<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Downloadable ACL on Cisco IOS router (from ACS) ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/downloadable-acl-on-cisco-ios-router-from-acs/m-p/1430653#M331953</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(I am a bit new to some of the IOS Security features)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to "download" and ACL from TACACS+ (ACS 5.1) OR RADIUS AV Pairs ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I know that the lists can be configured on ACS, but how are they applied on a IOS router ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read about "lock and key ACL" , but the examples I have seen only use ACS to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, if the lists can be downloaded, WHERE can they be applied ? Would it be limited to vty ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; What I ultimately want, is to have an ACL applied per user, when VPN users login to the crypto map / Tunnel interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:11:36 GMT</pubDate>
    <dc:creator>shahedvoicerite</dc:creator>
    <dc:date>2019-03-11T00:11:36Z</dc:date>
    <item>
      <title>Downloadable ACL on Cisco IOS router (from ACS) ?</title>
      <link>https://community.cisco.com/t5/network-access-control/downloadable-acl-on-cisco-ios-router-from-acs/m-p/1430653#M331953</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(I am a bit new to some of the IOS Security features)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to "download" and ACL from TACACS+ (ACS 5.1) OR RADIUS AV Pairs ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I know that the lists can be configured on ACS, but how are they applied on a IOS router ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read about "lock and key ACL" , but the examples I have seen only use ACS to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, if the lists can be downloaded, WHERE can they be applied ? Would it be limited to vty ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; What I ultimately want, is to have an ACL applied per user, when VPN users login to the crypto map / Tunnel interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:11:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/downloadable-acl-on-cisco-ios-router-from-acs/m-p/1430653#M331953</guid>
      <dc:creator>shahedvoicerite</dc:creator>
      <dc:date>2019-03-11T00:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Downloadable ACL on Cisco IOS router (from ACS) ?</title>
      <link>https://community.cisco.com/t5/network-access-control/downloadable-acl-on-cisco-ios-router-from-acs/m-p/1430654#M331978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Yes, this is possible. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Creating, Duplicating, and Editing Downloadable ACLs &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/pol_elem.html#wp1053438"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/pol_elem.html#wp1053438&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;For radius you may use the Cisco A/V pair, the format of ACL should be,&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;ip:inacl#&lt;N&gt;=&lt;ACL content=""&gt;&lt;/ACL&gt;&lt;/N&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;"ip:inacl#1=permit tcp any any"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Do rate helpful posts-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jun 2010 02:38:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/downloadable-acl-on-cisco-ios-router-from-acs/m-p/1430654#M331978</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2010-06-17T02:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Downloadable ACL on Cisco IOS router (from ACS) ?</title>
      <link>https://community.cisco.com/t5/network-access-control/downloadable-acl-on-cisco-ios-router-from-acs/m-p/1430655#M332075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but I already know that it IS possible in ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is how do I *USE* this on an IOS router like a 2811. (As opposed to a PIX/ASA)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; i.e What IOS commands do I enter, and where can I enter them, to make use of such ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant seem to find any docs on this, and the only "lock and key" dACL example, does not show how to download the ACL&lt;/P&gt;&lt;P&gt;from ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this point, I am not sure if this feature is even supported on IOS routers, or if its only for PIX/ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jun 2010 09:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/downloadable-acl-on-cisco-ios-router-from-acs/m-p/1430655#M332075</guid>
      <dc:creator>shahedvoicerite</dc:creator>
      <dc:date>2010-06-17T09:12:50Z</dc:date>
    </item>
  </channel>
</rss>

