Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ISE WLC DACL Flex

ISE 1.2 Patch 2

VWLC 7.4.100.0

Specifically flex connect APs

We have successfully built the first self registration MAB'ed Z policy which authorizes all MACs to hit the CWA and a redirect. WIth Flex you must have an IPV4 and a Flex ACL on the controller that is referenced in the Z result policy. We have this in and it is working to here. Upon completion of the Guest Portal signup, we also reauth, which then combs the Zs for the Guest flow, which is being hit and resulting in a Guest Z Result. Our dilemma is that upon the successful secondary Z, the client will receive the successful completion and the logs also show the successful Z and Z result, but the client can not go anywhere and soon reauths. On the controller, the client has the Guest IPV4 acl. Our big question, is the client supposed to have a cloned flex connect acl also applied, and if so, how do I tweak the Z result to do so as all of the documentation that I could find references are for the redirect only, and that is for a bug workaround until we're on 7.5.

Again, specifically flex APs

Everyone's tags (5)
3 REPLIES
New Member

ISE WLC DACL Flex

Ben,

Look at this doc. It appears you need to be on 7.5 for per user radius acl's to work on Flexconnect.

http://www.cisco.com/en/US/products/ps10315/products_tech_note09186a0080b3690b.shtml

New Member

ISE WLC DACL Flex

Still pretty buggy and my testing shows that you can only leverage one acl per mapped vlan too...someone please correct me.

New Member

apparently this bug was fixed

apparently this bug was fixed in 7.5 but that image was removed from Cisco's site and they released 7.6 which fixes the issue. I am about to start implementing this so I can update with any results.

Out of interest, do you have this working in 7.6?

 

Thanks

Mario

981
Views
0
Helpful
3
Replies