<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Nic, this should be in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/providing-different-acl-for-the-same-device-depending-where/m-p/3006538#M24188</link>
    <description>&lt;P&gt;Hi Nic, this should be possible. I have done this in the past where I had to push a different dACL based on the office location and floor #. For this, I used the "Device-Location" attribute. Thus, switches were grouped based on the device location which I used for the Authorization Rules. For instance, :&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If device location = SiteA-Floor-1 then dACL =&amp;nbsp;ACL_1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If device location = SiteA-Floor-3 then dACL =&amp;nbsp;ACL_2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2017 19:11:13 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2017-02-01T19:11:13Z</dc:date>
    <item>
      <title>Providing different ACL for the same device depending where connected ?</title>
      <link>https://community.cisco.com/t5/network-access-control/providing-different-acl-for-the-same-device-depending-where/m-p/3006537#M24186</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;in a classical and normal ISE - NAC design is it possible to send different downloadable ACL for a same device depending of where it is connected ? I mean for example :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;- Laptop X connected in vlan 100 (IP range 10.10.10.0/24) : get downloadable access-list "permit any".&lt;/P&gt;
&lt;P&gt;- Same laptop X connected in vlan 20 (IP range 20.20.20.0/24) : get different downloadable access-list "deny all".&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I know it is possible to provide dACL based on the IP range but is it also possible to base the ACL on "type of device + IP range" ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Nic&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/providing-different-acl-for-the-same-device-depending-where/m-p/3006537#M24186</guid>
      <dc:creator>NicolasDemonty</dc:creator>
      <dc:date>2019-03-11T07:25:18Z</dc:date>
    </item>
    <item>
      <title>Hi Nic, this should be</title>
      <link>https://community.cisco.com/t5/network-access-control/providing-different-acl-for-the-same-device-depending-where/m-p/3006538#M24188</link>
      <description>&lt;P&gt;Hi Nic, this should be possible. I have done this in the past where I had to push a different dACL based on the office location and floor #. For this, I used the "Device-Location" attribute. Thus, switches were grouped based on the device location which I used for the Authorization Rules. For instance, :&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If device location = SiteA-Floor-1 then dACL =&amp;nbsp;ACL_1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If device location = SiteA-Floor-3 then dACL =&amp;nbsp;ACL_2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2017 19:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/providing-different-acl-for-the-same-device-depending-where/m-p/3006538#M24188</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2017-02-01T19:11:13Z</dc:date>
    </item>
    <item>
      <title>Hi Neno,</title>
      <link>https://community.cisco.com/t5/network-access-control/providing-different-acl-for-the-same-device-depending-where/m-p/3006539#M24190</link>
      <description>&lt;P&gt;Hi Neno,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks for the reply. Actually this method doesn't suit me as I have to do the difference between vlan or IP net and I can have two of the vlans on the same location.&lt;/P&gt;
&lt;P&gt;kr&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Nic&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 07:16:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/providing-different-acl-for-the-same-device-depending-where/m-p/3006539#M24190</guid>
      <dc:creator>NicolasDemonty</dc:creator>
      <dc:date>2017-02-02T07:16:15Z</dc:date>
    </item>
    <item>
      <title>Before I can provide any</title>
      <link>https://community.cisco.com/t5/network-access-control/providing-different-acl-for-the-same-device-depending-where/m-p/3006540#M24192</link>
      <description>&lt;P&gt;Before I can provide any additional suggestions you will need to outline the exact requirements &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Can you give us more details on exactly what you are trying to accomplish?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 18:20:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/providing-different-acl-for-the-same-device-depending-where/m-p/3006540#M24192</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2017-02-02T18:20:25Z</dc:date>
    </item>
  </channel>
</rss>

