<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create SSID only LAN in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89698#M8437</link>
    <description>In that case, you'll need to create an IP ACL with the appropriate rules and then apply the ACL to the WLAN's inbound firewall. &lt;BR /&gt;
You'll need to allow things like DHCP server traffic, DNS, DGW, and whatever else might be needed, but then disallow all other traffic (which will prevent the user from accessing anything else on that LAN.</description>
    <pubDate>Sun, 28 Jul 2019 02:16:02 GMT</pubDate>
    <dc:creator>ckelly</dc:creator>
    <dc:date>2019-07-28T02:16:02Z</dc:date>
    <item>
      <title>How to create SSID only LAN</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89695#M8434</link>
      <description>Hi you&lt;BR /&gt;
&lt;BR /&gt;
I used Controller RFS 4000. How to create SSID only LAN, not connect to internet.&lt;BR /&gt;
&lt;BR /&gt;
Thank you</description>
      <pubDate>Fri, 26 Jul 2019 17:23:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89695#M8434</guid>
      <dc:creator>Tuan_Nguyen1</dc:creator>
      <dc:date>2019-07-26T17:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to create SSID only LAN</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89696#M8435</link>
      <description>Try supplying no default gateway or a non-existent default gateway in the DHCP lease?</description>
      <pubDate>Fri, 26 Jul 2019 18:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89696#M8435</guid>
      <dc:creator>ckelly</dc:creator>
      <dc:date>2019-07-26T18:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to create SSID only LAN</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89697#M8436</link>
      <description>&lt;BR /&gt;
&lt;BR /&gt;
Hi you&lt;BR /&gt;
&lt;BR /&gt;
If no default gateway, I pinged AP time out.</description>
      <pubDate>Sat, 27 Jul 2019 10:45:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89697#M8436</guid>
      <dc:creator>Tuan_Nguyen1</dc:creator>
      <dc:date>2019-07-27T10:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to create SSID only LAN</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89698#M8437</link>
      <description>In that case, you'll need to create an IP ACL with the appropriate rules and then apply the ACL to the WLAN's inbound firewall. &lt;BR /&gt;
You'll need to allow things like DHCP server traffic, DNS, DGW, and whatever else might be needed, but then disallow all other traffic (which will prevent the user from accessing anything else on that LAN.</description>
      <pubDate>Sun, 28 Jul 2019 02:16:02 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89698#M8437</guid>
      <dc:creator>ckelly</dc:creator>
      <dc:date>2019-07-28T02:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to create SSID only LAN</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89699#M8438</link>
      <description>Hello Chris,&lt;BR /&gt;
&lt;BR /&gt;
Just created the rule:&lt;BR /&gt;
 permit ip x.x.x.x/24 x.x.x.x/24 rule-precedence 1 &lt;BR /&gt;
 deny ip any any rule-precedence 100 &lt;BR /&gt;
&lt;BR /&gt;
and applied to IN wlan and filtering is working well, but I have something like roaming issues now.&lt;BR /&gt;
DHCP server is inside the subnet, don't need DNS.&lt;BR /&gt;
&lt;BR /&gt;
I need to allow something else?&lt;BR /&gt;
&lt;BR /&gt;
Thanks</description>
      <pubDate>Mon, 29 Jul 2019 00:48:15 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89699#M8438</guid>
      <dc:creator>Aviv_Kedem</dc:creator>
      <dc:date>2019-07-29T00:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to create SSID only LAN</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89700#M8439</link>
      <description>What are you seeing that looks like a roaming issue?</description>
      <pubDate>Mon, 29 Jul 2019 21:36:43 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89700#M8439</guid>
      <dc:creator>ckelly</dc:creator>
      <dc:date>2019-07-29T21:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to create SSID only LAN</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89701#M8440</link>
      <description>Hello Chris, &lt;BR /&gt;
&lt;BR /&gt;
After applying this policy when mu is roamed to other ap, there is no ip connection with the client.&lt;BR /&gt;
Seems the ethernet side is not synchronized.&lt;BR /&gt;
Any ideas? &lt;BR /&gt;
&lt;BR /&gt;
Thanks &lt;BR /&gt;
Aviv</description>
      <pubDate>Tue, 30 Jul 2019 00:18:35 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89701#M8440</guid>
      <dc:creator>Aviv_Kedem</dc:creator>
      <dc:date>2019-07-30T00:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to create SSID only LAN</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89702#M8441</link>
      <description>So saying that after the client roams, the client loses it's IP address?&lt;BR /&gt;
By chance, in the WLAN profile, do you have the option "Enforce DHCP Client Only" enabled? (It's under the WLAN Profile Client Settings section in the GUI)</description>
      <pubDate>Tue, 30 Jul 2019 04:50:29 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89702#M8441</guid>
      <dc:creator>ckelly</dc:creator>
      <dc:date>2019-07-30T04:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to create SSID only LAN</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89703#M8442</link>
      <description>Hello Chris,&lt;BR /&gt;
&lt;BR /&gt;
After roaming MUs are stay with the IPs, but I can't ping them, until the mu is coming back to the previous AP OR disconnecting+connecting to any AP.&lt;BR /&gt;
&lt;BR /&gt;
Seems ARPs/MACs are not synced when MUs roamed.&lt;BR /&gt;
&lt;BR /&gt;
ip access-list 111&lt;BR /&gt;
 permit ip x.x.x.x/24 x.x.x.x/24 rule-precedence 1&lt;BR /&gt;
 deny ip any any rule-precedence 100&lt;BR /&gt;
&lt;BR /&gt;
wlan xxx&lt;BR /&gt;
 ssid xxx&lt;BR /&gt;
 bridging-mode local&lt;BR /&gt;
 encryption-type ccmp&lt;BR /&gt;
 wpa-wpa2 psk 0 xxxxxxxx&lt;BR /&gt;
 use ip-access-list in 111&lt;BR /&gt;
 use ip-access-list out BROADCAST-MULTICAST-CONTROL&lt;BR /&gt;
 use mac-access-list out PERMIT-ARP-AND-IPv4&lt;BR /&gt;
&lt;BR /&gt;
 profile ap7532 test-ap7532&lt;BR /&gt;
 no mint mlcp vlan&lt;BR /&gt;
 ip default-gateway x.x.x.x&lt;BR /&gt;
 interface radio1&lt;BR /&gt;
 wlan xxx bss 1 primary&lt;BR /&gt;
 interface radio2&lt;BR /&gt;
 interface ge1&lt;BR /&gt;
 interface vlan1&lt;BR /&gt;
 ip address dhcp&lt;BR /&gt;
 ip address zeroconf secondary&lt;BR /&gt;
 logging on&lt;BR /&gt;
 controller host x.x.x.x pool 1 level 1&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
&lt;BR /&gt;
Aviv</description>
      <pubDate>Tue, 30 Jul 2019 14:51:08 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89703#M8442</guid>
      <dc:creator>Aviv_Kedem</dc:creator>
      <dc:date>2019-07-30T14:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to create SSID only LAN</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89704#M8443</link>
      <description>Okay, totally different issue then.  Client roams to another AP and maintains an IP address (Assuming that you are somehow verifying that the client still has an IP address - Is it the SAME IP address?).  And if the client roams back to original AP, the PING replies resume.  Interesting.&lt;BR /&gt;
&lt;BR /&gt;
So after the roam, client no longer responds to PING requests at a known IP address....or what you believe to be its IP address.&lt;BR /&gt;
&lt;BR /&gt;
Log into the AP that the client roams to (and the client is no longer PING'able) and from the CLI run:&lt;BR /&gt;
#&lt;B&gt;show wireless client&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
Do you see the client listed?&lt;BR /&gt;
You should...and you should see the device MAC and an IP address.&lt;BR /&gt;
Is the IP address what you expect it to be?&lt;BR /&gt;
If so, try running another PING against it while running the command on the CLI:&lt;BR /&gt;
&lt;BR /&gt;
#&lt;B&gt;service pktcap on bridge filter icmp&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
The AP should be proxy ARP'ing for the client.  But, if the AP isn't showing the client and the WLAN's Proxy ARP mode is set to strict, then I guess that's a scenario when there might not be a reply.</description>
      <pubDate>Tue, 30 Jul 2019 22:28:49 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/how-to-create-ssid-only-lan/m-p/89704#M8443</guid>
      <dc:creator>ckelly</dc:creator>
      <dc:date>2019-07-30T22:28:49Z</dc:date>
    </item>
  </channel>
</rss>

