Switches, Hubs, and Modems
1753767 Members
5286 Online
108799 Solutions
New Discussion юеВ

Re: HP MSM series user-based access lists

 
groque
Frequent Advisor

HP MSM series user-based access lists

Hi all,

Has anybody configured user-based access-lists on your MSM controllers/AP's?

I configured an ACL policy on my Radius -> Attribute pages

access-list=testing,DENY,all,10.100.1.1,all
access-list=testing,ACCEPT,all,all,all

I want to apply this ACL to my IT users via Radius. So on my Radius Access Profile for IT users I specified a VSA 8744 attribute 0 with this string

use-access-list=testing

I logged in with an account that is associated to the IT remote access policy and I am still able to ping 10.100.1.1

Any ideas on how to apply this it seems as if the ACL's isn't even working when it should.

I am using an MSM313-WW this is my system version
5.2.4.0-01-6771

Thanks for the replies
4 REPLIES 4
cenk sasmaztin
Honored Contributor

Re: HP MSM series user-based access lists

hi
what is default gateway address your wireless user ?

MSM controller or another gateway address

if your wireless user have another gatway address please test change default gateway address with MSM lan port and test

please say me result
cenk

groque
Frequent Advisor

Re: HP MSM series user-based access lists

Hi Cenk,

Thanks for replying HP support helped me figure it out and the problem is that I don't have access control setup on my AP.

My corporate SSID gets routed through my switch, my switch acts as the default gateway not the AP, therefore the ACL's don't work.

cenk sasmaztin
Honored Contributor

Re: HP MSM series user-based access lists

sorry I was wrong

I make test recently this config
with MSM controller worked properly

but don't test single access point

cenk

groque
Frequent Advisor

Re: HP MSM series user-based access lists

Hi did you configure your VSC with access control or non access control?