Internet only access ACL (not answer)

Hello

We have a new WLC set up in a remote desktop control 4 access points and must restrict access to our comments of SSID only internet access. It's the way the network is currently configured:

3750G Switch:

Two VLAN for layer 3, one for the inside network and internet access company and one guest access to the internet only. These two have addresses for assistance on them pointing to our DHCP server that has extended for comments and the Corporate VLAN. The controller is located in a trunk port with an address on our subnet management and the AP on access on the same subnet for management ports. Subnets are as follows:

10.80.27.0 - wireless Corporate (vlan 27)

10.80.28.0 - Wireless comments (vlan 28)

10.80.10.0 - management (vlan 10)

(In addition, we have several other VLANs on a 172.16.0.0/16 and the 10.80.X.0/24 network)

To limit access to clients without comment thread, I tried to add the following ACL on vlan 28 thinking this would allow requests DHCP and DNS for wireless and web access clients while denying access to others within the network resources:

IP extended ACL UNTRUSTED access list

permit udp 10.80.28.0 0.0.0.255 any eq area

permit udp 10.80.28.0 0.0.0.255 any eq bootps bootpc

permit tcp 10.80.28.0 0.0.0.255 any eq www

permit tcp 10.80.0.0 0.0.255.255 any what eq 443

deny ip 10.80.28.0 0.0.0.255 10.0.0.0 0.255.255.255

deny ip 10.80.28.0 0.0.0.255 172.16.0.0 0.0.255.255

So basically, without applied ACL, a customer receives an address from the DHCP server without problem and is able to surf on the internet as well as all inside resources. When I apply the ACL to the VLANs, customers can no longer receive an IP address from the DHCP server. However, if a customer had already received an address before the application of the ACL, that the customer is able to navigate while being denied access to the network when the ACL is applied. Which is the desired effect. It seems that the problem is access to the DHCP server when the ACL is in place. Is misconfigured my ACL or I go just about it entirely the wrong way?

(my apologies for the too wordy explanation, wanted to make sure I had enough detail in there)

I had a problem like this before.

I shared my bootps / bootpc in each for his own line and it started working

Something like

Note DHCP server

permit udp 10.80.28.0 0.0.0.255 eq bootpc host

permit udp 10.80.28.0 0.0.0.255 eq bootps host

What if you add the log after deny it. Logs show something? Send to a syslog might help filtering

Tags: Cisco Wireless

Similar Questions

  • BlackBerry Q5 downloads from the internet only recording does not

    Help please, how to save internet downloads? It gives the ability to save, it automatically opens the file.

    I had the same problem. But all you have to do is to maintain the link until the open option box then u click on save the link to the file and it will save

  • LR CC 2015 only opens after (not answer) and delay

    I have a recurring problem with LR being slow to open.  I almost always get a (LR does not) message and then I let stand opens, but not all the time.

    Help please. On the time limit.

    Hello

    It's ok if you are using Mac

    You can follow these steps

    Open Lr

    Go to Lightroom-> preferences-> file handling and change the size of the cache for at least 30 GB.

    Please press purge cache as well.

    Click OK

    Release of Lr and re - open that

    ~ Jitendra

  • SE error message: "nvlddmkm.sys not answer but recovered" and cannot access Starcraft II or LOTRO

    Original title: nvlddmkm.sys does not

    Just started having this couple weeks message. Killed or damaged at least one of my 9800 GT cards (SLI), which have been replaced under warranty. Who sets the part of the question of the display, but still cannot access to Starcraft II or LOTRO - connect and just get a black screen (have sound, no picture). Then the message "nvlddmkm.sys not answer but recovered" then nothing and having to use task Mgr to close the program. Here's the suspect: update the video driver (uninstalled old, clean install) which again helped a little but the screen remains black when entering the games. While they inspected the files, the file Nvidia\Displaydriver shows the new driver as the device Mgr when I check that. BUT then when I check the directory ofC:\windows\system32\drivers there is still an OLD version of nvlddmkm.sys. I'm sure that it is the culprit, but it won't let me delete it or rename it who were other corrections that I read about. I know that this is an endemic problem with Windows and has been for awhile now. ANY suggestions?

    Hi malomar,.

    1. This only happens when you play Starcraft II and LOTRO?

    You can try to uninstall and reinstall all the programs and features Nvidia drivers and Device Manager.

    Step 1:

    Uninstall the audio drivers from programs and features

    a. click on start

    b. type appwiz.cpl in the start search

    c. search for all driver packages, Nvidia, right click and uninstall.

    Step 2:

    Uninstall the drivers from Device Manager.

    a. click on start

    b. type devmgmt.msc in search, and then press enter

    c. in find Manager device for the device, right-click on it and select the option uninstall.

    After you remove the drivers of these two places, you can try to remove the NVIDIA folder and restart to see if that solves the problem after I installed the generic drivers.

    Step 3:

    To delete the folder:

    one. Click on start and Type C:\windows\system32\drivers folder in start search

    b. click on drivers and select nvlddmkm.sys

    c. right click and rename nvlddmkm.sys in nvlddmkm.sys.old. or delete.

    d. restart the computer and check.

    You can also check the manufacturer's website and download the latest drivers from Nvidia:

    http://www.nvidia.com/download/index.aspx?lang=en-us

    Also check the Nvidia support link:

    http://forums.nvidia.com/index.php?showtopic=45605

    Hope this information is useful.

    Jeremy K
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

    If this post can help solve your problem, please click the 'Mark as answer' or 'Useful' at the top of this message. Marking a post as answer, or relatively useful, you help others find the answer more quickly.

  • I subscribed to Pack Adobe and not only there me not allowed to do what I need it to do, he charged me the 9.99 and cannot me access to the subscription describes additional features. Worse, it is - I can't see it in my plans to UNSUBSCRIBE.

    I subscribed to Pack Adobe and not only there me not allowed to do what I need it to do, he charged me the 9.99 and cannot me access to the subscription describes additional features. Worse, it is - I can't see it in my plans on my Adobe account to UNSUBSCRIBE. Help! How can I unsubscribe?

    Hello

    An answer depends on where you bought the subscription for.  Please take a look at your purchase confirmation email.

    (a) Apple App Store

    Contact Apple - Apple Support support

    iTunes - account & billing - Apple Support

    (b) Google Play Store

    Subscriptions on Google Play - game Google Help

    (c) adobe web site

    Cancel your subscription or membership. Acrobat, services Cloud of Document PDF

    If none of the above answers your question, please contact Adobe customer service directly.  Sorry for the inconvenience.

  • connected as long as User1 I can only access the srv record (Explorer) - execute / run as he is denied (the path not found or insufficient rights)

    Original title: denied enforcement program

    Configuration:
    -Win server 2003 standard (in the Working Group)
    -Portable Acer Aspire 5100, Windowx XP Home Edition sp3

    Problem:
    On laptop, there are 3 users: administrator (administrators), (power user) User1 and User2 (user).
    Logged on as administrator or User2 I can access the server disk, run the executable SRV drive etc, but connected as
    User1, I can only access the srv record (Explorer) - execute / run as it is denied (the path not found or)
    insufficient rights). The same phenomenon occurs even if User1 receives administrator rights.
    On the server side there is no restriction or limitation to User1 (because it's in the group, where
    any member of this group (also User2) has no problem). Logging as User1 on others
    PC there is no problem.
    Grateful for any suggestions / help.
    Marjan

    Hello

    Try to take possession of the file or program and check.

  • If I buy Creative Cloud subscription should I used products only in connection or without an internet connection, I will not use this app?

    If I buy Creative Cloud subscription should I used products only in connection or without an internet connection, I will not use this app?

    Hi alperb33255764,

    You can use what you want, there is no such limitation. However when you go to cloud service based like loading or sync files to your cloud storage, you need an active Internet connection.

    I recommend you see this KB doc for more information on creative cloud: https://helpx.adobe.com/creative-cloud/kb/creative-cloud-connection-faq.html

    Kind regards

    Rahul

  • Window Media Center does not see the internet / only to download the guide.

    In the last three months. I was not able to download TV guide. I went through all NET configurations include the configuration of the tv tuner. Also bought new tuner. The computer has a modem of broad band always connectted to the internet. Count works very well on the internet. Media Center not connect and download tv guide to the registration of the advance. If I go to live TV, I see TV channels. It does not show the description of the channel or what's playing on this channel. When I go to the configuration of internet connection guide and test it just sitts there never out error just never connects. Help, please. I have windows Vista 32 bit. Also, did all the windows update and download the latest version of .net Framework.

    Be sure to reconfigure your firewall or internet security to allow WMC download guide. S.Sengupta Media Center MVP

  • System volume information stolen hard drive. VERY slow computer and windows show only (not answer) for 2 to 10 seconds at a time. Help, please.

    After starting my computer to Windows 7 Enterprise, I noticed that it runs very slowly.  for example, the scrolling of a window of firefox crashes every 10 seconds or more.  The gel lasts between 2 and 10 seconds with the little blue wheel, spinning, (not answer) in the toolbar.

    I pulled the top of resource monitor and to see that 4 PID - C:\System Volume Information\ {guid} {guid} is running non-stop with about 720ko read by writing dry and 6 MB per second Disk 0 length of the queue is pegged at 5.  from time to time (once every 10 to 15 minutes), the queue goes to 0 and the computer starts acting normally (i.e. fast) again.  But once the length of the queue points to 5, the problems continue.

    I am running in raid 5.

    I noticed that vssvc.exe is running (PID 4144) with a reference to c:\System Volume Information and the same GUID as PID 4 - system and kernel.

    Any idea what I can do to get back on my computer?  At this point, it is absolutely unusable.

    Thank you

    Marshall

    For any question on Windows 7:

    http://social.answers.Microsoft.com/forums/en-us/category/Windows7

    Link above is Windows 7 Forum for questions on Windows 7.

    Windows 7 questions should be directed to the it.

    You are in the Vista Forums.

    See you soon.

    Mick Murphy - Microsoft partner

  • Whenever I try to connect to my internet I get 'local internet only' and when I try to repair it it says that there may be a problem with your dns server.

    problem with connecting to the internet

    whenever I try to connect to my internet I get 'local internet only' and when I try to repair it it says that there may be a problem with your dns server, I looked for a solution for centuries now, and no one can seem to help me! Please someone help me?

    Hello

    First off I'm going to assume that when you say "local internet only", you really mean "local only". Also, I'll assume you are using a router for internet connection broadband. If I am wrong, then you will have to describe the answer how you try to connect to the internet more in detail.

    First of all, your router. The indicators show that there is an internet connection? Consult the manual, which probably came on a CD with the router. Internet connection led can resemble a planet with rings or a circle with a lower-case i in the middle of it, or some other symbol. It can also have a caption saying 'internet' or 'connected '. If the router is not connected while your PC will not have access to the internet.

    Click the Start button and type "cmd" then press ENTER. In the window type (mainly black) which results in ipconfig and press to enter. Transcribe the results of the command ipconfig for a response.

    Your (wired or wireless) network card is set to automatically get an ip address? Otherwise, set it to do that and also to get information from DNS server automatically...

    • Right-click on the icon network at the bottom right of your screen, and then click Network and sharing Center
    • In network and sharing Center, click on manage the network connections (on the left)
    • Right click on 'Connect to the Local network' or 'Wireless Network Connection' depending on how you connect to the router
    • Click on select Internet Protocol Version 4 (TCP/IPv4), and then click the properties button
    • If things are not set to 'automatic', please note all numbers so that you can restore the settings if necessary
    • Make sure that "Obtain an IP address automatically" and 'DNS server automatically get an address' is selected, then click OK
    • Click on close

    If you are using a wireless connection, what happens if you try to connect to your router with an Ethernet cable?

    Please post back with your comments to the above and give more details about your configuration, i.e. router brand and model (or another material of Internet), if you connect wireless or with an Ethernet cable, etc. etc.

    Tricky

  • I can only access local network with WPA/WPA2-PSK compatible. With out security I can connect without any problems.

    Issue of WPA/WPA2-PSK on Vista with SP2

    Belkin F7D2301 router, version1

    Vista Home Premium, Service Pack 2

    Network card: Atheros AR5007 802. 11a / g WiFi. version of the driver. 7.3.201.25.

    I am running 2-1 Vista, 1 Window7 laptop
    IPhone 2
    1 Wii game system

    When I installed initially the new router today, I installed it with WPA - PSK [TKIP] + security WPA2-PSK [AES] option. When in doing so, the Vista Home Premium (32 bit) would not connect to the internet. He would show local only access.

    But when I disable security it can connect to the internet. Rest of my devices are also able to connect to the internet regardless of WPA - PSK [TKIP] + WPA2-PSK [AES] or security number. I am running Vista with SP2.  That seems known problem Vista on Sp1. see http://support.microsoft.com/kb/935222.

    The network adapter I have is an Atheros AR5007 802. 11a / g WiFi with the version of the driver. 7.3.201.25.

    Any help would be very happy... I'm exhausted now try to solve this problem.

    SOLVED by updating the driver for Atheros. Atheros AR5007 802. 11a / g WiFi. It is not available on the official website. Check out this forum.

    http://forums.techguy.org/networking/981134-solved-NETGEAR-WNDR3700-incompatibilty-w.html

    Mysteryis yet to be sloverd

    • Why stop WPA has collaborated with the old version of Atheros AR5007 802. 11a / g WiFi. version of the driver. 7.3.201.25.
    • Why accpeting Linksys WRNT160 V3 ceased any connection.

    Thanks for the support

  • iOS 10.1 (Notes App) cannot access local notes

    Just upgraded iPhone 6s more iOS 10.1 of the latest version of iOS 9.x.x

    Used Notes app all the time without ever upgrade to iCloud version.

    Notes were always stored locally.

    Never signed in iCloud for Notes app.

    Now after the upgrade to iOS 10.1 I am unable to access my notes.

    Whenever I start the application notes I'm only given the opportunity to UPGRADE NOTES.

    How do I access my local notes?

    Can't update my notes to send to the cloud.

    Never received the memo that I loose the access to my notes after upgrading to iOS 10.1 without upgrade to iCloud.

    To the best of my knowledge, the upgrade does not require that you store your notes to iCloud. It updates of features such as the ability to add documents, photos, etc. As long as you turned off in the settings of Notes > iCloud, they should continue to be stored locally.

  • Mission Control only accesses the desktop. What happened to the rest?

    Mission Control only accesses the desktop. What happened to the rest?

    What happened to the others?  What you are looking for that you do not find?  If you want to help, give us more to go than that!

  • Internet ex 8 is not takeing a upgrade, 8024200d error code

    Internet ex 8 takeing not an upgrade; IE 8 is on and works but will not take it is a high grade? Why? the 8024200d error code

    Hi jamesfhoagland,

    Thank you for using answers Forum.

    You know that day is it?
    Their generally referenced by a KB as KB947562 article.
    If you can find the update, you can try to download the Setup file and install it manually.

    You can also run the Installer Cleanup utility.
    Here's an article on it:

    http://support.Microsoft.com/kb/290301

    Give that a try and let us know how it works.

    Chris
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Error number: Ox800CCC92 using Outlook Express 6.0 for email. Password continues to be rejected. Can get in emails via the web access but not my office.

    I am trying to log into my cox on Outlook Express 6.0 e-mail account.  I keep getting rejected for an invalid password.  The same password works if I pass by internet at webmail.cox.com.  I can send and receive e-mail from there.  I tried to speak with Cox and Microsoft without success.  The full error message is:

    There was a problem connecting to your e-mail server.  Your password was rejected.  Account: 'pop.cox.net', server 'pop.cox.net', Protocol: POP3, server response: '-ERR user name or password.': Port: 110, secure (SSL): no, Server error: Ox800CCC90, error number: Ox800CCC92

    Try to use port 995 for the outgoing and 465 for incoming as shown here.

    Names of Cox for POP and SMTP mail server
    http://WW2.Cox.com/residential/Sandiego/support/Internet/article.Cox?articleid=%7Ba8fb24c0-6440-11df-CCEF-000000000000%7d

    A moderator will soon be along to move this thread to the appropriate forum such as this one is for the feedback: site forum only. Please note the forum, proposed future questions about this program or feature.

Maybe you are looking for

  • Type 'L' and 't' of MagSafe adapter

    Good evening I am a very happy owner of a MacBook Pro 15 inch medio 2009. Yes still work after 7 years. At least it's better that the MacBook Pro from my little brother of 2011 that fell down right after the warranty expired and my iMac 27 inches whi

  • all my thunderbird folders disappeared: is there a way to recover them?

    I opened my firefox thunderbird email this am. I have three different accounts. Two of them were very good. The third party who is the most important of them (i.e. with most of my files) was empty except for the Inbox, sent, trash, junk, and drafts.

  • Lollipop for Yoga compressed 2 Pro when?

    I read that the Loli is out for the Yoga 2, but not the Pro aparently. I had updates. Is there a release date? EDIT 22/07/15: online edition of object for research opportunities. Amy_Lenovo

  • Free security software

    Now listen here objectors, I bought the year last for 14.99 for device sharing two, this year it's up to 49.00. no way I'm paying this dough a little! Anyone know good security software that can be downloaded/hacked on the web? Or you could send me s

  • Need help from Microsoft but request to pay that does not accept the product key

    I have a Dell computer that I bought from Currys, about 15 months ago and I have terrible problems with Vista crashing. I want to ask a question to Microsoft, but the system does not accept my product key so I want to charge me £46 for a question. Ho