I have a group of wireless AP running WDS, all authentications (infrastructure and clients) are done with a Cisco ACS 3.3 which is separated by a Checkpoint firewall. Everything was working fine until recently I relocated all the APs to a different VLAN. The only change is the IP of the APs, no change to the ACS, proper rules are created on the firewall. All authentications are now failed even with the same credentials and the Autentication Failure Code in ACS is "User Access Filtered". No "Network Access Restrictions" has ever configured on ACS, why ACS is giving this error code? Looking at the log of the ACS, the only thing different is that all requests now come from a high "NAS-Port" >80000. Anyone has a clue? Thanks.