACL not for PSK WLAN 
the IP ACL use for WLAN find in policy profile-> Access Policies 

MHM 

LeoTI_0-1702137242753.png

LeoTI_1-1702137361836.png

It got resolved perfectly, thank you very much

You are so welcome friend 

Have  a nice weekend 

MHM

Review Cisco Networking for a $25 gift card