<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I have same issue now, where in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971957#M175426</link>
    <description>&lt;P&gt;I have same issue now, where exactly was the issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;</description>
    <pubDate>Sun, 09 Jul 2017 09:31:12 GMT</pubDate>
    <dc:creator>Sherief Ahmed</dc:creator>
    <dc:date>2017-07-09T09:31:12Z</dc:date>
    <item>
      <title>dACL Download Fail</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971952#M175421</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im trying to configure Posture Remediation, however I'm not getting the redirect URL when the user is not compliant. Instead I get a "Windows Cannot Connect you to the network" after I authenticate if I have the supplicant enabled on my Windows Test Machine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also see the follwing events on the debug radius &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun 24 20:35:43.762: %EPM-6-AAA: POLICY xACSACLx-IP-POSTURE_REMEDIATION-4fe0538d| EVENT DOWNLOAD-FAIL&lt;/P&gt;&lt;P&gt;Jun 24 20:35:43.762: %EPM-4-POLICY_APP_FAILURE: IP 0.0.0.0| MAC c80a.a96e.367c| AuditSessionID AC101065000000CA9F843C74| AUTHTYPE DOT1X| POLICY_TYPE dACL| POLICY_NAME xACSACLx-IP-POSTURE_REMEDIATION-4fe0538d| RESULT FAILURE| REASON AAA download failure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I have the supplicant disabled I dont get any error messages on the PC (and I can browse just just which I think I shouldnt be able to) but I get similar debugs on the switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Relevant Switch Config: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RFNET-R1-P-SW1#sh run int gi 1/0/36&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 456 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/36&lt;/P&gt;&lt;P&gt; switchport access vlan 214&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport nonegotiate&lt;/P&gt;&lt;P&gt; switchport voice vlan 221&lt;/P&gt;&lt;P&gt; authentication host-mode multi-auth&lt;/P&gt;&lt;P&gt; authentication open&lt;/P&gt;&lt;P&gt; authentication order mab dot1x&lt;/P&gt;&lt;P&gt; authentication priority dot1x mab&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; storm-control broadcast level 30.00&lt;/P&gt;&lt;P&gt; storm-control multicast level 30.00&lt;/P&gt;&lt;P&gt; storm-control action trap&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RFNET-R1-P-SW1#sh run | inc aaa&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization exec AUTH_LIST local&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;aaa accounting dot1x default start-stop group radius&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;RFNET-R1-P-SW1#sh run | inc radisus&lt;/P&gt;&lt;P&gt;RFNET-R1-P-SW1#sh run | inc radius&lt;/P&gt;&lt;P&gt;RFNET-R1-P-SW1#sh run | inc radius&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;aaa accounting dot1x default start-stop group radius&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author&lt;/P&gt;&lt;P&gt;ip radius source-interface Vlan216&lt;/P&gt;&lt;P&gt;radius-server attribute 6 on-for-login-auth&lt;/P&gt;&lt;P&gt;radius-server attribute 8 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server attribute 25 access-request include&lt;/P&gt;&lt;P&gt;radius-server dead-criteria time 5 tries 3&lt;/P&gt;&lt;P&gt;radius-server host 172.16.10.50 auth-port 1812 acct-port 1813&lt;/P&gt;&lt;P&gt;radius-server key 7 02050D4808095E731F&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Extended IP access list ACL-POSTURE-REDIRECT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 deny udp any any eq domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 deny udp any host 172.16.10.50 eq 8905&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 deny udp any host 172.16.10.50 eq 8906&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 deny tcp any host 172.16.10.50 eq 8443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40 deny tcp any host 172.16.10.50 eq 8905&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50 deny tcp any host 74.217.77.52&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 60 permit ip any any (2 matches)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/8/2/93284-autho%20profiles.png" alt="autho profiles.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/6/8/2/93286-Posture%20Remediation.png" alt="Posture Remediation.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/7/8/2/93287-dACL%20Posture.png" alt="dACL Posture.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If somebody could take a look at the debugs and give me some hints about what's going I would appreciate it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached both debugs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971952#M175421</guid>
      <dc:creator>raga.fusionet</dc:creator>
      <dc:date>2019-03-11T02:13:55Z</dc:date>
    </item>
    <item>
      <title>dACL Download Fail</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971953#M175422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found it ... I had a typo on the dACL .. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks anyways. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 21:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971953#M175422</guid>
      <dc:creator>raga.fusionet</dc:creator>
      <dc:date>2012-06-24T21:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: dACL Download Fail</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971954#M175423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Disregard my post i see you just found it.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 21:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971954#M175423</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-06-24T21:16:29Z</dc:date>
    </item>
    <item>
      <title>dACL Download Fail</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971955#M175424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeap, that was it ... I changed a couple of minutes ago and it started working.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 21:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971955#M175424</guid>
      <dc:creator>raga.fusionet</dc:creator>
      <dc:date>2012-06-24T21:18:07Z</dc:date>
    </item>
    <item>
      <title>dACL Download Fail</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971956#M175425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No worries. Thanks!! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 21:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971956#M175425</guid>
      <dc:creator>raga.fusionet</dc:creator>
      <dc:date>2012-06-24T21:19:34Z</dc:date>
    </item>
    <item>
      <title>I have same issue now, where</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971957#M175426</link>
      <description>&lt;P&gt;I have same issue now, where exactly was the issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 09:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971957#M175426</guid>
      <dc:creator>Sherief Ahmed</dc:creator>
      <dc:date>2017-07-09T09:31:12Z</dc:date>
    </item>
    <item>
      <title>I have same issue, where</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971958#M175427</link>
      <description>&lt;P&gt;I have same issue, where exactly was the issue.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2017 09:31:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-download-fail/m-p/1971958#M175427</guid>
      <dc:creator>Sherief Ahmed</dc:creator>
      <dc:date>2017-07-09T09:31:46Z</dc:date>
    </item>
  </channel>
</rss>

