<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dACL not shown under the interface in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dacl-not-shown-under-the-interface/m-p/4418187#M567862</link>
    <description>&lt;P&gt;This is normal behavior. The DACL will not show in the interface output as it is applied on a session basis. Depending on how many endpoints are connected to the interface (e.g. phone with PC, dumb hub/switch with multiple PCs connected), there could be many different per-session DACLs applied to the same interface.&lt;/P&gt;
&lt;P&gt;The DACL will override any ACL applied to the switchport for the respective session and the auth/epm session output should reflect the DACL controlling that session.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jun 2021 00:47:05 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2021-06-15T00:47:05Z</dc:date>
    <item>
      <title>dACL not shown under the interface</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-not-shown-under-the-interface/m-p/4417563#M567833</link>
      <description>&lt;P&gt;When ISE dACL is applied correctly and is visible in the authenticated session:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;SW1-2960#show authentication sessions int g2/0/2 det
            Interface:  GigabitEthernet2/0/2
          MAC Address:  0050.5600.0141
         IPv6 Address:  Unknown
         IPv4 Address:  10.2.7.30
            User-Name:  nicole
               Status:  Authorized
               Domain:  DATA
       Oper host mode:  multi-auth
     Oper control dir:  both
      Session timeout:  N/A
      Restart timeout:  N/A
Periodic Acct timeout:  N/A
       Session Uptime:  25s
    Common Session ID:  0A304A19000000632C6CF72A
      Acct Session ID:  0x0000003E
               Handle:  0x38000046
       Current Policy:  POLICY_Gi2/0/2

Local Policies:
        Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)

Server Policies:
              ACS ACL:  xACSACLx-IP-TEMP_ACL-60b7be60

Method status list:
      Method            State

      dot1x              Authc Success

SW1-2960#&lt;/PRE&gt;&lt;P&gt;Does it override the ACL that is manually configured under the interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see the dACL applied using the command show epm sess:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;SW1-2960#show epm session ip 10.2.7.30

% NOTE: This command will be deprecated soon.
  Please use show authentication sessions or
  show access-session (eedge-mode) for all session
  related information


 Server Policies (priority 100)
              ACS ACL:  xACSACLx-IP-TEMP_ACL-60b7be60

 Server Policies (priority 255)

Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)

SW1-2960#&lt;/PRE&gt;&lt;P&gt;but when using this command t check the ACLs under the interfaces:&lt;/P&gt;&lt;PRE&gt;SW1-2960#$show ip interface | include is up|is administratively|is down|Outgoing|Inbound
...
GigabitEthernet2/0/2 is up, line protocol is up
  Inbound  access list is TEST-ACL --&amp;gt; Not the ACL from ISE&lt;BR /&gt;...&lt;/PRE&gt;&lt;P&gt;the applied ACL under the interface&amp;nbsp;GigabitEthernet2/0/2 is not the dACL.&lt;/P&gt;&lt;P&gt;Why is that? How do I know which ACL is in use?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jun 2021 23:33:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-not-shown-under-the-interface/m-p/4417563#M567833</guid>
      <dc:creator>SMD28316</dc:creator>
      <dc:date>2021-06-13T23:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: dACL not shown under the interface</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-not-shown-under-the-interface/m-p/4417624#M567842</link>
      <description>&lt;P&gt;Have you set up the NAD profile vendor as cisco ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;some diag tips :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/119374-technote-dacl-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/119374-technote-dacl-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 04:26:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-not-shown-under-the-interface/m-p/4417624#M567842</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-06-14T04:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: dACL not shown under the interface</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-not-shown-under-the-interface/m-p/4418187#M567862</link>
      <description>&lt;P&gt;This is normal behavior. The DACL will not show in the interface output as it is applied on a session basis. Depending on how many endpoints are connected to the interface (e.g. phone with PC, dumb hub/switch with multiple PCs connected), there could be many different per-session DACLs applied to the same interface.&lt;/P&gt;
&lt;P&gt;The DACL will override any ACL applied to the switchport for the respective session and the auth/epm session output should reflect the DACL controlling that session.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 00:47:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-not-shown-under-the-interface/m-p/4418187#M567862</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-06-15T00:47:05Z</dc:date>
    </item>
  </channel>
</rss>

