diff --git a/configs/wlc/wlc-b.cfg b/configs/wlc/wlc-b.cfg index de0930b..94b6ba6 100644 --- a/configs/wlc/wlc-b.cfg +++ b/configs/wlc/wlc-b.cfg @@ -461,9 +461,6 @@ ip access-list session deny_internal_byod any network 192.168.0.0 255.255.0.0 any deny any any any permit ! -ip access-list session guest - host 10.48.120.112 any any permit -! ip access-list session captiveportalbridge user alias localip svc-https dual-nat pool localip 8081 user any svc-http dual-nat pool localip 8080 @@ -502,6 +499,9 @@ ip access-list session apprf-student_byod-sacl ! ip access-list session apprf-staff_scsd-sacl ! +ip access-list session guest + host 10.48.120.112 any any permit +! ip access-list session apprf-scsd_test_role-sacl ! ip access-list session noe-acl @@ -1712,6 +1712,17 @@ crypto dynamic-map default-dynamicmap 10000 crypto map GLOBAL-IKEV2-MAP 10000 ipsec-isakmp dynamic default-rap-ipsecmap crypto map GLOBAL-MAP 10000 ipsec-isakmp dynamic default-dynamicmap +crypto-local ipsec-map default-ha-ipsecmap10.1.35.14 9999 + version v2 + set ikev2-policy 10015 + peer-ip 10.1.35.14 + src-net 10.1.35.12 255.255.255.255 + dst-net 10.1.35.14 255.255.255.255 + set transform-set "default-ha-transform" + factory-cert-auth + trusted +! + crypto-local ipsec-map default-ha-ipsecmap10.1.35.11 9999 version v2 set ikev2-policy 10015 @@ -1724,17 +1735,6 @@ crypto-local ipsec-map default-ha-ipsecmap10.1.35.11 9999 trusted ! -crypto-local ipsec-map default-ha-ipsecmap10.1.35.14 9999 - version v2 - set ikev2-policy 10015 - peer-ip 10.1.35.14 - src-net 10.1.35.12 255.255.255.255 - dst-net 10.1.35.14 255.255.255.255 - set transform-set "default-ha-transform" - factory-cert-auth - trusted -! - crypto isakmp eap-passthrough eap-tls crypto isakmp eap-passthrough eap-peap crypto isakmp eap-passthrough eap-mschapv2