<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic View DACL that has been downloaded to NAD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/view-dacl-that-has-been-downloaded-to-nad/m-p/3081259#M23207</link>
    <description>&lt;P&gt;I have an Auth Profile with DACL attached (permit all traffic) which looks to be working OK, but my query is - How do I view and confirm that the DACL is on the switch?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see the following on the switch -&lt;/P&gt;
&lt;P&gt;SW-TEST-01&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;#sh authentication sessions interface gi3/0/45 de&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Interface: GigabitEthernet3/0/45&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; IIF-ID: 0x1033AC0000001C4&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; MAC Address: f01f.af4e.f281&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; IPv6 Address: Unknown&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; IPv4 Address: 10.44.21.83&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; User-Name: xxxxxxxxx&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Status: Authorized&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Domain: DATA&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Oper host mode: multi-domain&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Oper control dir: both&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Session timeout: N/A&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Restart timeout: N/A&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Session Uptime: 11s&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Common Session ID: 0A2C0031000065CE7DC150DA&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Acct Session ID: 0x0000656E&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Handle: 0xCF000055&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Current Policy: POLICY_Gi3/0/45&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;SW-TEST-01#sh ip access-lists interface gi3/0/45&lt;BR /&gt;SW-TEST-01&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;From the Radius logs I can see the following and it says -&amp;nbsp;&lt;STRONG&gt;Added the dACL specified in the Authorization Profile&lt;/STRONG&gt; but I am unsure where to confirm this is indeed being pushed down.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;TABLE border="0" class="content_table"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;NAS Port Id&lt;/TD&gt;
&lt;TD width="69%"&gt;GigabitEthernet3/0/45&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;NAS Port Type&lt;/TD&gt;
&lt;TD width="69%"&gt;Ethernet&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;Authorization Profile&lt;/TD&gt;
&lt;TD width="69%"&gt;Corporate User Auth&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;TABLE class="content_table_steps" border="0" cellpadding="3"&gt;
&lt;TBODY&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;24439&lt;/TD&gt;
&lt;TD&gt;Machine Attributes retrieval from Active Directory succeeded&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;24422&lt;/TD&gt;
&lt;TD&gt;ISE has confirmed previous successful machine authentication for user in Active Directory&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;15036&lt;/TD&gt;
&lt;TD&gt;Evaluating Authorization Policy&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;15048&lt;/TD&gt;
&lt;TD&gt;Queried PIP&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;24432&lt;/TD&gt;
&lt;TD&gt;Looking up user in Active Directory -&amp;nbsp;xxxxxxxx&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;24355&lt;/TD&gt;
&lt;TD&gt;LDAP fetch succeeded&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;24416&lt;/TD&gt;
&lt;TD&gt;User's Groups retrieval from Active Directory succeeded&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;15048&lt;/TD&gt;
&lt;TD&gt;Queried PIP&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;15004&lt;/TD&gt;
&lt;TD&gt;Matched rule&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;15016&lt;/TD&gt;
&lt;TD&gt;Selected Authorization Profile - Corporate User Auth&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11022&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Added the dACL specified in the Authorization Profile&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11503&lt;/TD&gt;
&lt;TD&gt;Prepared EAP-Success&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11002&lt;/TD&gt;
&lt;TD&gt;Returned RADIUS Access-Accept&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:36:55 GMT</pubDate>
    <dc:creator>GRANT3779</dc:creator>
    <dc:date>2019-03-11T07:36:55Z</dc:date>
    <item>
      <title>View DACL that has been downloaded to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/view-dacl-that-has-been-downloaded-to-nad/m-p/3081259#M23207</link>
      <description>&lt;P&gt;I have an Auth Profile with DACL attached (permit all traffic) which looks to be working OK, but my query is - How do I view and confirm that the DACL is on the switch?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see the following on the switch -&lt;/P&gt;
&lt;P&gt;SW-TEST-01&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;#sh authentication sessions interface gi3/0/45 de&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Interface: GigabitEthernet3/0/45&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; IIF-ID: 0x1033AC0000001C4&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; MAC Address: f01f.af4e.f281&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; IPv6 Address: Unknown&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; IPv4 Address: 10.44.21.83&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; User-Name: xxxxxxxxx&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Status: Authorized&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Domain: DATA&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Oper host mode: multi-domain&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Oper control dir: both&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Session timeout: N/A&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Restart timeout: N/A&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Session Uptime: 11s&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Common Session ID: 0A2C0031000065CE7DC150DA&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Acct Session ID: 0x0000656E&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Handle: 0xCF000055&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; Current Policy: POLICY_Gi3/0/45&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;SW-TEST-01#sh ip access-lists interface gi3/0/45&lt;BR /&gt;SW-TEST-01&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;From the Radius logs I can see the following and it says -&amp;nbsp;&lt;STRONG&gt;Added the dACL specified in the Authorization Profile&lt;/STRONG&gt; but I am unsure where to confirm this is indeed being pushed down.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;TABLE border="0" class="content_table"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;NAS Port Id&lt;/TD&gt;
&lt;TD width="69%"&gt;GigabitEthernet3/0/45&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;NAS Port Type&lt;/TD&gt;
&lt;TD width="69%"&gt;Ethernet&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;Authorization Profile&lt;/TD&gt;
&lt;TD width="69%"&gt;Corporate User Auth&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;TABLE class="content_table_steps" border="0" cellpadding="3"&gt;
&lt;TBODY&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;24439&lt;/TD&gt;
&lt;TD&gt;Machine Attributes retrieval from Active Directory succeeded&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;24422&lt;/TD&gt;
&lt;TD&gt;ISE has confirmed previous successful machine authentication for user in Active Directory&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;15036&lt;/TD&gt;
&lt;TD&gt;Evaluating Authorization Policy&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;15048&lt;/TD&gt;
&lt;TD&gt;Queried PIP&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;24432&lt;/TD&gt;
&lt;TD&gt;Looking up user in Active Directory -&amp;nbsp;xxxxxxxx&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;24355&lt;/TD&gt;
&lt;TD&gt;LDAP fetch succeeded&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;24416&lt;/TD&gt;
&lt;TD&gt;User's Groups retrieval from Active Directory succeeded&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;15048&lt;/TD&gt;
&lt;TD&gt;Queried PIP&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;15004&lt;/TD&gt;
&lt;TD&gt;Matched rule&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;15016&lt;/TD&gt;
&lt;TD&gt;Selected Authorization Profile - Corporate User Auth&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11022&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Added the dACL specified in the Authorization Profile&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11503&lt;/TD&gt;
&lt;TD&gt;Prepared EAP-Success&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR onmouseover="this.className='content_table_steps_highlight';" onmouseout="this.className='';" class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11002&lt;/TD&gt;
&lt;TD&gt;Returned RADIUS Access-Accept&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:36:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/view-dacl-that-has-been-downloaded-to-nad/m-p/3081259#M23207</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2019-03-11T07:36:55Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/view-dacl-that-has-been-downloaded-to-nad/m-p/3081260#M23210</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You can check for&amp;nbsp;interface using below command&lt;/P&gt;
&lt;P&gt;sh access-list int &amp;lt;name of the DACL&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also you can enable "debug epm all" to check the DACL contents coming from ISE on switch.&lt;/P&gt;
&lt;P&gt;It generates huge amount of traffic. Try to enable if required and then disable it immediately.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;Rate helpful posts!!!!!!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 00:44:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/view-dacl-that-has-been-downloaded-to-nad/m-p/3081260#M23210</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-04-07T00:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/view-dacl-that-has-been-downloaded-to-nad/m-p/5275419#M595668</link>
      <description>&lt;P&gt;Did this work for you?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 15:49:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/view-dacl-that-has-been-downloaded-to-nad/m-p/5275419#M595668</guid>
      <dc:creator>tme</dc:creator>
      <dc:date>2025-03-26T15:49:59Z</dc:date>
    </item>
  </channel>
</rss>

