<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dacl / ACL enforcement from ISE to Wireless devices in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/dacl-acl-enforcement-from-ise-to-wireless-devices/m-p/4771893#M251430</link>
    <description>&lt;P&gt;DACL is not supported by any WLC as of today.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can refer the below link for how ACL works -&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/81733-contr-acls-rle.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/81733-contr-acls-rle.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regarding ISE and WLC integration with ACL enforcements;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://lihaifeng.net/?p=28" target="_blank"&gt;https://lihaifeng.net/?p=28&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Feb 2023 09:03:00 GMT</pubDate>
    <dc:creator>Arshad Safrulla</dc:creator>
    <dc:date>2023-02-09T09:03:00Z</dc:date>
    <item>
      <title>Dacl / ACL enforcement from ISE to Wireless devices</title>
      <link>https://community.cisco.com/t5/wireless/dacl-acl-enforcement-from-ise-to-wireless-devices/m-p/4771887#M251429</link>
      <description>&lt;P&gt;I am trying to create a ACL to deny access for wired and wireless clients, I am using ISE 3.1 and have 3504 WLC on version 8.10.151.0 . I created a Dacl in ISE and applied it to an authorization profile and it is working as intended but after doing some research it sounds like Dacl only works for wired clients and to enforce it on wireless clients i would need to create an ACL on the WLC. I could not find any good documentation on how to integrate the two. Do I Create the ACL on the WLC under Security-&amp;gt;ACL and then use the same ACL name in the "Airespace ACL Name" field in ISE under authorization policy? If not how do I go about doing this? Is it possible to push the Dacl to the WLC? Or is it possible to push a general ACL out to every WLC with a name ISE recognizes? When I created this student_test_acl on my WLC and then added it to the policy in ISE it seems like it was apply deny ip any any to my device, I'm assuming because it didnt recognize the ACL in ISE? Can anyone point me in the right direction or give me some type of way to leverage ISE's profiling to force an ACL down to wireless clients to prevent IP connectivity to certain addresses? SGT's/RBACL in DNA just seems to apply to port/protocols and not IP's.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 08:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dacl-acl-enforcement-from-ise-to-wireless-devices/m-p/4771887#M251429</guid>
      <dc:creator>jeaju99</dc:creator>
      <dc:date>2023-02-09T08:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dacl / ACL enforcement from ISE to Wireless devices</title>
      <link>https://community.cisco.com/t5/wireless/dacl-acl-enforcement-from-ise-to-wireless-devices/m-p/4771893#M251430</link>
      <description>&lt;P&gt;DACL is not supported by any WLC as of today.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can refer the below link for how ACL works -&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/81733-contr-acls-rle.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/81733-contr-acls-rle.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regarding ISE and WLC integration with ACL enforcements;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://lihaifeng.net/?p=28" target="_blank"&gt;https://lihaifeng.net/?p=28&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 09:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dacl-acl-enforcement-from-ise-to-wireless-devices/m-p/4771893#M251430</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2023-02-09T09:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Dacl / ACL enforcement from ISE to Wireless devices</title>
      <link>https://community.cisco.com/t5/wireless/dacl-acl-enforcement-from-ise-to-wireless-devices/m-p/4771896#M251432</link>
      <description>&lt;P&gt;For the brave ones, it is already supported in on 9800 WLCs version 17.9 for centralised WLANs. But for the OP, the AireOS will never get this feature.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 09:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dacl-acl-enforcement-from-ise-to-wireless-devices/m-p/4771896#M251432</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2023-02-09T09:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Dacl / ACL enforcement from ISE to Wireless devices</title>
      <link>https://community.cisco.com/t5/wireless/dacl-acl-enforcement-from-ise-to-wireless-devices/m-p/4772361#M251466</link>
      <description>&lt;P&gt;Yes - you have the right idea.&amp;nbsp; ACL on the controller and specify in the authorization result on ISE:&lt;/P&gt;&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;Airespace-ACL-Name = Allow_only_good_ACL&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 21:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/dacl-acl-enforcement-from-ise-to-wireless-devices/m-p/4772361#M251466</guid>
      <dc:creator>Wes Schochet</dc:creator>
      <dc:date>2023-02-09T21:38:50Z</dc:date>
    </item>
  </channel>
</rss>

