<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE - downloadable ACL (dACL) and Layer 2 switch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963215#M585304</link>
    <description>&lt;P&gt;I already answered you&lt;/P&gt;
&lt;P&gt;dACL apply as port acl (filters l3 ans l2 traffic) to l2 port.&lt;/P&gt;
&lt;P&gt;So dACL work with l2 switch.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Nov 2023 19:47:56 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-11-20T19:47:56Z</dc:date>
    <item>
      <title>Cisco ISE - downloadable ACL (dACL) and Layer 2 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963213#M585303</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;
&lt;P&gt;I'm new at Cisco ISE and I've been working on some quarantine options.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my example, I used Authorization Profile with dACL with result Acess-Accept and&amp;nbsp;&lt;STRONG&gt;deny&amp;nbsp;ip&amp;nbsp;any any. &lt;/STRONG&gt;Then I've&amp;nbsp;attached it to the host via Adaptive Network Control. &lt;BR /&gt;It worked, however, since this is L3 dACL, I'm still missing how switch is able to handle IP based information? My understanding of dACL is that ISE will push it to the access switch, which is in the most cases L2. How can it work then?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 19:45:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963213#M585303</guid>
      <dc:creator>Script Kiddie</dc:creator>
      <dc:date>2023-11-20T19:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - downloadable ACL (dACL) and Layer 2 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963215#M585304</link>
      <description>&lt;P&gt;I already answered you&lt;/P&gt;
&lt;P&gt;dACL apply as port acl (filters l3 ans l2 traffic) to l2 port.&lt;/P&gt;
&lt;P&gt;So dACL work with l2 switch.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 19:47:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963215#M585304</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-11-20T19:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - downloadable ACL (dACL) and Layer 2 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963228#M585307</link>
      <description>&lt;P&gt;Hello, thanks for the answer. I've created new discussion for this particular topic.&lt;BR /&gt;Can you please explain it more from the low-level?&lt;BR /&gt;How can L2 switch process L3 information, since it works with MACs only? Does it have something to do with TCAM?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 19:59:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963228#M585307</guid>
      <dc:creator>Script Kiddie</dc:creator>
      <dc:date>2023-11-20T19:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - downloadable ACL (dACL) and Layer 2 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963232#M585308</link>
      <description>&lt;P&gt;L2 SW can process l3 via not software like router but via tcam but it cannot routing l3 packet.&lt;/P&gt;
&lt;P&gt;Can l3 sw also use dacl? Yes it can also&lt;/P&gt;
&lt;P&gt;From Cisco doc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;""&amp;nbsp;&lt;/P&gt;
&lt;H3 class="p_H_Head2"&gt;Understanding Port ACLs&lt;/H3&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1106234" target="_blank"&gt;&lt;/A&gt;The port ACL (PACL) feature provides the ability to perform access control on specific Layer 2 ports. A Layer 2 port is a physical LAN or trunk port that belongs to a VLAN. Port ACLs are applied only on the ingress traffic. The port ACL feature is supported only in hardware (port ACLs are not applied to any packets routed in software).&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1116275" target="_blank"&gt;&lt;/A&gt;When you create a port ACL, an entry is created in the ACL TCAM. You can use the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;show tcam counts&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command to see how much TCAM space is available.&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1121113" target="_blank"&gt;&lt;/A&gt;The PACL feature does not affect Layer 2 control packets received on the port.""&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 20:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963232#M585308</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-11-20T20:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - downloadable ACL (dACL) and Layer 2 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963577#M585318</link>
      <description>&lt;P&gt;Got it, thanks.&lt;BR /&gt;So from my understanding, I have to make sure that I have L2 switch that &lt;STRONG&gt;has TCAM &lt;/STRONG&gt;so its able to work with dACL.&lt;/P&gt;
&lt;P&gt;Dumb question now, since it has TCAM, if I push dACL&amp;nbsp;&lt;STRONG&gt;ip deny any &lt;/STRONG&gt;to the switch, the host should not be able to communicate with others even on the same VLAN, right?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 09:27:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963577#M585318</guid>
      <dc:creator>Script Kiddie</dc:creator>
      <dc:date>2023-11-21T09:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - downloadable ACL (dACL) and Layer 2 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963585#M585319</link>
      <description>&lt;P&gt;Yes it should that.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 09:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-downloadable-acl-dacl-and-layer-2-switch/m-p/4963585#M585319</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-11-21T09:33:06Z</dc:date>
    </item>
  </channel>
</rss>

