<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Anyconnect return ACL/VPN Filter in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-anyconnect-return-acl-vpn-filter/m-p/3491718#M496240</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Originally I tried the filter ID, using the "ACL &lt;SPAN&gt;(Filter-ID)" field in the authorization profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This resulted on the following entry: &lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Access Type = ACCESS_ACCEPT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Filter-ID = MYACLNAME.in&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;ISE automatically ads the ".in" after the ACL name, resulting in not even passing authentication on Anyconnect&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Just a side question: Why the ".in"?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When I manually added the Radius:Filter-ID [11] it works like a charm!&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;/P&gt;
&lt;P&gt;Filter-ID = MYACLNAME&lt;/P&gt;
&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jul 2018 18:22:40 GMT</pubDate>
    <dc:creator>Bram Van den Bosch</dc:creator>
    <dc:date>2018-07-12T18:22:40Z</dc:date>
    <item>
      <title>ASA Anyconnect return ACL/VPN Filter</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-anyconnect-return-acl-vpn-filter/m-p/3491716#M496237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 13.3333px;"&gt;Hi All,&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Would it be possible to return a ACL name to be used as 'VPN Filter'?&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;I know it is possible to return a DACL or Group policy, but I want to return the name of an ACL that is configured on the ASA to be used as the VPN Filter.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Using 'ACL (Filter-ID)' in the authorisation profile does not seem to work.&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;Thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 06:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-anyconnect-return-acl-vpn-filter/m-p/3491716#M496237</guid>
      <dc:creator>Bram Van den Bosch</dc:creator>
      <dc:date>2018-07-12T06:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Anyconnect return ACL/VPN Filter</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-anyconnect-return-acl-vpn-filter/m-p/3491717#M496239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113449-asa-vpn-acs-00.html#fid" title="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113449-asa-vpn-acs-00.html#fid"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113449-asa-vpn-acs-00.ht…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/vpn/vpn-filter-attribute-for-radius-server/td-p/1993224" title="https://supportforums.cisco.com/t5/vpn/vpn-filter-attribute-for-radius-server/td-p/1993224"&gt;https://supportforums.cisco.com/t5/vpn/vpn-filter-attribute-for-radius-server/td-p/1993224&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 15:05:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-anyconnect-return-acl-vpn-filter/m-p/3491717#M496239</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-07-12T15:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Anyconnect return ACL/VPN Filter</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-anyconnect-return-acl-vpn-filter/m-p/3491718#M496240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Originally I tried the filter ID, using the "ACL &lt;SPAN&gt;(Filter-ID)" field in the authorization profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This resulted on the following entry: &lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Access Type = ACCESS_ACCEPT&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Filter-ID = MYACLNAME.in&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;ISE automatically ads the ".in" after the ACL name, resulting in not even passing authentication on Anyconnect&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Just a side question: Why the ".in"?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When I manually added the Radius:Filter-ID [11] it works like a charm!&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;/P&gt;
&lt;P&gt;Filter-ID = MYACLNAME&lt;/P&gt;
&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 18:22:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-anyconnect-return-acl-vpn-filter/m-p/3491718#M496240</guid>
      <dc:creator>Bram Van den Bosch</dc:creator>
      <dc:date>2018-07-12T18:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Anyconnect return ACL/VPN Filter</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-anyconnect-return-acl-vpn-filter/m-p/3491719#M496241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The .in is a directive for "Inbound" ACL and would be interpreted correctly by wired switch.&amp;nbsp; Since ASA not accepting, adding under Advanced attributes to avoid any undesired extensions is correct option.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 19:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-anyconnect-return-acl-vpn-filter/m-p/3491719#M496241</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-07-12T19:51:17Z</dc:date>
    </item>
  </channel>
</rss>

