<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pushing object groups dACLs through ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/5299780#M596786</link>
    <description>&lt;P&gt;I am finding through my research and to much disappointment, that the device has to support the addrgroup version of object-groups, what I mean by this is look at the how the object-groups are displayed after creating them in the switch... or rather, look at how you would implement an ACL using object-groups on the switch... for example on the 68xx I'm using the addrgroup pushed down from ISE and it's working, but when I try to create an object-group ACL on that same device, it doesn't use the traditional&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;permit ip any object-group TEST_LIMIT_GROUP log-input&lt;BR /&gt;&lt;BR /&gt;but rather&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;permit ip any addrgroup TEST_LIMIT_GROUP log-input&lt;BR /&gt;&lt;BR /&gt;on all my other devices I'm having issues using the dACL with the object-groups because those devices require the object-group statement, not the addrgroup statement. I'm continuing to validate, but that's what I've found so far...&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jun 2025 21:26:53 GMT</pubDate>
    <dc:creator>richard bedwell</dc:creator>
    <dc:date>2025-06-16T21:26:53Z</dc:date>
    <item>
      <title>Pushing object groups dACLs through ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307363#M566137</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to push dACLs containing object groups to the switch? Do I need to configure the object groups locally on the switch or can it be pushed too?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My main goal is to minimize the amount of ACEs, in order to do so I want to group a few services into an object group and then apply the ACL on it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 09:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307363#M566137</guid>
      <dc:creator>orp</dc:creator>
      <dc:date>2021-03-15T09:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing object groups dACLs through ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307372#M566139</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/477820"&gt;@orp&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Good question !! I have never found any Cisco's document having any information regarding this but I have a very poor experience with these object-groups on switch and routers. While checking I have found that on ISE 2.1 and later, you can create a DACL with object-group such as "&lt;EM&gt;permit tcp any addrgroup myobject&lt;/EM&gt;" and you need to create these object groups locally on switches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to recommend using them in a test environment first as they are never get tested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;***Please mark all helpful posts***&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 09:51:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307372#M566139</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2021-03-15T09:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing object groups dACLs through ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307380#M566140</link>
      <description>&lt;P&gt;Thanks for the answer! Seems like checking it on a test environment will be necessary indeed.&lt;/P&gt;&lt;P&gt;Just to make sure - In case I'll apply a dACL like this - "&lt;EM&gt;permit tcp any addrgroup myobject"&amp;nbsp;&lt;/EM&gt;and&amp;nbsp;&lt;EM&gt;"myobject"&amp;nbsp;&lt;/EM&gt;contains 3 different hosts, it will count as 1 ACE for the 64 ACEs limit, right?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 10:11:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307380#M566140</guid>
      <dc:creator>orp</dc:creator>
      <dc:date>2021-03-15T10:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing object groups dACLs through ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307386#M566141</link>
      <description>&lt;P&gt;Yes, that is true.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 10:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307386#M566141</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2021-03-15T10:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing object groups dACLs through ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307413#M566142</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/477820"&gt;@orp&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;please take a look: &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj94873/" target="_blank" rel="noopener"&gt;CSCvj94873 Add possibility to use object groups in DACL on ISE&lt;/A&gt; ...&lt;/P&gt;&lt;PRE&gt;Last Modified: Mar 10,2020&lt;BR /&gt;Status: Open&lt;BR /&gt;Severity: 6 Enhancement&lt;BR /&gt;Symptom: Currently ISE allows to create the DACL only in the format supported by switches (i.e. the source should be 'any', object groups are not allowed, etc.).&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 11:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307413#M566142</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-03-15T11:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing object groups dACLs through ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307799#M566161</link>
      <description>&lt;P&gt;Please read the &lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_self"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt; which does a good job of documenting switch configuration including pushing dACLs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: disc; margin-left: 15px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-785487082" rel="nofollow noopener noreferrer" target="_blank"&gt;Pre-Authentication and Post-Authentication Access Control with Low Impact&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId--892884662" rel="nofollow noopener noreferrer" target="_blank"&gt;Switch Configuration for Low Impact Mode&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId--212826292" rel="nofollow noopener noreferrer" target="_blank"&gt;Downloadable ACL Authorization&lt;/A&gt;&lt;/LI&gt;
&lt;LI style="list-style-type: disc; margin-left: 30px; margin-bottom: 1px;"&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId--2020280755" rel="nofollow noopener noreferrer" target="_blank"&gt;Validating ACL Authorization/Low-Impact Mode&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 21:32:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/4307799#M566161</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-03-15T21:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Pushing object groups dACLs through ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/5299780#M596786</link>
      <description>&lt;P&gt;I am finding through my research and to much disappointment, that the device has to support the addrgroup version of object-groups, what I mean by this is look at the how the object-groups are displayed after creating them in the switch... or rather, look at how you would implement an ACL using object-groups on the switch... for example on the 68xx I'm using the addrgroup pushed down from ISE and it's working, but when I try to create an object-group ACL on that same device, it doesn't use the traditional&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;permit ip any object-group TEST_LIMIT_GROUP log-input&lt;BR /&gt;&lt;BR /&gt;but rather&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;permit ip any addrgroup TEST_LIMIT_GROUP log-input&lt;BR /&gt;&lt;BR /&gt;on all my other devices I'm having issues using the dACL with the object-groups because those devices require the object-group statement, not the addrgroup statement. I'm continuing to validate, but that's what I've found so far...&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 21:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-object-groups-dacls-through-ise/m-p/5299780#M596786</guid>
      <dc:creator>richard bedwell</dc:creator>
      <dc:date>2025-06-16T21:26:53Z</dc:date>
    </item>
  </channel>
</rss>

