<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dACL only works after a clear access-session in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217849#M592866</link>
    <description>&lt;P&gt;Hi Together&lt;/P&gt;
&lt;P&gt;Thanks for the many replies!&lt;BR /&gt;I found the problem (It's a stupid fault from my site)&lt;BR /&gt;The Clients couldn't get any ip address. In the ACL I allow connection to the dhcp.&lt;BR /&gt;But for dhcp the Client tries with a broadcast address.&lt;/P&gt;
&lt;P&gt;I just hat to add: permit udp any any eq 67.&lt;/P&gt;
&lt;P&gt;I didn't saw it first because this devices only has a web UI (which wasn't reachable)&lt;BR /&gt;Also there APIPPA Looks like the old address from the dhcp a.a.20.13 -&amp;gt; 169.254.20.13&lt;BR /&gt;&lt;BR /&gt;I really appreciate your help and I am sorry for your loss of time.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Oct 2024 06:48:56 GMT</pubDate>
    <dc:creator>User42</dc:creator>
    <dc:date>2024-10-31T06:48:56Z</dc:date>
    <item>
      <title>dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217217#M592808</link>
      <description>&lt;DIV&gt;Hi&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;ISE: 3.2 Patch 4&lt;/DIV&gt;
&lt;DIV&gt;Switch: C9300-48P mit IOS XE 17.09.04a&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Without dACL:&lt;/DIV&gt;
&lt;DIV&gt;Authorization Policy Result&lt;/DIV&gt;
&lt;DIV&gt;Result: Access-Accept&lt;/DIV&gt;
&lt;DIV&gt;Vlan: 12&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Device gets plugged in:&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; ISE:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Correct Policy and correct result&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Switch:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Client Authorized, vlan 12&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Client:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; ping a.a.a.a -&amp;gt; successfull&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; ping b.b.b.b -&amp;gt; successfull&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;With dACL:&lt;/DIV&gt;
&lt;DIV&gt;Authorization Policy Result&lt;/DIV&gt;
&lt;DIV&gt;Result: Access-Accept&lt;/DIV&gt;
&lt;DIV&gt;Vlan: 12&lt;/DIV&gt;
&lt;DIV&gt;dACL:&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; permit ip any host a.a.a.a&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; deny ip any any&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Device Plugged in:&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; ISE:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Correct Policy, correct result and dACL Download successful&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Switch:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Client Authorized, vlan 12, dACL download complete and mapped to interface&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Client:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; ping a.a.a.a -&amp;gt; not successfull&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; ping b.b.b.b -&amp;gt; not successfull&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;If I clear the access-session with clear access-session on the switch:&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; ISE:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Correct Policy, correct result and dACL Download successful&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Switch:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Client Authorized, vlan 12, dACL download complete and mapped to interface&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; Client:&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; ping a.a.a.a -&amp;gt; successfull&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt; ping b.b.b.b -&amp;gt; not successfull&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;If the client is unplugged and plugged in again, the ping tests are again unsuccessful.&lt;/DIV&gt;
&lt;DIV&gt;The dACL only seems to work correctly after a clear access session.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;I looked in Cisco's BST but didn't find anything.&lt;/DIV&gt;
&lt;DIV&gt;Does anyone have an idea?&lt;/DIV&gt;</description>
      <pubDate>Wed, 30 Oct 2024 08:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217217#M592808</guid>
      <dc:creator>User42</dc:creator>
      <dc:date>2024-10-30T08:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217231#M592809</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1637380"&gt;@User42&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I believe this is an expect behavior and you need to use CoA to overcome this. Take a look on the below thread and there are lots of similar threads here in the forum.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/coa-session-reauth-required-after-successful-authentication/td-p/4158220" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/coa-session-reauth-required-after-successful-authentication/td-p/4158220&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 09:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217231#M592809</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-10-30T09:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217236#M592810</link>
      <description>&lt;P&gt;I think here it is another problem because I'm not speaking of Guest Access.&lt;BR /&gt;These Clients I described authenticate with dot1x EAP-TLS.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 09:23:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217236#M592810</guid>
      <dc:creator>User42</dc:creator>
      <dc:date>2024-10-30T09:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217240#M592811</link>
      <description>&lt;P&gt;&lt;SPAN&gt;permit ip any host a.a.a.a &amp;lt;&amp;lt;- remove this&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Add&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Permit ip any any &amp;lt;&amp;lt;-&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And let device tracking adjust any&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 09:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217240#M592811</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-30T09:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217242#M592812</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Here are a number of related bugs with DACL&amp;nbsp; , which include your ISE version :&lt;BR /&gt;&amp;nbsp; &amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&amp;amp;prdNam=Cisco%20Identity%20Services%20Engine%203.2&amp;amp;kw=dacl%203.2&amp;amp;bt=custV&amp;amp;sb=anfr" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&amp;amp;prdNam=Cisco%20Identity%20Services%20Engine%203.2&amp;amp;kw=dacl%203.2&amp;amp;bt=custV&amp;amp;sb=anfr&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Check if anything related comes up ; it's probably advisable to test with the latest patch for ISE 3.&lt;U&gt;&lt;STRONG&gt;2&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp;&lt;STRONG&gt;(p7)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 09:31:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217242#M592812</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-10-30T09:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217244#M592813</link>
      <description>&lt;P&gt;Thanks for the reply!&lt;BR /&gt;With permit ip any any it works.&lt;BR /&gt;But then I cloud just use no dACL&lt;BR /&gt;&lt;BR /&gt;The Goal is this:&lt;/P&gt;
&lt;DIV&gt;&lt;SPAN&gt;ping a.a.a.a -&amp;gt; successfull&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;ping b.b.b.b -&amp;gt; not successfull&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;I want that the Client only can reach his server.&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 30 Oct 2024 09:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217244#M592813</guid>
      <dc:creator>User42</dc:creator>
      <dc:date>2024-10-30T09:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217734#M592858</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;I would check for dACL related bugs on that ISE version. Second, do you have "&lt;STRONG&gt;epm logging&lt;/STRONG&gt;" to validate that dACL is actually correctly applied on the port via "&lt;STRONG&gt;show logging&lt;/STRONG&gt;"?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 21:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217734#M592858</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2024-10-30T21:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217837#M592864</link>
      <description>&lt;P&gt;This issue' how ISE know that this is user a.a.a.a or user b.b.b.b to assign correct dacl?&lt;/P&gt;
&lt;P&gt;Instead push in dacl permit ip any any&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And try use ACL in port connect to server or use vlan access list.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 06:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217837#M592864</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-31T06:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217849#M592866</link>
      <description>&lt;P&gt;Hi Together&lt;/P&gt;
&lt;P&gt;Thanks for the many replies!&lt;BR /&gt;I found the problem (It's a stupid fault from my site)&lt;BR /&gt;The Clients couldn't get any ip address. In the ACL I allow connection to the dhcp.&lt;BR /&gt;But for dhcp the Client tries with a broadcast address.&lt;/P&gt;
&lt;P&gt;I just hat to add: permit udp any any eq 67.&lt;/P&gt;
&lt;P&gt;I didn't saw it first because this devices only has a web UI (which wasn't reachable)&lt;BR /&gt;Also there APIPPA Looks like the old address from the dhcp a.a.20.13 -&amp;gt; 169.254.20.13&lt;BR /&gt;&lt;BR /&gt;I really appreciate your help and I am sorry for your loss of time.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 06:48:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217849#M592866</guid>
      <dc:creator>User42</dc:creator>
      <dc:date>2024-10-31T06:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217869#M592869</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; By enabling the logging i've recommended, you would have seen that dACL was not actually applied because hosts had no IP address that switch can make use of before applying the dACL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; Good you fixed it.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 08:16:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217869#M592869</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2024-10-31T08:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: dACL only works after a clear access-session</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217886#M592870</link>
      <description>&lt;P&gt;with respect to your solution&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how ISE know this endpoint is a.a.a.a or b.b.b.b&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this can only done via dhcp profiling&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 07:45:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-only-works-after-a-clear-access-session/m-p/5217886#M592870</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-31T07:45:28Z</dc:date>
    </item>
  </channel>
</rss>

