<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending ACL from ISE to 9800 WLC in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4903715#M259510</link>
    <description>&lt;P&gt;1. The dACL feature is only supported from 17.10.1 onwards - so you'll have to use 17.12.1 if you want to use dACLs.&lt;BR /&gt;2. Check the documentation at&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_dACL.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_dACL.html&lt;/A&gt;&amp;nbsp; That includes a link to the guide for configuring the ACLs on ISE.&amp;nbsp; Have you reviewed that?&lt;/P&gt;</description>
    <pubDate>Fri, 11 Aug 2023 13:19:31 GMT</pubDate>
    <dc:creator>Rich R</dc:creator>
    <dc:date>2023-08-11T13:19:31Z</dc:date>
    <item>
      <title>Sending ACL from ISE to 9800 WLC</title>
      <link>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4530941#M237074</link>
      <description>&lt;P&gt;Hi All-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Migrating from 5520 -&amp;gt; 9800.&amp;nbsp; I have many use cases where ISE is sending the "Airespace-ACL-Name = xxx_ACL" message to enforce an ACL on the client.&amp;nbsp; Looking to implement the same functionality on the 9800.&amp;nbsp; Is this just a standard dACL now?&amp;nbsp; I saw a lot of messages about bugs with dACLs?&amp;nbsp; How do I best implement this functionality?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 15:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4530941#M237074</guid>
      <dc:creator>Wes Schochet</dc:creator>
      <dc:date>2022-01-13T15:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sending ACL from ISE to 9800 WLC</title>
      <link>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4530985#M237082</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - dACL is not yet supported on the 9800 :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvw89561" target="_blank" rel="nofollow noopener noreferrer"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvw89561&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183" target="_blank" rel="nofollow noopener noreferrer"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 16:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4530985#M237082</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-01-13T16:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Sending ACL from ISE to 9800 WLC</title>
      <link>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4531969#M237139</link>
      <description>&lt;P&gt;Yep even in the latest release 17.7.1&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-7/config-guide/b_wl_17_7_cg/m_wlan_9800.html#reference_937F7E4B0BEE4CC79D01B90AF723E192" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-7/config-guide/b_wl_17_7_cg/m_wlan_9800.html#reference_937F7E4B0BEE4CC79D01B90AF723E192&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"Downloadable ACL (DACL) is not supported in the FlexConnect mode or the local mode."&lt;/P&gt;&lt;P&gt;You can configure the ACL on the WLC and get ISE to send the pre-configured ACL name in av-pair.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jan 2022 10:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4531969#M237139</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2022-01-15T10:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Sending ACL from ISE to 9800 WLC</title>
      <link>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4532631#M237223</link>
      <description>&lt;P&gt;Hi Guys,&amp;nbsp;&lt;/P&gt;&lt;P&gt;OP is not referring to Downloadable ACL's and it was not supported in 5520 or any AireOS WLC's. So I guess the problem here is that ACL name sent by ISE.&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt;&amp;nbsp;mentioned you need to make sure that the ACL Name sent by ISE is configured in the WLC, if AP's are in Flexconnect mode you have to make sure that the ACL is pushed to AP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;wireless profile flex FLEX-SITE-20&lt;BR /&gt;acl-policy &lt;U&gt;&lt;STRONG&gt;POSTURE-REDIRECT&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;central-webauth&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;I would also suggest that if the issue persist, post a RA trace for a client who is facing the issue. Or you can analyze the log your self by Wireless debug analzyer.&lt;/P&gt;&lt;P&gt;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;Wireless Debug Analyzer (cisco.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 13:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4532631#M237223</guid>
      <dc:creator>Arshad Safrulla</dc:creator>
      <dc:date>2022-01-17T13:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Sending ACL from ISE to 9800 WLC</title>
      <link>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4532875#M237241</link>
      <description>&lt;P&gt;Thanks - I am attempting to send the ACL name, I can't find any info on what the av-pair is supposed to look like for the Cat controllers,&amp;nbsp; The old style AirOS av-pair does not seem to be working.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 19:26:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4532875#M237241</guid>
      <dc:creator>Wes Schochet</dc:creator>
      <dc:date>2022-01-17T19:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sending ACL from ISE to 9800 WLC</title>
      <link>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4903699#M259505</link>
      <description>&lt;P&gt;did you come up with an answer for this by any chance? I am looking to implement the same thing, but not sure how the av pairs should be formatted etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 12:19:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4903699#M259505</guid>
      <dc:creator>ABM Networking</dc:creator>
      <dc:date>2023-08-11T12:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: Sending ACL from ISE to 9800 WLC</title>
      <link>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4903715#M259510</link>
      <description>&lt;P&gt;1. The dACL feature is only supported from 17.10.1 onwards - so you'll have to use 17.12.1 if you want to use dACLs.&lt;BR /&gt;2. Check the documentation at&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_dACL.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/m_dACL.html&lt;/A&gt;&amp;nbsp; That includes a link to the guide for configuring the ACLs on ISE.&amp;nbsp; Have you reviewed that?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 13:19:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/sending-acl-from-ise-to-9800-wlc/m-p/4903715#M259510</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-08-11T13:19:31Z</dc:date>
    </item>
  </channel>
</rss>

