<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send a DACL to switch for non-domain device? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/send-a-dacl-to-switch-for-non-domain-device/m-p/3495452#M536566</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dustin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use autosmart ports on the switch for this, so that you dont have to do it per interface. You can try out interface templates as well. These are switch related configuration. Here is a link to it fyi.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/switches/lan/auto_smartports/12-2_55_se/configuration/guide/asp_cg.pdf" title="http://www.cisco.com/c/en/us/td/docs/switches/lan/auto_smartports/12-2_55_se/configuration/guide/asp_cg.pdf"&gt;http://www.cisco.com/c/en/us/td/docs/switches/lan/auto_smartports/12-2_55_se/configuration/guide/asp_cg.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you can use Network access: Auth fail attribute for failed authentication in authorization polcy and limit access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jan 2017 22:34:26 GMT</pubDate>
    <dc:creator>kthiruve</dc:creator>
    <dc:date>2017-01-06T22:34:26Z</dc:date>
    <item>
      <title>Send a DACL to switch for non-domain device?</title>
      <link>https://community.cisco.com/t5/network-access-control/send-a-dacl-to-switch-for-non-domain-device/m-p/3495449#M536561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, we use an unauth acl on switches and send back to use the auth ACL on proper 802.1x verification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, this is annoying to maintain and change and they wanted to see about moving this to ISE. My issue is that if the PC can't be verified, it never runs through the rules. How do I send the unauth as a DACL if the PC can't be verified?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2017 17:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-a-dacl-to-switch-for-non-domain-device/m-p/3495449#M536561</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-01-06T17:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Send a DACL to switch for non-domain device?</title>
      <link>https://community.cisco.com/t5/network-access-control/send-a-dacl-to-switch-for-non-domain-device/m-p/3495450#M536563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dustin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can control the initial traffic with interface ACL's and use DACL after authentication. &lt;/P&gt;&lt;P&gt;If you are using services such as Guest, BYOD as part of url-redirect acl, you can open other traffic using this.&lt;/P&gt;&lt;P&gt;And then after a change of authorization you can send a final DACL.&lt;/P&gt;&lt;P&gt;So there are a couple of ways to handle this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2017 22:03:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-a-dacl-to-switch-for-non-domain-device/m-p/3495450#M536563</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-01-06T22:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Send a DACL to switch for non-domain device?</title>
      <link>https://community.cisco.com/t5/network-access-control/send-a-dacl-to-switch-for-non-domain-device/m-p/3495451#M536565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, so there is no way to get away from an interface ACL. Thought was to block traffic, system comes on and gets a limited access dacl, then if authorized would get the final dacl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Main reason is systems when imaging are not on the domain, so fail auth at first. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, just toying around and they were asking about getting the ACL off the switch since they have to force reauth if they change it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2017 22:13:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-a-dacl-to-switch-for-non-domain-device/m-p/3495451#M536565</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-01-06T22:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Send a DACL to switch for non-domain device?</title>
      <link>https://community.cisco.com/t5/network-access-control/send-a-dacl-to-switch-for-non-domain-device/m-p/3495452#M536566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dustin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use autosmart ports on the switch for this, so that you dont have to do it per interface. You can try out interface templates as well. These are switch related configuration. Here is a link to it fyi.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/switches/lan/auto_smartports/12-2_55_se/configuration/guide/asp_cg.pdf" title="http://www.cisco.com/c/en/us/td/docs/switches/lan/auto_smartports/12-2_55_se/configuration/guide/asp_cg.pdf"&gt;http://www.cisco.com/c/en/us/td/docs/switches/lan/auto_smartports/12-2_55_se/configuration/guide/asp_cg.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you can use Network access: Auth fail attribute for failed authentication in authorization polcy and limit access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2017 22:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-a-dacl-to-switch-for-non-domain-device/m-p/3495452#M536566</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-01-06T22:34:26Z</dc:date>
    </item>
  </channel>
</rss>

