<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Preauth acl cuts out connectivity in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5300312#M596813</link>
    <description>&lt;P&gt;When the last ACE (permit ip any any) is removed, devices lose connectivity despite having a dACL (permit ip any any). This suggests the dACL is not overriding the pre-auth ACL correctly. Compare configurations between the two switches, verify ACL enforcement in show authentication sessions, check RADIUS logs, and use debugging (debug dot1x all and debug aaa authentication) to investigate further. If needed, modify the dACL to test different access scenarios.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jun 2025 10:41:36 GMT</pubDate>
    <dc:creator>crystal99roberts</dc:creator>
    <dc:date>2025-06-18T10:41:36Z</dc:date>
    <item>
      <title>Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5300268#M596811</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I have configured pre auth acl on C1000 switch. This acl looks like:&lt;BR /&gt;10 permit xxx&lt;BR /&gt;20 permit xxx&lt;BR /&gt;...&lt;BR /&gt;100 permit ip any any&lt;/P&gt;&lt;P&gt;When I delete last ace devices lost connectivity except services included in preauth acl. That would be absolutely normal, but devices are authenticated and have assigned dacl with only one ace permit ip any any. It does not matter if it is printer authenticated via mab or user authenticated via dot1x.&lt;/P&gt;&lt;P&gt;I have another one C1000 switch with simmilar config and software and there everything works fine. What is wrong and how to troubleshoot it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;SW-Branch1#sh auth sess int g1/0/5 det
            Interface:  GigabitEthernet1/0/5
          MAC Address:  0020.6b44.3e58
         IPv6 Address:  Unknown
         IPv4 Address:  10.203.20.236
            User-Name:  00-20-6B-44-3E-58
               Status:  Authorized
               Domain:  DATA
       Oper host mode:  multi-auth
     Oper control dir:  in
      Session timeout:  N/A
      Restart timeout:  N/A
Periodic Acct timeout:  N/A
       Session Uptime:  3720s
    Common Session ID:  0ACB1409000001FF87ADBD89
      Acct Session ID:  0x000029F8
               Handle:  0x2700005B
       Current Policy:  POLICY_Gi1/0/5

Local Policies:
        Service Template: DEFAULT_LINKSEC_POLICY_SHOULD_SECURE (priority 150)

Server Policies:
              ACS ACL:  xACSACLx-IP-ACL_PRINTER-6257f002

Method status list:
      Method            State

      dot1x              Stopped
      mab                Authc Success

SW-Branch1#sh ip access-lists xACSACLx-IP-ACL_PRINTER-6257f002
Extended IP access list xACSACLx-IP-ACL_PRINTER-6257f002 (per-user)
    1 permit ip any any
SW-Branch1#&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 07:45:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5300268#M596811</guid>
      <dc:creator>koukourde</dc:creator>
      <dc:date>2025-06-18T07:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5300308#M596812</link>
      <description>&lt;P&gt;You push ACL line or name of ACL from AAA server ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 10:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5300308#M596812</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-18T10:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5300312#M596813</link>
      <description>&lt;P&gt;When the last ACE (permit ip any any) is removed, devices lose connectivity despite having a dACL (permit ip any any). This suggests the dACL is not overriding the pre-auth ACL correctly. Compare configurations between the two switches, verify ACL enforcement in show authentication sessions, check RADIUS logs, and use debugging (debug dot1x all and debug aaa authentication) to investigate further. If needed, modify the dACL to test different access scenarios.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 10:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5300312#M596813</guid>
      <dc:creator>crystal99roberts</dc:creator>
      <dc:date>2025-06-18T10:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301001#M596858</link>
      <description>&lt;P&gt;I'm not sure what you asking, it is standard dacl from ise&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 06:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301001#M596858</guid>
      <dc:creator>koukourde</dc:creator>
      <dc:date>2025-06-20T06:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301917#M596901</link>
      <description>&lt;P&gt;It sounds like a tricky situation with the preauth ACL affecting connectivity. Double-checking the ACL rules and ensuring they’re applied correctly is a good start. Sometimes, small misconfigurations can lead to issues like this. If possible, testing in a controlled environment might help narrow down the problem. Hope this helps, and good luck resolving it!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 09:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301917#M596901</guid>
      <dc:creator>ainajohn96</dc:creator>
      <dc:date>2025-06-24T09:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301923#M596903</link>
      <description>&lt;P&gt;The SW have preauth ACL&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After the Authc success ISE push named and ACL line of dACL to SW&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now SW will use dACL instead of preauthc ACL.&lt;/P&gt;
&lt;P&gt;In end SW will use one ACL per one direction.&lt;/P&gt;
&lt;P&gt;That normal I dont see issue' permit any any allow all traffic inlcude that allow in preauth.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 10:03:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301923#M596903</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-24T10:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301979#M596906</link>
      <description>&lt;P&gt;I disagree there is no issue. Preauth acl is configured for inbound direction on switchport.&lt;BR /&gt;&lt;BR /&gt;After successful authentication dacl should override preauth-acl, but it does not. After successful authentication devices have limited access included in preauth acl (permit ip any any in preauth acl is temporary) instead of full acces according to dacl.&lt;BR /&gt;&lt;BR /&gt;I identified this issue at 3 branches, rest of them (about 15) works fine. Most of them have tha same switch and the same ios version. Configuration is simmilar, differences are only vlans and ip addresses.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 12:22:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301979#M596906</guid>
      <dc:creator>koukourde</dc:creator>
      <dc:date>2025-06-24T12:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301984#M596907</link>
      <description>&lt;P&gt;In issue with SW change host mode to be single-host and check&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 12:32:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301984#M596907</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-24T12:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301996#M596908</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1888771"&gt;@koukourde&lt;/a&gt;&amp;nbsp;is authorisation command configured on the switch? - "aaa authorization network default group radius"&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 13:02:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5301996#M596908</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-06-24T13:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5302250#M596916</link>
      <description>&lt;P&gt;No luck, this change didn't help.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 06:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5302250#M596916</guid>
      <dc:creator>koukourde</dc:creator>
      <dc:date>2025-06-25T06:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5302271#M596918</link>
      <description>&lt;P&gt;Of course, authn and authz works fine.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 07:43:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5302271#M596918</guid>
      <dc:creator>koukourde</dc:creator>
      <dc:date>2025-06-25T07:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5302334#M596926</link>
      <description>&lt;P&gt;Add this command ""single-host"" in new port of switch with issue' and check.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 10:34:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5302334#M596926</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-25T10:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5302357#M596927</link>
      <description>&lt;P&gt;This command does not work or I don't get it. Current port config as below, before i changed&amp;nbsp;authentication host-mode multi-auth to authentication host-mode single-host.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; switchport access vlan 220
 switchport mode access
 switchport nonegotiate
 switchport port-security maximum 3
 switchport port-security aging time 15
 switchport port-security
 ip access-group ACL_PRE_AUTH in
 no logging event link-status
 authentication control-direction in
 authentication event fail action next-method
 authentication event server dead action authorize
 authentication event server dead action authorize voice
 authentication event server alive action reinitialize
 authentication host-mode multi-auth
 authentication open
 authentication order dot1x mab
 authentication priority dot1x mab
 authentication port-control auto
 authentication periodic
 authentication timer reauthenticate server
 mab
 snmp trap mac-notification change added
 snmp trap mac-notification change removed
 dot1x pae authenticator
 dot1x timeout tx-period 10
 spanning-tree portfast edge
 spanning-tree bpduguard enable
 ip dhcp snooping limit rate 100&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 25 Jun 2025 11:36:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5302357#M596927</guid>
      <dc:creator>koukourde</dc:creator>
      <dc:date>2025-06-25T11:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5302436#M596933</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="flow of trouble shot.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/246978i7779D84BCCAC971C/image-size/large?v=v2&amp;amp;px=999" role="button" title="flow of trouble shot.png" alt="flow of trouble shot.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 13:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5302436#M596933</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-25T13:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Preauth acl cuts out connectivity</title>
      <link>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5304332#M597030</link>
      <description>&lt;P&gt;Ip device tracking command didn't solve issue.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2025 11:44:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/preauth-acl-cuts-out-connectivity/m-p/5304332#M597030</guid>
      <dc:creator>koukourde</dc:creator>
      <dc:date>2025-07-01T11:44:25Z</dc:date>
    </item>
  </channel>
</rss>

