<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE 1.2 Checking DACL Syntax in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473232#M87454</link>
    <description>&lt;P&gt;Greetings, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we first set up all of the DACLs for our ISE deployment, it was explained to us that the "!" was a replacement for the "remark" entry on the access list, but when I utilize the "Check DACL Syntax", ISE tells me that my statements are improper:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;Line 13 - In "! permit tcp any any eq 80", argument #1 "!" is not valid. Legal option(s):&lt;/P&gt;&lt;P&gt;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&amp;nbsp; deny&lt;/P&gt;&lt;P&gt;&amp;nbsp; remark&lt;/P&gt;&lt;P&gt;&amp;nbsp; no&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesn't appear that my DACLs are giving any errors when is use, so is this just an &lt;SPAN style="font-size: 10pt;"&gt;aesthetic error or do I need to go through and change all fo my DACLs to reflect this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thank You for any input!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:30:09 GMT</pubDate>
    <dc:creator>David Pease</dc:creator>
    <dc:date>2019-03-11T04:30:09Z</dc:date>
    <item>
      <title>Cisco ISE 1.2 Checking DACL Syntax</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473232#M87454</link>
      <description>&lt;P&gt;Greetings, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we first set up all of the DACLs for our ISE deployment, it was explained to us that the "!" was a replacement for the "remark" entry on the access list, but when I utilize the "Check DACL Syntax", ISE tells me that my statements are improper:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;Line 13 - In "! permit tcp any any eq 80", argument #1 "!" is not valid. Legal option(s):&lt;/P&gt;&lt;P&gt;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&amp;nbsp; deny&lt;/P&gt;&lt;P&gt;&amp;nbsp; remark&lt;/P&gt;&lt;P&gt;&amp;nbsp; no&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesn't appear that my DACLs are giving any errors when is use, so is this just an &lt;SPAN style="font-size: 10pt;"&gt;aesthetic error or do I need to go through and change all fo my DACLs to reflect this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thank You for any input!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:30:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473232#M87454</guid>
      <dc:creator>David Pease</dc:creator>
      <dc:date>2019-03-11T04:30:09Z</dc:date>
    </item>
    <item>
      <title>It is an incorrect format for</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473233#M87462</link>
      <description>&lt;P&gt;It is an incorrect format for ISE , please refer correct format from&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_authz_polprfls.html#wp1231465&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 07:24:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473233#M87462</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-03-10T07:24:29Z</dc:date>
    </item>
    <item>
      <title>Salodh,  While I appreciate</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473234#M87470</link>
      <description>&lt;P&gt;Salodh,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While I appreciate that you took the time to reply to me, your response does not actually address my question, and the link you provided does not discuss the "Remark" command at all. &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please feel free to re-read my question, and provide additional assistance if you are able.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 13:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473234#M87470</guid>
      <dc:creator>David Pease</dc:creator>
      <dc:date>2014-03-11T13:45:12Z</dc:date>
    </item>
    <item>
      <title>While IOS allows the use of</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473235#M87474</link>
      <description>&lt;P&gt;While IOS allows the use of the ! character instead of "remark", ISE does not, and as a result you get the warning message you're seeing.&lt;/P&gt;&lt;P&gt;Javier Henderson&lt;/P&gt;&lt;P&gt;Cisco Systems&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2014 15:50:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473235#M87474</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2014-03-14T15:50:15Z</dc:date>
    </item>
    <item>
      <title>Hello David,I guess there are</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473236#M87480</link>
      <description>&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;I guess there are many more keywords and format that "check DACL syntax" doesn't approve but they do work. A customer wanted to use a keyword ESTABLISHED so I created an ACE and clicked save.&lt;/P&gt;&lt;P&gt;"permit tcp any any established"&lt;/P&gt;&lt;P&gt;It gives me a pop-up stating "syntax check of the DACL content has failed, do you want to submit anyway.&lt;/P&gt;&lt;P&gt;I clicked yes and moved ahead. I then check the dacl syntax and it says&lt;/P&gt;&lt;P&gt;Line 1 - In "permit tcp any any established", argument #5 "established" is not valid.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finally, I &amp;nbsp;tested this on dot1x configured switch and the output of 'show ip access-list interface &amp;lt;interface-id&amp;gt;' shows it in downloaded access-list. Even though the syntax was not approved by the ISE we still manage to download it to the switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case if you are using remarks with dot1x and mab, please keep a watch on this defect&lt;/P&gt;&lt;P&gt;CSCuj35704 &amp;nbsp; &amp;nbsp;Remark in DACL causing dot1x and MAB authorization failure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jatin Katyal&lt;/P&gt;&lt;P&gt;**Do rate helpful posts**&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Mar 2014 00:44:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-2-checking-dacl-syntax/m-p/2473236#M87480</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-03-16T00:44:39Z</dc:date>
    </item>
  </channel>
</rss>

