QuestionQ48

Security

Your customer requested help applying an ACL for wireless guest users with the following criteria:

  • Wi-Fi guests are on VLAN 555.
  • Allow Internet access.
  • Allow access only to public DNS servers.
  • Deny access to all internal networks except any DHCP server.

These session ACLs are already present in the CLI of the mobility gateway group:

Question Image

You have CLI access. Which user role meets all the criteria?

Explanation

The DHCP permit must appear before the private-network deny so DHCP remains reachable when its server is internal. The private-network deny must appear before the DNS permit so DNS traffic to 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 is blocked; the later DNS permit therefore applies only to public destinations. A final allow-all rule permits the remaining Internet traffic, and VLAN 555 assigns the guest VLAN.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!