wlc/wlc-b.cfg Thu Sep 25 10:34:16 PM EDT 2025

This commit is contained in:
John Poland 2025-09-25 22:34:17 -04:00
parent 67bf054324
commit 1646b917b2

View File

@ -461,9 +461,6 @@ ip access-list session deny_internal_byod
any network 192.168.0.0 255.255.0.0 any deny
any any any permit
!
ip access-list session guest
host 10.48.120.112 any any permit
!
ip access-list session captiveportalbridge
user alias localip svc-https dual-nat pool localip 8081
user any svc-http dual-nat pool localip 8080
@ -502,6 +499,9 @@ ip access-list session apprf-student_byod-sacl
!
ip access-list session apprf-staff_scsd-sacl
!
ip access-list session guest
host 10.48.120.112 any any permit
!
ip access-list session apprf-scsd_test_role-sacl
!
ip access-list session noe-acl
@ -1712,6 +1712,17 @@ crypto dynamic-map default-dynamicmap 10000
crypto map GLOBAL-IKEV2-MAP 10000 ipsec-isakmp dynamic default-rap-ipsecmap
crypto map GLOBAL-MAP 10000 ipsec-isakmp dynamic default-dynamicmap
crypto-local ipsec-map default-ha-ipsecmap10.1.35.14 9999
version v2
set ikev2-policy 10015
peer-ip 10.1.35.14
src-net 10.1.35.12 255.255.255.255
dst-net 10.1.35.14 255.255.255.255
set transform-set "default-ha-transform"
factory-cert-auth
trusted
!
crypto-local ipsec-map default-ha-ipsecmap10.1.35.11 9999
version v2
set ikev2-policy 10015
@ -1724,17 +1735,6 @@ crypto-local ipsec-map default-ha-ipsecmap10.1.35.11 9999
trusted
!
crypto-local ipsec-map default-ha-ipsecmap10.1.35.14 9999
version v2
set ikev2-policy 10015
peer-ip 10.1.35.14
src-net 10.1.35.12 255.255.255.255
dst-net 10.1.35.14 255.255.255.255
set transform-set "default-ha-transform"
factory-cert-auth
trusted
!
crypto isakmp eap-passthrough eap-tls
crypto isakmp eap-passthrough eap-peap
crypto isakmp eap-passthrough eap-mschapv2