<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: It's not only the problem, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/4303500#M565957</link>
    <description>&lt;P&gt;Is the IPv6 dACL issue still there on the 2960X switches?&lt;/P&gt;&lt;P&gt;I was doing some testing and thought configuring with the IBNS 2.0 style configuration rather than the legacy style might fix this, however it doesn't.&lt;/P&gt;&lt;P&gt;If an AV-Pair is presented with 'ipv6:inacl#xxxxxxx' then authentication just fails and you get a dot1x override message in the log&lt;/P&gt;&lt;PRE&gt;Mar  8 20:54:59.752: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for client (40b0.340b.bb45) on Interface Gi1/0/1 AuditSessionID C0A8F73300000025029F22A6&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;If you remove the ipv6 acl av-pair the device authenticates OK.&amp;nbsp; ipv4 acl av-pair works fine.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Mar 2021 22:22:23 GMT</pubDate>
    <dc:creator>andrew.butterworth</dc:creator>
    <dc:date>2021-03-08T22:22:23Z</dc:date>
    <item>
      <title>ISE: support for IPv6 DACL's</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594700#M75304</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Does anyone know if/when ISE will be able to push out IPv6 dynamic acl's? I have not managed to find any information on this other than an old post here: &lt;A href="https://supportforums.cisco.com/discussion/11795676/ise-support-ipv6-dynamic-acls" target="_blank"&gt;https://supportforums.cisco.com/discussion/11795676/ise-support-ipv6-dynamic-acls&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Phill Macey&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594700#M75304</guid>
      <dc:creator>Phillip Macey</dc:creator>
      <dc:date>2019-03-13T00:44:58Z</dc:date>
    </item>
    <item>
      <title>ISE 1.3 do not support IPV6</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594701#M75306</link>
      <description>&lt;P&gt;ISE 1.3 do not support IPV6 as of now but its in road map&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2015 14:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594701#M75306</guid>
      <dc:creator>Venkatesh Attuluri</dc:creator>
      <dc:date>2015-01-06T14:21:53Z</dc:date>
    </item>
    <item>
      <title>It's not supported as of the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594702#M75308</link>
      <description>&lt;P&gt;It's not supported as of the current ISE 1.3.&lt;/P&gt;&lt;P&gt;I've heard it is planned for a future release but there's no announced or committed date as of yet.&lt;/P&gt;&lt;P&gt;If your're working with a partner or Cisco account manager, be sure to officially request it&amp;nbsp;if it's important to you. Customer requests help build the business case for prioritizing the features.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 02:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594702#M75308</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-01-07T02:22:02Z</dc:date>
    </item>
    <item>
      <title>It would seem that ISE 2.0</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594703#M75309</link>
      <description>&lt;P&gt;It would seem that ISE 2.0 has added support for IPv6 dACL's. I have not yet tried it out.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/release_notes/ise20_rn.html#pgfId-592126&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 02:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594703#M75309</guid>
      <dc:creator>Phillip Macey</dc:creator>
      <dc:date>2015-11-30T02:26:22Z</dc:date>
    </item>
    <item>
      <title>It's not only the problem,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594704#M75310</link>
      <description>&lt;P&gt;It's not only the problem, whether the ISE supports pushing of IPv6 dACLs or not. It's already possible - even with ISE version 1.4 using Cisco AVPs:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;cisco-av-pair = ipv6:inacl#1=&amp;lt;IPv6-ACL-LINE-1&amp;gt;&lt;BR /&gt;cisco-av-pair = ipv6:inacl#2=&amp;lt;IPv6-ACL-LINE-2&amp;gt;&lt;BR /&gt;cisco-av-pair = ipv6:inacl#n=&amp;lt;IPv6-ACL-LINE-n&amp;gt;&lt;/PRE&gt;
&lt;P&gt;So the ISE can do this very easily within autorization profiles.&lt;/P&gt;
&lt;P&gt;The problem is mainly the switch hardware platforms supporting IPv6 dACLs.&lt;/P&gt;
&lt;P&gt;From what I know IPv6 dACLs are currently only supported on the new IOS-XE platforms (3650, 3850 maybe 4500-S8). For all the &lt;STRONG&gt;still current &lt;/STRONG&gt;platforms this is not supported (like Cat2960S, 2960X, Cat6k). Hopefully Cisco will introduce support for these platforms as well. Honestly I'm not seeing a lot of people which actually use the 3650 and 3850 in the access layer (yet).&lt;/P&gt;
&lt;P&gt;Maybe someone from Cisco sees this and state if this IPv6 dACL will be supported on these platforms as well.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2016 12:06:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594704#M75310</guid>
      <dc:creator>Johannes Luther</dc:creator>
      <dc:date>2016-03-24T12:06:22Z</dc:date>
    </item>
    <item>
      <title>I did not know you could do</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594705#M75311</link>
      <description>&lt;P&gt;I did not know you could do that with the cisco-av-pair. Thanks for mentioning it!&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 05:01:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/2594705#M75311</guid>
      <dc:creator>Phillip Macey</dc:creator>
      <dc:date>2016-03-31T05:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: It's not only the problem,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/4303500#M565957</link>
      <description>&lt;P&gt;Is the IPv6 dACL issue still there on the 2960X switches?&lt;/P&gt;&lt;P&gt;I was doing some testing and thought configuring with the IBNS 2.0 style configuration rather than the legacy style might fix this, however it doesn't.&lt;/P&gt;&lt;P&gt;If an AV-Pair is presented with 'ipv6:inacl#xxxxxxx' then authentication just fails and you get a dot1x override message in the log&lt;/P&gt;&lt;PRE&gt;Mar  8 20:54:59.752: %DOT1X-5-RESULT_OVERRIDE: Authentication result overridden for client (40b0.340b.bb45) on Interface Gi1/0/1 AuditSessionID C0A8F73300000025029F22A6&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;If you remove the ipv6 acl av-pair the device authenticates OK.&amp;nbsp; ipv4 acl av-pair works fine.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 22:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-ipv6-dacl-s/m-p/4303500#M565957</guid>
      <dc:creator>andrew.butterworth</dc:creator>
      <dc:date>2021-03-08T22:22:23Z</dc:date>
    </item>
  </channel>
</rss>

