<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and dAcl in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-dacl/m-p/2265242#M136206</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Renato,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked the latest user guide and you're correct it's not documented. DACL should not be more than 64 ACE's. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://preview.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_authz_polprfls.html#wp1219887"&gt;http://preview.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_authz_polprfls.html#wp1219887&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The below link says that the maximum limit on per-user ACL is 4000 ASCII characters.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/12.2_55_se/configuration/guide/sw8021x.html#wp1264996"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/12.2_55_se/configuration/guide/sw8021x.html#wp1264996&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like there is a DOC defect filed on this as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCud44176" target="_blank"&gt;CSCud44176&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; DOC: Add Any key word must be the source in all DACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "Any" key word must be the source in all DACL.&amp;nbsp; This is not a limitation of ISE, but of the IOS. This is documented in the config guide of the IOS&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/12.2_55_se/configuration/guide/sw8021x.html#wp1264996"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/12.2_55_se/configuration/guide/sw8021x.html#wp1264996&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible can we add this note to the ISE User Guide in the DACL section.The length of the DACL is limited, but is not documented well.&amp;nbsp; There is an internal (to Cisco) document that says the DACL's are limited to 64 lines, but does not speak to the limitation of 4000 char.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 May 2013 16:14:23 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-05-28T16:14:23Z</dc:date>
    <item>
      <title>ISE and dAcl</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-dacl/m-p/2265241#M136105</link>
      <description>&lt;P&gt;hi guys, i'd to know if there is a real limitation in the number of lines that can be written in dAcl, in official documentation i couldn't&amp;nbsp; find any info about that&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-dacl/m-p/2265241#M136105</guid>
      <dc:creator>renato.efrati</dc:creator>
      <dc:date>2019-03-11T03:28:25Z</dc:date>
    </item>
    <item>
      <title>ISE and dAcl</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-dacl/m-p/2265242#M136206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Renato,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked the latest user guide and you're correct it's not documented. DACL should not be more than 64 ACE's. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://preview.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_authz_polprfls.html#wp1219887"&gt;http://preview.cisco.com/en/US/docs/security/ise/1.2/user_guide/ise_authz_polprfls.html#wp1219887&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The below link says that the maximum limit on per-user ACL is 4000 ASCII characters.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/12.2_55_se/configuration/guide/sw8021x.html#wp1264996"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/12.2_55_se/configuration/guide/sw8021x.html#wp1264996&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like there is a DOC defect filed on this as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCud44176" target="_blank"&gt;CSCud44176&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; DOC: Add Any key word must be the source in all DACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "Any" key word must be the source in all DACL.&amp;nbsp; This is not a limitation of ISE, but of the IOS. This is documented in the config guide of the IOS&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/12.2_55_se/configuration/guide/sw8021x.html#wp1264996"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst3750x_3560x/software/release/12.2_55_se/configuration/guide/sw8021x.html#wp1264996&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible can we add this note to the ISE User Guide in the DACL section.The length of the DACL is limited, but is not documented well.&amp;nbsp; There is an internal (to Cisco) document that says the DACL's are limited to 64 lines, but does not speak to the limitation of 4000 char.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 16:14:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-dacl/m-p/2265242#M136206</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-28T16:14:23Z</dc:date>
    </item>
    <item>
      <title>ISE and dAcl</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-dacl/m-p/2265243#M136252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The limitation comes from the fact that the dACL has to be delivered in a single RADIUS Accounting Packet and these packets have a 4096 byte limit, which equates to just under 4000 characters by the time you account for the 52-bytes of headers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/dot1x.html#wp1133397"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/dot1x.html#wp1133397&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.ietf.org/html/rfc2866"&gt;http://tools.ietf.org/html/rfc2866&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 20:22:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-dacl/m-p/2265243#M136252</guid>
      <dc:creator>Richard Atkin</dc:creator>
      <dc:date>2013-05-28T20:22:32Z</dc:date>
    </item>
  </channel>
</rss>

