<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 'dacl' option not showing in authorization profile in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556619#M572900</link>
    <description>&lt;P&gt;Yes &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp;, the network device profile which i have chosen is our custom profile pointing to our x86-based nas-server with radius-client in it and we are planning to use dacl in our own way. Is it like cisco-ise will send dacl only to known/predefined set of network-devices-profiles like HP/Aruba/Cisco/Ruckus ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;i have tried changing network-device-profile to Cisco, then i could see "DACL name" option under 'common tasks' in authz profile creation. Attached here the screenshot for reference. When i change the network-device-profile to anything other than Cisco , then the dacl option vanishes. Does this mean this dacl feature will work only for cisco devices? If i want to make dacl work for devices other than Cisco, is there some configuration i need to enable while creating new device-profile/device-group or adding device itself?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Feb 2022 17:51:10 GMT</pubDate>
    <dc:creator>ping2balaji</dc:creator>
    <dc:date>2022-02-21T17:51:10Z</dc:date>
    <item>
      <title>'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556515#M572889</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;I am trying to configure downloadable-acl (or dynamic-acl dacl) under authorization profile.&lt;/P&gt;&lt;P&gt;Under 'authorization-&amp;gt;downloadable acls' i have created a dacl with 'permit ip any any' in the name of 'dacl1'.&lt;/P&gt;&lt;P&gt;Then under 'policy -&amp;gt; results -&amp;gt; authorization -&amp;gt; authorization profiles' im trying to create authorization-profile but i am not able to see 'dacl' option under 'common tasks' as described in admin guides of cisco ise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its only 'ACL' option im seeing under 'common tasks' instead.&lt;/P&gt;&lt;P&gt;Am i missing some configuration/steps on why im not getting option to set dacl under authz profile?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please clarify.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;...Balaji.J&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 14:33:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556515#M572889</guid>
      <dc:creator>ping2balaji</dc:creator>
      <dc:date>2022-02-21T14:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556537#M572890</link>
      <description>&lt;P&gt;Can you share a screenshot? It should be there as the first option:&lt;/P&gt;
&lt;DIV id="tinyMceEditor_2424e6287466f7KarstenIwen_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CleanShot 2022-02-21 at 16.11.52@2x.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/144408i05BD08CACEECFC00/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CleanShot 2022-02-21 at 16.11.52@2x.png" alt="CleanShot 2022-02-21 at 16.11.52@2x.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 15:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556537#M572890</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2022-02-21T15:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556599#M572895</link>
      <description>&lt;P&gt;Thanks for the response&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached the screenshot of authz profile for your reference.&lt;/P&gt;&lt;P&gt;I am using cisco ise-eval edition R3.1. Does that makes any difference like evaluation version does not support dacl or something?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also i have tried applying dacl as shown below as a workaround for my test purpose:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Navigate to&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Administration &amp;gt; Identity Management &amp;gt; Identities &amp;gt; Users &amp;gt; Add&lt;/STRONG&gt;&lt;SPAN&gt;. Create a user and configure the custom attribute value with the name of the dACL that the user needs to get when authorized"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The new user i have created got authN success with Access-Accept message but it does not contain this custom-attribute dacl AVP in that msg. Any input here as well will help.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;...Balaji.J&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 16:52:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556599#M572895</guid>
      <dc:creator>ping2balaji</dc:creator>
      <dc:date>2022-02-21T16:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556611#M572897</link>
      <description>&lt;P&gt;What version of ISE? It seems buggy, are you working with TAC? Have you tried other browsers?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 17:00:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556611#M572897</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2022-02-21T17:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556612#M572898</link>
      <description>&lt;P&gt;Your chosen "Network Device Profile" does not support DACLs. What kind of devices are you using? Do they support DACLs?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 17:01:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556612#M572898</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2022-02-21T17:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556619#M572900</link>
      <description>&lt;P&gt;Yes &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp;, the network device profile which i have chosen is our custom profile pointing to our x86-based nas-server with radius-client in it and we are planning to use dacl in our own way. Is it like cisco-ise will send dacl only to known/predefined set of network-devices-profiles like HP/Aruba/Cisco/Ruckus ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;i have tried changing network-device-profile to Cisco, then i could see "DACL name" option under 'common tasks' in authz profile creation. Attached here the screenshot for reference. When i change the network-device-profile to anything other than Cisco , then the dacl option vanishes. Does this mean this dacl feature will work only for cisco devices? If i want to make dacl work for devices other than Cisco, is there some configuration i need to enable while creating new device-profile/device-group or adding device itself?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 17:51:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556619#M572900</guid>
      <dc:creator>ping2balaji</dc:creator>
      <dc:date>2022-02-21T17:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556620#M572901</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using R3.1.0.518 Cisco-Evaluation version. Is there any limitation in eval?&lt;/P&gt;&lt;P&gt;Can you please clarify?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using chrome and also tried in ms-edge. Both places same issue.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;...Balaji.J&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 17:31:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556620#M572901</guid>
      <dc:creator>ping2balaji</dc:creator>
      <dc:date>2022-02-21T17:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556666#M572902</link>
      <description>Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1315694"&gt;@ping2balaji&lt;/a&gt;!&lt;BR /&gt;&lt;BR /&gt;I hope you are doing well!&lt;BR /&gt;&lt;BR /&gt;I think "vendor" attributes are not customizable, but maybe you can use&lt;BR /&gt;your custom profile with vendor "Cisco" and customize RADIUS Dictionaries&lt;BR /&gt;like you wish. Is it not enough for your purposes?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;</description>
      <pubDate>Mon, 21 Feb 2022 20:43:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556666#M572902</guid>
      <dc:creator>tjezer</dc:creator>
      <dc:date>2022-02-21T20:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556795#M572909</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1296770"&gt;@tjezer&lt;/a&gt;&amp;nbsp;, so is it right to assume dacl feature is only for cisco network devices and does not work with any other vendor devices?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 01:51:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4556795#M572909</guid>
      <dc:creator>ping2balaji</dc:creator>
      <dc:date>2022-02-22T01:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4557083#M572912</link>
      <description>&lt;P&gt;It's not that it is only Cisco, but it is not a standard-feature. A vendor has to build its devices to support DACLs. Look at your vendor documentation if they do and if yes, you need to build your own Network device profile to "tell" the ISE how the vendor implements it.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 09:26:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4557083#M572912</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2022-02-22T09:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4557373#M572919</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp;for the clarification.&lt;/P&gt;&lt;P&gt;my vendor support ACLs and they have to be in specific syntax/format. so im writing a intermediate layer which can convert DACLs from cisco ISE during authentication to the ACL format the vendor device understand.&lt;/P&gt;&lt;P&gt;Another&amp;nbsp;intention here to not disturb the existing DACLs configured in cisco acls as we are looking for brownfield deployment with smooth integration into existing network architecture.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So suppose if doctors identityGroup user is connecting through Cisco device then DACLs get downloaded and it will work straightforward. But if the same user(doctor) is connecting through my vendor device, we thought it can still get the DACLs from cisco ISE which are already available and convert into my vendor device format.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As i understand from your reply above is not possible. is that correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i might have to define a new custom AVP in vendor dictionary and define how to encode acls using 5 tuple there so that my vendor device understands. Then create a Network Device Profile using this dictionary to make it work. Is this assumption correct? If yes, we felt the integration won't be smooth as our customer need to define another set of acls for same user in cisco ise for this work. But idea is to leverage DACL feature in cisco ISE for non-cisco vendor. Any suggestion here &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp; please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;...Balaji.J&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 17:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4557373#M572919</guid>
      <dc:creator>ping2balaji</dc:creator>
      <dc:date>2022-02-23T17:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: 'dacl' option not showing in authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4565124#M573260</link>
      <description>&lt;P&gt;ISE 3.1 is the latest version and you have the full capabilites for 90-days free trial/evaluation after every installation.&lt;/P&gt;
&lt;P&gt;Downloadable ACLs are a Cisco-specific feature.&lt;/P&gt;
&lt;P&gt;For all other vendors/products (and some Cisco products!) you typically send an Access Control List &lt;EM&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/EM&gt; to the network device which already has the ACL preconfigured and ready for assignment when it receives the name from ISE.&lt;/P&gt;
&lt;P&gt;Even some Cisco devices do this with &lt;STRONG&gt;Airespace ACL Name&lt;/STRONG&gt; or &lt;STRONG&gt;ACL &amp;nbsp;(Filter-ID) . &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;RADIUS:Filter-ID&lt;/STRONG&gt; is the standard way to send an ACL Name.&lt;/P&gt;
&lt;P&gt;See &lt;LI-MESSAGE title="ISE RADIUS Network Access Attributes" uid="3616253" url="https://community.cisco.com/t5/security-documents/ise-radius-network-access-attributes/m-p/3616253#U3616253"&gt;&lt;/LI-MESSAGE&gt; &amp;gt; &lt;A class="" href="https://community.cisco.com/t5/security-documents/ise-radius-network-access-attributes/ta-p/3616253#toc-hId-1189009796" rel="nofollow noopener noreferrer" target="_blank"&gt;RADIUS&lt;/A&gt;&amp;nbsp; or &lt;A href="https://datatracker.ietf.org/doc/html/rfc2865#page-36" target="_self"&gt;RFC2865&lt;/A&gt;&lt;/P&gt;
&lt;TABLE style="font-size: 8pt;" border="1" cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR valign="top"&gt;
&lt;TD&gt;Filter-ID&lt;/TD&gt;
&lt;TD style="text-align: right;"&gt;11&lt;/TD&gt;
&lt;TD&gt;text&lt;/TD&gt;
&lt;TD&gt;?&lt;/TD&gt;
&lt;TD&gt;Authentication&lt;/TD&gt;
&lt;TD&gt;The name of the filter list for this user. Zero or more Filter-Id attributes MAY be sent in an Access-Accept packet.&lt;BR /&gt;Identifying a filter list by name allows the filter to be used on different NASes without regard to filter-list implementation details.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or there is always&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 04:23:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-option-not-showing-in-authorization-profile/m-p/4565124#M573260</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-03-07T04:23:23Z</dc:date>
    </item>
  </channel>
</rss>

