<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default denyaccess in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3196990#M555476</link>
    <description>&lt;P&gt;Just to confirm, when you say that the device has network access, do you mean that the ACL-DEFAULT is not in effect, or do you just want the endpoint to have no network access at all - even more restrictive than the ACL-DEFAULT? In that case you would need to pass Access-Accept from ISE with dACL that denies all traffic. Switch would honour the dACL then, if it is passed in RADIUS Access-Accept message.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2017 11:09:14 GMT</pubDate>
    <dc:creator>agrissimanis</dc:creator>
    <dc:date>2017-10-11T11:09:14Z</dc:date>
    <item>
      <title>Default denyaccess</title>
      <link>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3196925#M555428</link>
      <description>&lt;P&gt;Hello guys, I noticed that the default deny access ACL does not be (push) download on the interface from the Cisco ISE server. when a default rule on the authorization policy is matched with a denyAccess ACL. The device has an access on the network and also when I check which ACL is applied on the current device interface, we noticed that there is no ACL on the interface though the radius live logs show that the default rule is matched with a DenyAccess ACL. And on the switch with the &lt;STRONG&gt;sh authentication session interface Gy/x,&amp;nbsp;&lt;/STRONG&gt;we see that&lt;STRONG&gt; Dot1x and MAB are failed&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:35:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3196925#M555428</guid>
      <dc:creator>mdjan</dc:creator>
      <dc:date>2020-02-21T18:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: Default denyaccess</title>
      <link>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3196939#M555444</link>
      <description>&lt;P&gt;That is expected behaviour, deny access means just that and no RADIUS attributes are honoured by the switch.&lt;/P&gt;
&lt;P&gt;What is your standard port configuration? Do you have pre-auth ACL configured?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 09:02:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3196939#M555444</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-10-11T09:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Default denyaccess</title>
      <link>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3196964#M555462</link>
      <description>&lt;P&gt;I have a default ACL configure on the port&lt;/P&gt;
&lt;PRE&gt;ip access-list extended ACL-DEFAULT
 permit udp any eq bootpc any eq bootps
 permit udp any any eq domain
 permit ip any host 10.18.0.138
 permit ip any host 10.18.26.13
 deny   ip any any log
interface GigabitEthernet0/1
 description white cable
 switchport access vlan 3
 switchport mode access
 switchport voice vlan 2
 ip access-group ACL-DEFAULT in
 authentication event fail action next-method
 authentication event server alive action reinitialize 
 authentication host-mode multi-auth
 authentication open
 authentication order dot1x mab
 authentication priority dot1x mab
 authentication port-control auto
 authentication periodic
 authentication timer reauthenticate server
 authentication timer inactivity server
 mab
 snmp trap mac-notification change added
 snmp trap mac-notification change removed
 dot1x pae authenticator
 dot1x timeout quiet-period 15
 dot1x timeout tx-period 3
 spanning-tree portfast
 spanning-tree bpduguard enable
 ip dhcp snooping trust&lt;/PRE&gt;</description>
      <pubDate>Wed, 11 Oct 2017 09:57:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3196964#M555462</guid>
      <dc:creator>mdjan</dc:creator>
      <dc:date>2017-10-11T09:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: Default denyaccess</title>
      <link>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3196990#M555476</link>
      <description>&lt;P&gt;Just to confirm, when you say that the device has network access, do you mean that the ACL-DEFAULT is not in effect, or do you just want the endpoint to have no network access at all - even more restrictive than the ACL-DEFAULT? In that case you would need to pass Access-Accept from ISE with dACL that denies all traffic. Switch would honour the dACL then, if it is passed in RADIUS Access-Accept message.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 11:09:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3196990#M555476</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-10-11T11:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Default denyaccess</title>
      <link>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3197022#M555492</link>
      <description>&lt;P&gt;I just want the endpoint to have no network access at all, like deny ip any any on the current interface when the default rule matched.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 12:06:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3197022#M555492</guid>
      <dc:creator>mdjan</dc:creator>
      <dc:date>2017-10-11T12:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: Default denyaccess</title>
      <link>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3197036#M555502</link>
      <description>&lt;P&gt;OK, in that case just change the authorization profile to Access-Accept, and specify&amp;nbsp;dACL that has deny ip any any. Generally in low impact mode, it is accepted that the services available with the pre-auth ACL are fine, even if the endpoint fails authentication, but if you would like to completely restrict access, this approach will work.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 12:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3197036#M555502</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-10-11T12:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Default denyaccess</title>
      <link>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3197047#M555507</link>
      <description>&lt;P&gt;That is the issue because it is not working&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 12:28:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3197047#M555507</guid>
      <dc:creator>mdjan</dc:creator>
      <dc:date>2017-10-11T12:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Default denyaccess</title>
      <link>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3197080#M555511</link>
      <description>&lt;P&gt;And you definitely&amp;nbsp;don't have any problems with dACLS being applied to the hosts that pass normal corporate auth for example (that is dACLS with permit ip any any)?&lt;/P&gt;
&lt;P&gt;What is your ip device tracking config? And could you post the Attributes details section of your Authorization profile?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 13:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3197080#M555511</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-10-11T13:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Default denyaccess</title>
      <link>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3352195#M555513</link>
      <description>&lt;P&gt;The issue was on the switch side&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 07:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/default-denyaccess/m-p/3352195#M555513</guid>
      <dc:creator>mdjan</dc:creator>
      <dc:date>2018-03-21T07:34:37Z</dc:date>
    </item>
  </channel>
</rss>

