<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fixed my issue.  DHCP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698058#M55540</link>
    <description>&lt;P&gt;Fixed my issue. &amp;nbsp;DHCP snooping was getting blocked at port on server. &amp;nbsp;Trusted the port and everything started working.&lt;/P&gt;</description>
    <pubDate>Sun, 17 May 2015 17:41:42 GMT</pubDate>
    <dc:creator>Justin.Nichols</dc:creator>
    <dc:date>2015-05-17T17:41:42Z</dc:date>
    <item>
      <title>ISE dACL issues 4510</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698054#M55523</link>
      <description>&lt;P&gt;I am having an issue with my permit all dACL for printers on a 4510 switch.&lt;/P&gt;&lt;P&gt;Everything looks to be getting applied correctly from ISE, but I'm still getting blocked by my default ACL after the dACL has been successfully downloaded.&amp;nbsp; This is working on 3560 with the same config.&lt;/P&gt;&lt;P&gt;cat4500e-universalk9.SPA.03.04.06.SG.151-2.SG6.bin&lt;/P&gt;&lt;P&gt;&amp;nbsp;Interface:&amp;nbsp; GigabitEthernet8/1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC Address:&amp;nbsp; 0014.3889.3278&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address:&amp;nbsp; Unknown&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name:&amp;nbsp; 00-14-38-89-32-78&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;&lt;SPAN style="color:#FF0000;"&gt;Status:&amp;nbsp; Authz Success&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain:&amp;nbsp; DATA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Policy:&amp;nbsp; Should Secure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Security Status:&amp;nbsp; Unsecure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper host mode:&amp;nbsp; multi-auth&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oper control dir:&amp;nbsp; both&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authorized By:&amp;nbsp; Authentication Server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan Policy:&amp;nbsp; 9&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;&lt;SPAN style="color:#FF0000;"&gt;ACS ACL:&amp;nbsp; xACSACLx-IP-PERMIT_ALL_TRAFFIC-5484c0cc&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle timeout:&amp;nbsp; N/A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Common Session ID:&amp;nbsp; 0A01D2FC000001DC08B4190C&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct Session ID:&amp;nbsp; 0x000001E5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Handle:&amp;nbsp; 0x230001DD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="color:#FF0000;"&gt;May 15 03:02:29: %SEC-6-IPACCESSLOGP: list ACL_DEFAULT denied tcp 10.1.230.99(9100) -&amp;gt; 10.1.210.74(53091), 2 packets&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698054#M55523</guid>
      <dc:creator>Justin.Nichols</dc:creator>
      <dc:date>2019-03-13T00:46:01Z</dc:date>
    </item>
    <item>
      <title>add:  VLAN assignment is</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698055#M55527</link>
      <description>&lt;P&gt;add:&amp;nbsp; VLAN assignment is working correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet8/1&lt;BR /&gt;&amp;nbsp;switchport access vlan 8&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 3&lt;BR /&gt;&amp;nbsp;authentication event fail action next-method&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 1&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-auth&lt;BR /&gt;&amp;nbsp;authentication order dot1x mab&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication violation restrict&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;snmp trap mac-notification change added&lt;BR /&gt;&amp;nbsp;snmp trap mac-notification change removed&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;BR /&gt;&amp;nbsp;ip dhcp snooping trust&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2015 15:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698055#M55527</guid>
      <dc:creator>Justin.Nichols</dc:creator>
      <dc:date>2015-05-15T15:29:10Z</dc:date>
    </item>
    <item>
      <title>Can you see the ip adds of</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698056#M55532</link>
      <description>&lt;P&gt;Can you see the ip adds of your printer as active in "show ip device tracking all", when it's not working ?&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2015 20:06:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698056#M55532</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-05-15T20:06:21Z</dc:date>
    </item>
    <item>
      <title>You can use debug epm to</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698057#M55537</link>
      <description>&lt;P&gt;You can use debug epm to verify DACL installation errors. It seems like DACL is not installed on TCAM because we're not learning the endpoint IP.&amp;nbsp; As Jan said,&amp;nbsp; do a "show ip device tracking all"&amp;nbsp; and verify if we are learning the endpoint's IP on Gig8/1.&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2015 03:33:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698057#M55537</guid>
      <dc:creator>Antonio Torres</dc:creator>
      <dc:date>2015-05-17T03:33:31Z</dc:date>
    </item>
    <item>
      <title>Fixed my issue.  DHCP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698058#M55540</link>
      <description>&lt;P&gt;Fixed my issue. &amp;nbsp;DHCP snooping was getting blocked at port on server. &amp;nbsp;Trusted the port and everything started working.&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2015 17:41:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698058#M55540</guid>
      <dc:creator>Justin.Nichols</dc:creator>
      <dc:date>2015-05-17T17:41:42Z</dc:date>
    </item>
    <item>
      <title>This is somewhat off subject.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698059#M55541</link>
      <description>&lt;P&gt;This is somewhat off subject. I am looking for a solution to whitelisting printers. Currently we whitelist printers on our 802.1x wired network. I have whitelisted over 30 new devices in that last month, but have not taken any out of the list. Any sample acls, or dAcls would be appreciated. Being a university we have a variety of printers, HP, Brother, Canon, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2015 15:30:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dacl-issues-4510/m-p/2698059#M55541</guid>
      <dc:creator>rschwart</dc:creator>
      <dc:date>2015-06-22T15:30:12Z</dc:date>
    </item>
  </channel>
</rss>

