<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.4 and Authenticating Printers Using a DACL in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4497088#M570815</link>
    <description>&lt;P&gt;Please rate if this has been helpful.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Nov 2021 11:35:42 GMT</pubDate>
    <dc:creator>Anthony O'Reilly</dc:creator>
    <dc:date>2021-11-03T11:35:42Z</dc:date>
    <item>
      <title>ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4028494#M453931</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would like to use a DACL in my ISE deployment to more secure networked printers.&lt;/P&gt;&lt;P&gt;I am currently at ISE 2.4 patch 8. I have a two-node deployment which has been working well.&lt;/P&gt;&lt;P&gt;I am now allowing printers onto the network by adding them to a Endpoint Identity group and then allowing that group network access.&lt;/P&gt;&lt;P&gt;I would like to be more secure than what I am doing now. I have considered certificates but because of the number of printers (about 110) and the variety of printer manufacturers I believe this would be very difficult.&lt;/P&gt;&lt;P&gt;I am now considering adding a DACL to more secure the printers. I have a DACL already created for the Printers Authorization Profile but it is simply "Permit IP any any".&lt;/P&gt;&lt;P&gt;I have researched and I would need to allow only certain ports (515 and 9100) and maybe others.&lt;/P&gt;&lt;P&gt;Can someone direct me to a sample of what a Printer DACL would look like?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 19:19:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4028494#M453931</guid>
      <dc:creator>RSundstrom</dc:creator>
      <dc:date>2020-02-12T19:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4028570#M453933</link>
      <description>&lt;P&gt;Every environment would be different.&amp;nbsp; Different vendors use different ports, some have centralized management on their own ports, users add printers to their computers in different ways (i.e. TCP/IP printing, print server, etc.).&amp;nbsp; Try to discuss with your Service Desk or Desktop Support teams to gain a better understanding of the types of printers and how they are added to workstations.&amp;nbsp; Then you can pick a small area to test with.&amp;nbsp; Use a new authorization rule that adds a condition for a specific network device or a group of test network devices.&amp;nbsp; Test printing different ways and do some packet captures if needed.&amp;nbsp; As you get comfortable that your dACL is working, deploy it to all switches and troubleshoot one-off's as needed.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 21:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4028570#M453933</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-02-12T21:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4306032#M566077</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you apply at dACL for your printing solution?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 00:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4306032#M566077</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2021-03-12T00:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4306835#M566104</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/327177"&gt;@RSundstrom&lt;/a&gt;&amp;nbsp; Please do share your findings with us about the various printers and ports!&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 19:52:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4306835#M566104</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-03-13T19:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4307171#M566131</link>
      <description>&lt;P&gt;As &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/624773"&gt;@Colby LeMaire&lt;/a&gt; mentioned, the DACLs can vary depending on the vendor/model of the printer as well as the features being used. You would definitely need to consult the vendor documentation and the technical team designing/deploying the printer solution to determine exactly what ports/protocols are required. You need to consider TCAM limitations on the switches that will use the DACL as having large ACLs applied to multiple ports can cause TCAM exhaustion and lead to memory issues.&lt;/P&gt;
&lt;P&gt;Here is an example DACL we defined for one customer that is using Lexmark printers:&lt;/P&gt;
&lt;PRE&gt;permit tcp any any eq 25
permit udp any any eq 53
permit udp any eq bootpc any eq bootps
permit udp any any eq 162
permit udp any eq 161 any
permit tcp any eq 161 any
permit udp any eq 9300 any range 1024 65534
permit udp any eq 9187 any range 1024 65534
permit tcp any eq 631 any
permit tcp any eq 515 any
permit tcp any eq 443 any
permit tcp any eq 80 any
permit tcp any eq 5000 5001 any
permit tcp any eq 5900 any
permit tcp any any eq 2939
permit tcp any eq 6110 any
permit udp any eq 6100 any eq 6100
permit udp any eq 5353 any
permit tcp any eq 21 any
permit tcp any eq 20 any
permit tcp any eq 9100 any
permit icmp any any echo-reply
deny ip any any&lt;/PRE&gt;</description>
      <pubDate>Sun, 14 Mar 2021 22:45:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4307171#M566131</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-03-14T22:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4489830#M570567</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I'm looking for help and explain on DACL. Currently, we're planning to improve restriction on IoT device in order to prevent any attacks as well Mac address spoofing.&lt;/P&gt;&lt;P&gt;Kindly, please help to explain as below.&lt;/P&gt;&lt;P&gt;What is the mainly purpose to have DACL?&amp;nbsp; How DACL work with IoT device?&lt;/P&gt;&lt;P&gt;Can we use DACL to limited IoT device in the same VLAN? How it works without network segmentation? example: in case improper network segmentation or allow VLAN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One more thing, what is the information or prerequisite that we could have and collect for configuration DACL for IoT devices?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please help share if you have any documents or guideline end to end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 11:52:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4489830#M570567</guid>
      <dc:creator>Sina Dy</dc:creator>
      <dc:date>2021-10-21T11:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4489957#M570577</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1195261"&gt;@Sina Dy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The main purpose of a dACL is to restrict traffic from the device to the network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After your IoT device authenticates, it will go through the authorization process, get an authorization profile from the policy set it matches and in the authz profile, you can assign a dACL.&lt;/P&gt;&lt;P&gt;You can enable probes on ISE, from this information that is sent to ISE, profiles can be created. You can create policy sets to match against this profile and you can also select security groups on the same ruleset.&lt;/P&gt;&lt;P&gt;You can also set a VLAN change if matched against the ruleset. This is also completed on the Authz profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this makes sense.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 14:47:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4489957#M570577</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2021-10-21T14:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4489987#M570579</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/202309"&gt;@Anthony O'Reilly&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the information or prerequisite that we could have and collect for configuration DACL for IoT devices?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please help share if you have any documents or guideline end to end.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 15:21:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4489987#M570579</guid>
      <dc:creator>Sina Dy</dc:creator>
      <dc:date>2021-10-21T15:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4490766#M570607</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1195261"&gt;@Sina Dy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a look at this, it goes through all the steps. When configuring your dACL add in networks, hosts and/or ports that your IoT device can connect to:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/b_ise_admin_guide_sample_chapter_010100.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/b_ise_admin_guide_sample_chapter_010100.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is also good, old version of ISE but the concept is the same&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ciscopress.com/articles/article.asp?p=2091952&amp;amp;seqNum=4" target="_blank"&gt;Authorization Policies &amp;gt; Authentication and Authorization Policies: Using Cisco Identity Services Engine in a BYOD World | Cisco Press&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 15:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4490766#M570607</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2021-10-22T15:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4491145#M570615</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/202309"&gt;@Anthony O'Reilly&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for your sharing. I will take a look. if have any other question will drop here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Oct 2021 16:48:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4491145#M570615</guid>
      <dc:creator>sinady</dc:creator>
      <dc:date>2021-10-23T16:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 and Authenticating Printers Using a DACL</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4497088#M570815</link>
      <description>&lt;P&gt;Please rate if this has been helpful.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 11:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-and-authenticating-printers-using-a-dacl/m-p/4497088#M570815</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2021-11-03T11:35:42Z</dc:date>
    </item>
  </channel>
</rss>

