<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DACL with over 100 lines in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574283#M528243</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You all for you responses&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Jul 2017 18:03:46 GMT</pubDate>
    <dc:creator>umahar</dc:creator>
    <dc:date>2017-07-27T18:03:46Z</dc:date>
    <item>
      <title>DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574279#M528234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a customer who is creating DACLs going beyond 100 IPs.&lt;/P&gt;&lt;P&gt;I have never encountered such use case but just wanted to get confirmation if this is recommended or not recommended due to TCAM utilization issues.&lt;/P&gt;&lt;P&gt;Also what is the best recommended DACL size in 3850s with 48 port ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2017 14:12:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574279#M528234</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-07-25T14:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574280#M528237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Utkarsh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if this is pertaining to ISE. Please post this question in the switching community.&lt;/P&gt;&lt;P&gt;If you are using ISE, here is the scalability and performance community site you may need.&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-68347&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-63901&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2017 17:15:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574280#M528237</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-07-25T17:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574281#M528239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't done TCAM limit checking on 3850s but look at this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/switches/catalyst-3850-series-switches/118957-troubleshoot-sec-acl-tcam-cat3850.html" title="http://www.cisco.com/c/en/us/support/docs/switches/catalyst-3850-series-switches/118957-troubleshoot-sec-acl-tcam-cat3850.html"&gt;Troubleshoot Security ACL TCAM Exhaustion on Catalyst 3850 Switches - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command "&lt;SPAN style="font-style: inherit; font-size: inherit; font-family: inherit;"&gt;show platform tcam utilization asic all" looks like a promising command to tell you exactly how many ACL entries are supported.&amp;nbsp; Have them run tests with big DACLs to confirm how the usage maps to that command.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2017 17:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574281#M528239</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-07-25T17:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574282#M528242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Utkarsh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We typically recommend using max 64 ACEs for dACLs. This is not a hard limit, but a best practice recommendation, because some platforms can do more. The collective ACE limit on the 3850 is around 3000 ACEs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="0" cellspacing="0" style="border: none;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: solid windowtext 1.0pt; padding: 0 5.4pt 0 5.4pt;" valign="top" width="468"&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;c3850-switch#show sdm prefer &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;Showing SDM Template Info&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;This is the Advanced (high scale) template.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Number of VLANs:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4094&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Unicast MAC addresses:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 32768&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Overflow Unicast MAC addresses:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 512&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; IGMP and Multicast groups:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8192&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Overflow IGMP and Multicast groups:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 512&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Directly connected routes:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16384&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Indirect routes:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7168&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; &lt;SPAN style="background: yellow;"&gt;Security Access Control Entries:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3072&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; QoS Access Control Entries:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2816&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Policy Based Routing ACEs:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1024&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Netflow ACEs:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 768&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Wireless Input Microflow policer ACEs:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Wireless Output Microflow policer ACEs:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Flow SPAN ACEs:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 512&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Tunnels:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 256&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Control Plane Entries:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 512&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Input Netflow flows:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8192&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; Output Netflow flows:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16384&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; SGT/DGT entries:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4096&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;&amp;nbsp; SGT/DGT Overflow entries:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 512&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;These numbers are typical for L2 and IPv4 features.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;Some features such as IPv6, use up double the entry size;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Courier',serif;"&gt;so only half as many entries can be created.&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps..&lt;/P&gt;&lt;P&gt;-Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jul 2017 23:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574282#M528242</guid>
      <dc:creator>hariholla</dc:creator>
      <dc:date>2017-07-25T23:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574283#M528243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You all for you responses&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jul 2017 18:03:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3574283#M528243</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2017-07-27T18:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3865627#M528245</link>
      <description>&lt;P&gt;Checking my switches, these seem to be the hard TCAM limits.&lt;/P&gt;&lt;P&gt;9400 = 18432&lt;BR /&gt;9300 = 5120&lt;BR /&gt;4500 = 4096&lt;BR /&gt;3850 = 3072&lt;BR /&gt;3560x = 924&lt;BR /&gt;2960 = 384&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 08:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3865627#M528245</guid>
      <dc:creator>Brian Taylor</dc:creator>
      <dc:date>2019-05-31T08:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3866198#M528248</link>
      <description>&lt;P&gt;deleted&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 03:35:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/3866198#M528248</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2020-09-03T03:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/4017002#M528251</link>
      <description>&lt;P&gt;For future reference, please disregard the feedback on dACL size limitation:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;dACLs are &lt;STRONG&gt;not&lt;/STRONG&gt; delivered via accounting packets&lt;/LI&gt;
&lt;LI&gt;Longer dACLs may be fragmented across multiple requests from a switch to a policy server&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Einar&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2020 12:34:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/4017002#M528251</guid>
      <dc:creator>einarnn</dc:creator>
      <dc:date>2020-01-23T12:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/4029137#M528253</link>
      <description>&lt;P&gt;As often the case, there is a grain of truth in each source of information, but often that truth becomes distorted in translation!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first point of confusion is the references to RADIUS Accounting (RFC 2866).&amp;nbsp; These references are incorrect and instead should be a reference simply to RADIUS (RFC 2865).&amp;nbsp; Per-User ACLs and downloadable ACLs (dACLs) do not use RADIUS Accounting, but RADIUS auth for transmitting ACL content. &amp;nbsp;That said, there is still a single packet maximum of 4096 bytes for RADIUS packets, notwithstanding RFCs advocating support for larger RADIUS packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second point of confusion is that there is a functional difference between Per-User ACLs and downloadable ACLs (dACLs).&amp;nbsp; Per-User ACLs are sent via RADIUS auth and Access Control Entries (ACEs) are returned as individual vendor-specific attributes (VSAs) in Access-Accept messages. &amp;nbsp;These are the ACL type which appear to be most commonly referenced in the Cisco documentation and communities.&amp;nbsp; However, these are distinct from dACLs which are an optimization to the RADIUS authorization process.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More specifically, unlike Per-User ACLs which use a direct authorization response to a Cisco switch, for example, where the AAA server returns all of the VSAs in an authorization response (Access Accept packet), dACLs use a flow where the AAA server first sends down the name of the dACL as an authorization.&amp;nbsp; The switch then makes a separate RADIUS auth request for the ACL by name. If the dACL contents have changed since a prior download (as tracked by the dACL hash extension), the current dACL contents are sent down to the RADIUS client (ex: switch). Unlike per-user ACLs that are limited to a single Access-Accept packet (max 4096 bytes), dACL contents can be returned over multiple packets, thus not limited to the same 4096-byte size restrictions as Per-User ACLs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that clarifies the sources of prior responses, each holding a bit of fact, but easily confused without understanding terminology and specific use cases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 17:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/4029137#M528253</guid>
      <dc:creator>chyps</dc:creator>
      <dc:date>2020-02-13T17:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/4029441#M528255</link>
      <description>&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Can you screenshot the per-user and dACL to clarify where each is configured?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 01:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/4029441#M528255</guid>
      <dc:creator>Brian Taylor</dc:creator>
      <dc:date>2020-02-14T01:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: DACL with over 100 lines</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/4029464#M528256</link>
      <description>&lt;P&gt;Brian, Before creating new sample entries in ISE from scratch, I did a quick search and found a site that posted decent ISE configuration examples of a dACL, Per-User ACL, as well as the IETF standard ACL (Filter-Id): &lt;A title="Delivering ACLs for MAB/DOT1x Authentication" href="https://srftw.wordpress.com/2017/02/05/delivering-acls-for-mabdot1x-authentication/" target="_self"&gt;Delivering ACLs for MAB/DOT1x Authentication&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Per-User ACLs are rarely used.&amp;nbsp; There was a time you could leverage them in multi-match policy rule set to allow ACL entries from multiple policy rules to be concatenated into a single ACL by matching individual rules.&amp;nbsp; This rule logic was removed in earlier ISE 2.x releases so not seen too often.&amp;nbsp; I recall ASA Remote Access VPN also supporting such logic with Dynamic Access Policy (DAP).&amp;nbsp; In any case, they are nice in that they allow central configuration, but you rarely see them deployed in production due to the availability of dACLs which can scale larger, detect ACE modifications, and simpler to configure.&amp;nbsp; The ISE interface allows contents to be copied and pasted from another source as text rather than entered as singular AV-pair entries in Advanced Settings, and ISE dACLs include a syntax checker. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Filter-ID is still used, but primarily with 3rd-party equipment that lack dACL support. A major downside of the IETF Filter-Id option is that the ACL must be pre-configured on each access device before it can be referenced in an authorization response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 02:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-with-over-100-lines/m-p/4029464#M528256</guid>
      <dc:creator>chyps</dc:creator>
      <dc:date>2020-02-14T02:41:43Z</dc:date>
    </item>
  </channel>
</rss>

