<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization Failure Reason: ACL Failure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authorization-failure-reason-acl-failure/m-p/5300703#M596837</link>
    <description>&lt;P&gt;Hello, I have just run into this issue. Just for the info: I had a DACL with 10 lines, i deleted 4 deny statements, leaving only permit tcp any host xxx . it helped me, so I hope it will help to others. Always check the syntax of DACL and the source always has to be ANY&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jun 2025 09:39:13 GMT</pubDate>
    <dc:creator>mariya.telitsina</dc:creator>
    <dc:date>2025-06-19T09:39:13Z</dc:date>
    <item>
      <title>Authorization Failure Reason: ACL Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failure-reason-acl-failure/m-p/4777523#M579887</link>
      <description>&lt;P&gt;I have a Cisco 3650 on IOS XE 16.12.06 that has some endpoints connected to it and authorizing successfully via MAB.&lt;/P&gt;&lt;P&gt;Here is the issue that has happened multiple times now - Randomly, usually during the middle of the night, these devices will fail with the following error:&lt;/P&gt;&lt;P&gt;%SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (abcd.1234.954a) on Interface GigabitEthernet1/0/5 AuditSessionID 0A98004A000000115673EC93. Failure Reason: ACL Failure. Failed attribute name xACSACLx-IP-ALLOW-627e6a57.&lt;/P&gt;&lt;P&gt;The devices do have a reauthentication timer set and the DACL is pulled from ISE. The DACL is a single line, allowing ipv4 any. The fix action for when this occurs is to just bounce the port - then they will auth successfully.&lt;/P&gt;&lt;P&gt;Does anyone have an idea of what could be causing this random ACL failure?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 15:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failure-reason-acl-failure/m-p/4777523#M579887</guid>
      <dc:creator>Walker</dc:creator>
      <dc:date>2023-02-17T15:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Failure Reason: ACL Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failure-reason-acl-failure/m-p/4777626#M579891</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/485442"&gt;@Walker&lt;/a&gt;&amp;nbsp;, your behavior may be related to the following bug&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz32377" target="_blank"&gt;CSCvz32377&lt;/A&gt;&amp;nbsp;, it would be worthy to verify if with a different version of IOS the behavior improves.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if that helped you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 18:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failure-reason-acl-failure/m-p/4777626#M579891</guid>
      <dc:creator>Rodrigo Diaz</dc:creator>
      <dc:date>2023-02-17T18:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Failure Reason: ACL Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failure-reason-acl-failure/m-p/5300703#M596837</link>
      <description>&lt;P&gt;Hello, I have just run into this issue. Just for the info: I had a DACL with 10 lines, i deleted 4 deny statements, leaving only permit tcp any host xxx . it helped me, so I hope it will help to others. Always check the syntax of DACL and the source always has to be ANY&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 09:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failure-reason-acl-failure/m-p/5300703#M596837</guid>
      <dc:creator>mariya.telitsina</dc:creator>
      <dc:date>2025-06-19T09:39:13Z</dc:date>
    </item>
  </channel>
</rss>

