<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Good 2960S code for ISE?? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314822#M130059</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep us posted.&amp;nbsp; I'm keen to know what you'll find.&amp;nbsp; &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 26 Oct 2013 00:04:36 GMT</pubDate>
    <dc:creator>Leo Laohoo</dc:creator>
    <dc:date>2013-10-26T00:04:36Z</dc:date>
    <item>
      <title>Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314813#M129798</link>
      <description>&lt;P&gt;There is a bug (CSCug08069) that I'm hitting that prevents the dACL in the ISE authz profile from overriding the default ACL applied as a pACL on the switch. This is destroying my move from monitor mode to low-impact mode, and I'm wondering if anyone has used and can recommend some good 2960S 15.x code that has worked with their radius server dACL in the past. Any insight would be very helpful. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards, &lt;BR /&gt; &lt;BR /&gt;Kevin &lt;BR /&gt; &lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:00:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314813#M129798</guid>
      <dc:creator>Kevin P Sheahan</dc:creator>
      <dc:date>2019-03-11T04:00:53Z</dc:date>
    </item>
    <item>
      <title>Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314814#M129801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This error code is related to AAA functionality, I will suggest to contact SAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 22:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314814#M129801</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2013-10-25T22:42:52Z</dc:date>
    </item>
    <item>
      <title>Re:Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314815#M129806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for replying. Can you please elaborate on what your knowledge and experience is with this bug. Also, what is SAC?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 22:48:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314815#M129806</guid>
      <dc:creator>Kevin P Sheahan</dc:creator>
      <dc:date>2013-10-25T22:48:13Z</dc:date>
    </item>
    <item>
      <title>Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314816#M129811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What exact IOS are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 22:54:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314816#M129811</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2013-10-25T22:54:32Z</dc:date>
    </item>
    <item>
      <title>Re:Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314817#M129825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've tried both 15.0(2)SE2, and SE4&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 22:58:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314817#M129825</guid>
      <dc:creator>Kevin P Sheahan</dc:creator>
      <dc:date>2013-10-25T22:58:41Z</dc:date>
    </item>
    <item>
      <title>Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314818#M129841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;I've tried both 15.0(2)SE2, and SE4&lt;/PRE&gt;&lt;P&gt;That's disturbing. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Disturbing because the next IOS is 15.1(2)S and I haven't tested this version yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 23:37:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314818#M129841</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2013-10-25T23:37:35Z</dc:date>
    </item>
    <item>
      <title>Re:Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314819#M129853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just got a 2960S for my lab today so I'm gonna test it this weekend. Hope I don't have to drop to 12 code just to make it work. This is one of the most irritating bugs I've encountered recently because everything will work beautifully for a while and then suddenly user complaints cause me to look at the switch and the default ACL is blocking random flows even though the dACL is applied. It's back in monitor mode until I can find code that works.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 23:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314819#M129853</guid>
      <dc:creator>Kevin P Sheahan</dc:creator>
      <dc:date>2013-10-25T23:46:06Z</dc:date>
    </item>
    <item>
      <title>Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314820#M129894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you ever need to go down to 12.X then I highly recommend 12.2(55)SE8.&amp;nbsp; Don't even bother with the rest. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 23:59:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314820#M129894</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2013-10-25T23:59:44Z</dc:date>
    </item>
    <item>
      <title>Re:Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314821#M129975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for that recommendation it will save me quite a bit of time and effort if I do have to downgrade to 12. I'll update the discussion with results.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Oct 2013 00:03:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314821#M129975</guid>
      <dc:creator>Kevin P Sheahan</dc:creator>
      <dc:date>2013-10-26T00:03:05Z</dc:date>
    </item>
    <item>
      <title>Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314822#M130059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep us posted.&amp;nbsp; I'm keen to know what you'll find.&amp;nbsp; &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Oct 2013 00:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314822#M130059</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2013-10-26T00:04:36Z</dc:date>
    </item>
    <item>
      <title>Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314823#M130092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not running into this issue, but I wanted to see if moving your users from static ips over to the dhcp reservations would be out of the equation? I have a feeling that the 12.2(58) will fix this issue either as my experience with any ip device tracking with static ip addressing has been to move away from static ips...I know this doesnt help but didnt want you to hit this same issue after downgrading to 12.2(58) since that can take some time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Oct 2013 07:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314823#M130092</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-10-27T07:15:43Z</dc:date>
    </item>
    <item>
      <title>Re:Good 2960S code for ISE??</title>
      <link>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314824#M130132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well this is getting frustrating. dACLs are applying to the session appropriately, even with static IPs, as the first 'any' in the ACE is replaced by the host's ip address. Even with the 12.2(55)SE8 code, I'm seeing the pACL (default ACL) is still blocking very small amounts and random sets of traffic from a successfully authenticated/authorized host. I have to be out on another project tomorrow but Wednesday I will be opening a TAC case for this. I've configured this function many times I cannot imagine that it's anything but a bug but we'll see. Hard to see it as a bug if I've tried all available 15.x code releases as well as this 12.2(55)SE8 with the same results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any new ideas are appreciated, some notes are below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ip device tracking is enabled, as well as with the use svi probe option.&lt;/LI&gt;&lt;LI&gt;'show ip access-list interface g1/0/x' shows that the first 'any' in the dACL is being properly replaced by the host's ip address.&lt;/LI&gt;&lt;LI&gt;90% of the time, everything works wonderfully. Randomly, the default ACL applied to the switchport for unauthenticated sessions starts blocking legitimate traffic even though the dACL is applied. I've seen IGMP, CAPWAP, HTTP, HTTPS, and other ports that are not permitted by default being blocked randomly after a dACL is applied. This condition will typically resolve itself within minutes, only to be seen again on a completely different random switch/port/session/host later on in the day.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards, &lt;BR /&gt; &lt;BR /&gt;Kevin Sheahan, CCIE # 41349 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 02:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/good-2960s-code-for-ise/m-p/2314824#M130132</guid>
      <dc:creator>Kevin P Sheahan</dc:creator>
      <dc:date>2013-12-03T02:55:37Z</dc:date>
    </item>
  </channel>
</rss>

