<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dACL don't working properly in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282727#M596007</link>
    <description>&lt;P&gt;this new style mode are you sure about both SW use new mode ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Fri, 18 Apr 2025 12:38:58 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-04-18T12:38:58Z</dc:date>
    <item>
      <title>dACL don't working properly</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282337#M596001</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am writing you about a issue i am facing.&lt;/P&gt;&lt;P&gt;After credentials validation on Cisco ISE captive portal our Cisco 2960 witch receive a dACL to users port.&lt;/P&gt;&lt;P&gt;However after almost 30 seconds the port lose dACL configuration.&lt;/P&gt;&lt;P&gt;As you can see below&lt;/P&gt;&lt;P&gt;show access-session interface gigabitEthernet 1/0/6 details&lt;BR /&gt;Interface: GigabitEthernet1/0/6&lt;BR /&gt;MAC Address:&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address:&lt;BR /&gt;User-Name: rnsh5697&lt;BR /&gt;Status: Authorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Session Uptime: 38s&lt;BR /&gt;Common Session ID: AC1C8EA20000B52CC86E1B21&lt;BR /&gt;Acct Session ID: 0x0000B4ED&lt;BR /&gt;Handle: 0x2D000084&lt;BR /&gt;Current Policy: CISCO_ISE&lt;/P&gt;&lt;P&gt;Server Policies:&lt;BR /&gt;ACS ACL: xACSACLx-IP-Remediation-dacl-67beffcf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show access-session interface gigabitEthernet 1/0/6 details&lt;BR /&gt;Interface: GigabitEthernet1/0/6&lt;BR /&gt;MAC Address:&lt;BR /&gt;IPv6 Address: Unknown&lt;BR /&gt;IPv4 Address:&lt;BR /&gt;User-Name: rnsh5697&lt;BR /&gt;Status: Unauthorized&lt;BR /&gt;Domain: DATA&lt;BR /&gt;Oper host mode: multi-domain&lt;BR /&gt;Oper control dir: both&lt;BR /&gt;Session timeout: N/A&lt;BR /&gt;Restart timeout: N/A&lt;BR /&gt;Periodic Acct timeout: N/A&lt;BR /&gt;Session Uptime: 161s&lt;BR /&gt;Common Session ID: AC1C8EA20000B52CC86E1B21&lt;BR /&gt;Acct Session ID: 0x0000B4ED&lt;BR /&gt;Handle: 0x2D000084&lt;BR /&gt;Current Policy: CISCO_ISE&lt;/P&gt;&lt;P&gt;Method status list:&lt;BR /&gt;Method State&lt;/P&gt;&lt;P&gt;dot1x Stopped&lt;BR /&gt;mab Authc Success&lt;/P&gt;&lt;P&gt;Do you have a idea how i can fix this problem ?&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 13:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282337#M596001</guid>
      <dc:creator>DA587</dc:creator>
      <dc:date>2025-04-17T13:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: dACL don't working properly</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282690#M596004</link>
      <description>&lt;P&gt;You share two authc session' first one is not complete.&lt;/P&gt;
&lt;P&gt;Also the different between two authc session is one is authz and other not authz' can I see port config&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 10:49:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282690#M596004</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-18T10:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: dACL don't working properly</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282709#M596005</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;You will find below port configuration.&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/6&lt;BR /&gt;switchport access vlan 105&lt;BR /&gt;switchport mode access&lt;BR /&gt;access-session host-mode multi-domain&lt;BR /&gt;access-session port-control auto&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;service-policy type control subscriber CISCO_ISE&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;show policy-map type control subscriber CISCO_ISE&lt;BR /&gt;CISCO_ISE&lt;BR /&gt;event session-started match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 authenticate using dot1x priority 10&lt;BR /&gt;20 authenticate using mab priority 20&lt;/P&gt;&lt;P&gt;I use the same configuration on other switch and i have not encountered this problem.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 12:09:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282709#M596005</guid>
      <dc:creator>DA587</dc:creator>
      <dc:date>2025-04-18T12:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: dACL don't working properly</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282727#M596007</link>
      <description>&lt;P&gt;this new style mode are you sure about both SW use new mode ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 12:38:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282727#M596007</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-18T12:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: dACL don't working properly</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282754#M596009</link>
      <description>&lt;P&gt;Yes, both use new mode.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 14:29:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5282754#M596009</guid>
      <dc:creator>DA587</dc:creator>
      <dc:date>2025-04-18T14:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: dACL don't working properly</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5284204#M596056</link>
      <description>&lt;P&gt;I checked by my side the log.&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I noticed an uninstallation of Dacl after about 1 minute&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Apr 16 09:29:59 172.28.142.162 EPM_SESS_EVENT: ACL xACSACLx-IP-Remediation-dacl-67beffcf provisioning successful&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Apr 16 09:30:25 172.28.142.162 EPM_SESS_EVENT: Feature (EPM MISC PLUG-IN) identity has been updated (status 1)&lt;/P&gt;&lt;P&gt;Apr 16 09:30:25 172.28.142.162 EPM_SESS_EVENT: Feature (SM ACCOUNTING PLUG-IN) identity has been updated (status 1)&lt;/P&gt;&lt;P&gt;Apr 16 09:30:25 172.28.142.162 EPM_SESS_EVENT: Received Mac [246a.0ea2.7413]&lt;/P&gt;&lt;P&gt;Apr 16 09:30:25 172.28.142.162 EPM_SESS_EVENT: Received audit-session-id [AC1C8EA20000B52CC86E1B21]&lt;/P&gt;&lt;P&gt;Apr 16 09:30:25 172.28.142.162 EPM_SESS_EVENT: Received IDB [GigabitEthernet1/0/6]&lt;/P&gt;&lt;P&gt;Apr 16 09:30:25 172.28.142.162 EPM_SESS_EVENT: Received IPv4 [10.242.3.99]&lt;/P&gt;&lt;P&gt;Apr 16 09:30:25 172.28.142.162 EPM_SESS_EVENT: Feature (EPM ACL PLUG-IN) identity has been updated (status 0)&lt;/P&gt;&lt;P&gt;Apr 16 09:30:51 172.28.142.162 EPM_SESS_EVENT: Feature (EPM ACL PLUG-IN) Status (2) Notified&lt;/P&gt;&lt;P&gt;Apr 16 09:30:51 172.28.142.162 EPM_SESS_EVENT: Successful feature attrs provided for EPM MISC PLUG-IN&lt;/P&gt;&lt;P&gt;Apr 16 09:30:51 172.28.142.162 EPM_SESS_EVENT: Successful feature attrs provided for SM ACCOUNTING PLUG-IN&lt;/P&gt;&lt;P&gt;Apr 16 09:30:51 172.28.142.162 EPM_SESS_EVENT: Successful feature attrs provided for EPM ACL PLUG-IN&lt;/P&gt;&lt;P&gt;Apr 16 09:30:51 172.28.142.162 EPM_SESS_EVENT: Feature (EPM MISC PLUG-IN) has been terminated&lt;/P&gt;&lt;P&gt;Apr 16 09:30:51 172.28.142.162 EPM_SESS_EVENT: Feature (SM ACCOUNTING PLUG-IN) has been terminated&lt;/P&gt;&lt;P&gt;Apr 16 09:30:51 172.28.142.162 EPM_SESS_EVENT: Feature (EPM ACL PLUG-IN) has been terminated&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Apr 16 09:30:51 172.28.142.162 EPM_SESS_EVENT: Un-Installing Named ACL xACSACLx-IP-Remediation-dacl-67beffcf session_ctx F3A2CD0 feat_ctx EF80968 feat_conf F4ED158&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 09:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5284204#M596056</guid>
      <dc:creator>DA587</dc:creator>
      <dc:date>2025-04-23T09:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: dACL don't working properly</title>
      <link>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5284390#M596066</link>
      <description>&lt;P&gt;There is bug about number of line of ACL' try reduce number of line of dacl if you use many lines.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 17:05:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dacl-don-t-working-properly/m-p/5284390#M596066</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-23T17:05:47Z</dc:date>
    </item>
  </channel>
</rss>

