<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dACL Validation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dacl-validation/m-p/3745782#M488301</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the update.&lt;/P&gt;
&lt;P&gt;I have validated it in ISE and it is showing an Valid dACL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, in ISE it only checks the Syntax and I am more concerned about multiple ports mentioned in same line for few of the IP's as mentioned in dACL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sadashiv&lt;/P&gt;</description>
    <pubDate>Tue, 13 Nov 2018 14:28:48 GMT</pubDate>
    <dc:creator>sadashivpalde</dc:creator>
    <dc:date>2018-11-13T14:28:48Z</dc:date>
    <item>
      <title>dACL Validation</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-validation/m-p/3745663#M488298</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;We are&amp;nbsp;having ISE2.4 Patch1 in deployment with Cisco WS-C2960+48TC-L {IOS v15.2(4)E6}.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We&amp;nbsp;want to use&amp;nbsp;dACL for Non-Compliant Endpoints with limited access.&lt;/P&gt;
&lt;P&gt;We used dACL of 67 lines, the dACL gets applied on interface, but something goes wrong and everything is permitted for non-compliant endpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, we reduced the same dACL in below format upto 41 lines, want to verify if this dACL is valid and will work??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;permit tcp any host 10.1.x.x eq 53&lt;BR /&gt;permit udp any host 10.225.x.x eq 53&lt;BR /&gt;permit tcp any host 10.1.&lt;SPAN&gt;x.x&lt;/SPAN&gt; eq 53&lt;BR /&gt;permit udp any host 10.225.&lt;SPAN&gt;x.x&lt;/SPAN&gt;&amp;nbsp;eq 53&lt;BR /&gt;permit udp any eq bootpc any eq bootps&lt;BR /&gt;permit udp any eq bootps any eq bootpc &lt;BR /&gt;permit ip any 10.227.254.0 0.0.0.255&lt;BR /&gt;permit ip any 10.225.254.0 0.0.0.255&lt;BR /&gt;permit tcp any any eq 52311&lt;BR /&gt;permit udp any any eq 52311&lt;BR /&gt;permit tcp any any eq 888&lt;BR /&gt;permit ip any host 10.225.x.x&lt;BR /&gt;permit tcp any any eq 445&lt;BR /&gt;permit ip any host 10.226.x.x&lt;BR /&gt;permit ip any host 10.226.x.x&lt;BR /&gt;permit ip any host 10.227.x.x&lt;BR /&gt;permit ip any host 10.227.x.x&lt;BR /&gt;permit tcp any any eq 2967&lt;BR /&gt;permit ip any host 10.226.x.x&lt;BR /&gt;permit ip any host 10.226.x.x&lt;BR /&gt;permit ip any host 10.225.x.x&lt;BR /&gt;permit ip any host 172.18.x.x&lt;BR /&gt;permit ip any host 10.226.x.x&lt;BR /&gt;permit ip any host 10.225.x.x&lt;BR /&gt;permit tcp any host 10.1.x.x eq 389 88 445 135 3268 636 3269 464&lt;BR /&gt;permit udp any host 10.1.x.x eq 389 88 445 123 138 137 464&lt;BR /&gt;permit tcp any host 10.225.x.x eq 389 88 445 135 3268 636 3269 464 &lt;BR /&gt;permit udp any host 10.225.x.x eq 389 88 445 123 138 137 464&lt;BR /&gt;permit tcp any host 10.1.33.x range 49152 65535&lt;BR /&gt;permit tcp any host 10.225.x.x range 49152 65535&lt;BR /&gt;permit tcp any host 10.1.x.x range 1024 5000 &lt;BR /&gt;permit tcp any host 10.225.x.x range 1024 5000 &lt;BR /&gt;permit tcp any host 10.226.&lt;SPAN&gt;x.x&lt;/SPAN&gt; eq 80&lt;BR /&gt;permit tcp any host 10.225.&lt;SPAN&gt;x.x&lt;/SPAN&gt;&amp;nbsp;eq 80&lt;BR /&gt;permit tcp any host 10.226.&lt;SPAN&gt;x.x&lt;/SPAN&gt; eq 80 443&lt;BR /&gt;permit tcp any host 10.225.&lt;SPAN&gt;x.x&lt;/SPAN&gt; eq 81 443&lt;BR /&gt;permit tcp any host 10.226.&lt;SPAN&gt;x.x&lt;/SPAN&gt; eq 80&lt;BR /&gt;permit tcp any host 10.226.&lt;SPAN&gt;x.x&lt;/SPAN&gt; eq 80&lt;BR /&gt;permit tcp any host 10.225.&lt;SPAN&gt;x.x&lt;/SPAN&gt; eq 8014&lt;BR /&gt;permit tcp any host 10.225.&lt;SPAN&gt;x.x&lt;/SPAN&gt; eq 8014&lt;BR /&gt;deny ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sadashiv&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 10:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-validation/m-p/3745663#M488298</guid>
      <dc:creator>sadashivpalde</dc:creator>
      <dc:date>2018-11-13T10:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: dACL Validation</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-validation/m-p/3745704#M488300</link>
      <description>&lt;P&gt;Hi , you can always check DaCL validation by ISE&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 12:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-validation/m-p/3745704#M488300</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-11-13T12:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: dACL Validation</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-validation/m-p/3745782#M488301</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the update.&lt;/P&gt;
&lt;P&gt;I have validated it in ISE and it is showing an Valid dACL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, in ISE it only checks the Syntax and I am more concerned about multiple ports mentioned in same line for few of the IP's as mentioned in dACL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sadashiv&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 14:28:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-validation/m-p/3745782#M488301</guid>
      <dc:creator>sadashivpalde</dc:creator>
      <dc:date>2018-11-13T14:28:48Z</dc:date>
    </item>
  </channel>
</rss>

