Zalion,
Here is the output of some show commands that might help:
(wlan01.cedardoc.com) #show rights
RoleTable
---------
Name ACL Bandwidth ACL List Type
---- --- --------- -------- ----
CDTGreen_Role 84 Up: No Limit,Dn: No Limit global-sacl/,apprf-CDTGreen_Role-sacl/,CDTGreen_Policy/ User
(wlan01.cedardoc.com) # show ip access-list br
Access list table (4 - IPv4, 6 - IPv6)
--------------------------------------
Name Type Use Count Roles
---- ---- --------- -----
CDTGreen_Policy session(4) 1 CDTGreen_Role
ip access-list session CDTGreen_Policy
CDTGreen_Policy
---------------
Priority Source Destination Service Application Action TimeRange Log Expired Queue TOS 8021P Blacklist Mirror DisScan ClassifyMedia IPv4/6 Contract
-------- ------ ----------- ------- ----------- ------ --------- --- ------- ----- --- ----- --------- ------ ------- ------------- ------ --------
1 any any svc-dhcp permit Low 4
2 any any tcp 443 permit Low 4
3 any any tcp 80 permit Low 4
4 any any udp 53 permit Low 4
wlan virtual-ap "CDTGreen"
aaa-profile "CDTGreen_AAA"
ssid-profile "CDTGreen_SSID"
no vap-enable
vlan 1109
deny-inter-user-traffic
aaa profile "CDTGreen_AAA"
initial-role "CDTGreen_Role"
authentication-dot1x "dot1x_prof-ckz60"
user-role CDTGreen_Role
captive-portal "default"
access-list session global-sacl
access-list session apprf-CDTGreen_Role-sacl
access-list session CDTGreen_Policy