<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Downloadable Access-list  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545505#M426616</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is windows XP running a ssh client to connect to the Cisco devices. The downloadable access-list is ceated using Cisco ACS server. Thanks for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Aug 2006 15:27:04 GMT</pubDate>
    <dc:creator>kanwar</dc:creator>
    <dc:date>2006-08-24T15:27:04Z</dc:date>
    <item>
      <title>Downloadable Access-list</title>
      <link>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545503#M426590</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created a one line downloadble access-list in Cisco ACS to deny a host. deny tcp any host 192.168.115.1 eq 22 and assinged it to a user and group. when I try ssh it should be denied but it works. Thx for the help in advance&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545503#M426590</guid>
      <dc:creator>kanwar</dc:creator>
      <dc:date>2019-03-10T21:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Downloadable Access-list</title>
      <link>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545504#M426601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What platform is requesting the ACL? is the ACL actually downloading? (show access-lists should show an access-list starting with #ACSACL#).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have the keyword "per-user-override" defined on the access-group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Andrew.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Aug 2006 11:21:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545504#M426601</guid>
      <dc:creator>andrew.burns</dc:creator>
      <dc:date>2006-08-24T11:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: Downloadable Access-list</title>
      <link>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545505#M426616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is windows XP running a ssh client to connect to the Cisco devices. The downloadable access-list is ceated using Cisco ACS server. Thanks for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Aug 2006 15:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545505#M426616</guid>
      <dc:creator>kanwar</dc:creator>
      <dc:date>2006-08-24T15:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Downloadable Access-list</title>
      <link>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545506#M426625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A downloadable acl can only be downloaded to an aaa-client that supports it (i.e. pix/asa/router/etc.) so I was just wondering what aaa-client is configured to request the ACL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2006 07:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545506#M426625</guid>
      <dc:creator>andrew.burns</dc:creator>
      <dc:date>2006-08-25T07:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Downloadable Access-list</title>
      <link>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545507#M426628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There's a few things you can check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) the device is typed in the network config correctly... must be a device that supports DACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) If you run csradius -z -p from the command line you should see the access accept include a Cisco VSA that gives the device the name of the DSCL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) You should then see a further access request from the device to pull down the DACL content.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2006 18:47:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/downloadable-access-list/m-p/545507#M426628</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-08-25T18:47:15Z</dc:date>
    </item>
  </channel>
</rss>

