<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to create ACLs? in Controllers</title>
    <link>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429332#M1827</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the hint. Unfortunately, I cannot find an answer to my problem in this lab as it only covers QoS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;Kind regards,&lt;/P&gt;&lt;P style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;Dominik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Nov 2016 14:10:14 GMT</pubDate>
    <dc:creator>paradoxxl</dc:creator>
    <dc:date>2016-11-16T14:10:14Z</dc:date>
    <item>
      <title>Is it possible to create ACLs?</title>
      <link>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429330#M1825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I’ve played around APIC-EM for a few days now, especially discovering the API. I used postman and the go-apic-em library (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://github.com/jbogarin/go-apic-em" rel="nofollow" target="_blank"&gt;https://github.com/jbogarin/go-apic-em&lt;/A&gt;&lt;SPAN&gt;). At the beginning, I was confused by the naming similarities with cisco APIC which is a total different technology. Therefore, I had some wrong expectations as I thought it was SDN like in APIC/ACI.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my semester project, I need to evaluate APIC-EM and Onos (OpenFlow Controller) to build a classical campus network. Therefore, creating ACL or more general ‘policies’ is crucial. I understand it it possible to create QoS Policies, but &lt;STRONG&gt;is it also possible to create ACL with APIC-EM and are there any examples if yes? Or do I have to switch to another product from the ‘ONE’-portfolio?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first thought I had was using a DENY-Action when creating a policy (v1) via API. Unfortunately, I could not find the permitted values for the actions in the policy API and ‘DENY’ does not seem to work. I also checked the documents I found on the cisco website, but I was unable to find a clear description for the capabilities of APIC-EM, especially the word ‘policy’ they often use in the descriptions and videos.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Dominik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2019 12:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429330#M1825</guid>
      <dc:creator>paradoxxl</dc:creator>
      <dc:date>2019-03-01T12:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create ACLs?</title>
      <link>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429331#M1826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please take a look this learning lab see if you can find what you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://learninglabs.cisco.com/lab/apic-em-policy/step/1" title="https://learninglabs.cisco.com/lab/apic-em-policy/step/1"&gt;Cisco DevNet Learning Labs&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2016 17:25:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429331#M1826</guid>
      <dc:creator>yawming</dc:creator>
      <dc:date>2016-11-14T17:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create ACLs?</title>
      <link>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429332#M1827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the hint. Unfortunately, I cannot find an answer to my problem in this lab as it only covers QoS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;Kind regards,&lt;/P&gt;&lt;P style="font-size: 12px; font-family: arial; color: #3d3d3d;"&gt;Dominik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2016 14:10:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429332#M1827</guid>
      <dc:creator>paradoxxl</dc:creator>
      <dc:date>2016-11-16T14:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create ACLs?</title>
      <link>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429333#M1828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried create policy example ? You can create policy single policy with your application and push ACL down to network device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may need to change attributes in JSON.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"actions":[&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "PERMIT"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"actions":[&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "DENY"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;I tried to change the actions from&amp;nbsp; "SET_PROPERTY" to "DENY" but it fail ( "SET_PROPERTY" is OK)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2016 15:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429333#M1828</guid>
      <dc:creator>yawming</dc:creator>
      <dc:date>2016-11-16T15:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create ACLs?</title>
      <link>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429334#M1829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACL are not supported in policy in 1.3.&amp;nbsp; We did have them in EFT code.&lt;/P&gt;&lt;P&gt;The policy model will be extended next year&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Nov 2016 18:01:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429334#M1829</guid>
      <dc:creator>aradford</dc:creator>
      <dc:date>2016-11-16T18:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create ACLs?</title>
      <link>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429335#M1830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the clarification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there another product of the cisco ONE-portfolio which is yet able do distribute ACL? APIC/ACI can clearly do it, but we would need nexus switches for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Dominik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Nov 2016 08:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429335#M1830</guid>
      <dc:creator>paradoxxl</dc:creator>
      <dc:date>2016-11-17T08:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create ACLs?</title>
      <link>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429336#M1831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There's the possibility to use Cisco ISE with Downloadable ACLs. (ACL based on Radius)&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010011.html?bookSearch=true#task_D2F097D1BD834D8DBA0FDF02DF9F1297" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_010011.html?bookSearch=true#task_D2F097D1BD834D8DBA0FDF02DF9F1297"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.1&amp;nbsp; - Manage Authorization Policies and Profiles [Cisco Ide…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then there's APIs on Cisco Prime Infra for using templates (ACL based on CLI commands)&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/migration-blogpost/7993"&gt;Template based provisioning with Cisco Prime Infrastructure – Part 1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both products are included when buying Cisco One for Access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Nov 2016 12:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/is-it-possible-to-create-acls/m-p/3429336#M1831</guid>
      <dc:creator>rcsapo</dc:creator>
      <dc:date>2016-11-21T12:53:05Z</dc:date>
    </item>
  </channel>
</rss>

