<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic dACL dont apply in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dacl-dont-apply/m-p/2268405#M111480</link>
    <description>&lt;P&gt;For some user create dACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only_default_router&lt;/P&gt;&lt;P&gt;permit icmp any host 192.168.100.1&lt;/P&gt;&lt;P&gt;permit tcp any host 192.168.100.1&lt;/P&gt;&lt;P&gt;deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After user log in windows i found logs on switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;001867: *Mar 16 22:03:58.196: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:ip access-list extended xACSACLx-IP-only_default_router-51ded09c&lt;/P&gt;&lt;P&gt;001868: *Mar 16 22:03:58.204: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:permit icmp any host 192.168.100.1&lt;/P&gt;&lt;P&gt;001869: *Mar 16 22:03:58.221: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:ip access-list extended xACSACLx-IP-only_default_router-51ded09c&lt;/P&gt;&lt;P&gt;001870: *Mar 16 22:03:58.229: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:permit tcp any host 192.168.100.1&lt;/P&gt;&lt;P&gt;001871: *Mar 16 22:03:58.254: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:ip access-list extended xACSACLx-IP-only_default_router-51ded09c&lt;/P&gt;&lt;P&gt;001872: *Mar 16 22:03:58.254: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:deny ip any any&lt;/P&gt;&lt;P&gt;001873: *Mar 16 22:03:58.405: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (000c.29d6.02a6) on Interface Gi1/0/2 AuditSessionID C0A8641E00000034511FC4B0&lt;/P&gt;&lt;P&gt;001874: *Mar 16 22:03:58.422: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/2, changed state to up&lt;/P&gt;&lt;P&gt;001875: *Mar 16 22:03:59.429: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/2, changed state to up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But on interface apply &lt;SPAN style="font-size: 10pt;"&gt;Auth-Default-ACL and what is why all traffic block.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;And on interface I found&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE-SWITCH#show ip interface gigabitEthernet 1/0/2&lt;/P&gt;&lt;P&gt;GigabitEthernet1/0/2 is up, line protocol is up&lt;/P&gt;&lt;P&gt;&amp;nbsp; Inbound&amp;nbsp; access list is Auth-Default-ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why my dACL not apply?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:38:25 GMT</pubDate>
    <dc:creator>Alexey Leontiev</dc:creator>
    <dc:date>2019-03-11T03:38:25Z</dc:date>
    <item>
      <title>dACL dont apply</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-dont-apply/m-p/2268405#M111480</link>
      <description>&lt;P&gt;For some user create dACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only_default_router&lt;/P&gt;&lt;P&gt;permit icmp any host 192.168.100.1&lt;/P&gt;&lt;P&gt;permit tcp any host 192.168.100.1&lt;/P&gt;&lt;P&gt;deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After user log in windows i found logs on switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;001867: *Mar 16 22:03:58.196: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:ip access-list extended xACSACLx-IP-only_default_router-51ded09c&lt;/P&gt;&lt;P&gt;001868: *Mar 16 22:03:58.204: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:permit icmp any host 192.168.100.1&lt;/P&gt;&lt;P&gt;001869: *Mar 16 22:03:58.221: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:ip access-list extended xACSACLx-IP-only_default_router-51ded09c&lt;/P&gt;&lt;P&gt;001870: *Mar 16 22:03:58.229: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:permit tcp any host 192.168.100.1&lt;/P&gt;&lt;P&gt;001871: *Mar 16 22:03:58.254: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:ip access-list extended xACSACLx-IP-only_default_router-51ded09c&lt;/P&gt;&lt;P&gt;001872: *Mar 16 22:03:58.254: %PARSER-5-CFGLOG_LOGGEDCMD: User:console&amp;nbsp; logged command:deny ip any any&lt;/P&gt;&lt;P&gt;001873: *Mar 16 22:03:58.405: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (000c.29d6.02a6) on Interface Gi1/0/2 AuditSessionID C0A8641E00000034511FC4B0&lt;/P&gt;&lt;P&gt;001874: *Mar 16 22:03:58.422: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/2, changed state to up&lt;/P&gt;&lt;P&gt;001875: *Mar 16 22:03:59.429: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/2, changed state to up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But on interface apply &lt;SPAN style="font-size: 10pt;"&gt;Auth-Default-ACL and what is why all traffic block.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;And on interface I found&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE-SWITCH#show ip interface gigabitEthernet 1/0/2&lt;/P&gt;&lt;P&gt;GigabitEthernet1/0/2 is up, line protocol is up&lt;/P&gt;&lt;P&gt;&amp;nbsp; Inbound&amp;nbsp; access list is Auth-Default-ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why my dACL not apply?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-dont-apply/m-p/2268405#M111480</guid>
      <dc:creator>Alexey Leontiev</dc:creator>
      <dc:date>2019-03-11T03:38:25Z</dc:date>
    </item>
    <item>
      <title>Re:dACL dont apply</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-dont-apply/m-p/2268406#M111535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a loom at the show authentication session interface gig xxx, that will show you the acl applied after the authentication.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Jul 2013 05:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-dont-apply/m-p/2268406#M111535</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-07-13T05:47:33Z</dc:date>
    </item>
    <item>
      <title>Re:dACL dont apply</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-dont-apply/m-p/2268407#M111567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you post the output of the following commands after authorization:&lt;/P&gt;&lt;P&gt;show authentication session interface &lt;INTERFACE_NAME&gt;&lt;/INTERFACE_NAME&gt;&lt;/P&gt;&lt;P&gt;sh ip access-lists interface &lt;INTERFACE_NAME&gt;&lt;/INTERFACE_NAME&gt;&lt;/P&gt;&lt;P&gt;show running-config interface &lt;INT_NAME&gt;&lt;/INT_NAME&gt;&lt;/P&gt;&lt;P&gt;show access-list &lt;INT_NAME&gt;&lt;/INT_NAME&gt;&lt;/P&gt;&lt;P&gt;sh ip access-lists&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jul 2013 05:20:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-dont-apply/m-p/2268407#M111567</guid>
      <dc:creator>mmangat</dc:creator>
      <dc:date>2013-07-15T05:20:18Z</dc:date>
    </item>
    <item>
      <title>Re:dACL dont apply</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-dont-apply/m-p/2268408#M111633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alexey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;check if the IOS version and hardware platform (switch) you're using is mentioned in TrustSec document (page 6):&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/TrustSec_2.0/trustsec_2.0_dig.pdf" target="_blank"&gt;http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/TrustSec_2.0/trustsec_2.0_dig.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; had the same problem and it turned out that I had to upgrade the&amp;nbsp; switch, because the IOS version I used wasn't fully supported. The&amp;nbsp; minimum IOS version to use with ISE should be 12.2(55), but generally&amp;nbsp; it's better to use 15.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also,&amp;nbsp; check if you have configured everything that is recommended for switch&amp;nbsp; devices in TrustSec (page 59), including "ip device tracking".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's also a very nice document for troubleshooting:&lt;/P&gt;&lt;P&gt;"Cisco TrustSec How-To Guide: Failed Authentications and Authorizations"&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns744/docs/howto_81_troubleshooting_failed_authc.pdf" target="_blank"&gt;http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns744/docs/howto_81_troubleshooting_failed_authc.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 03:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-dont-apply/m-p/2268408#M111633</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-08-06T03:12:55Z</dc:date>
    </item>
  </channel>
</rss>

