cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
641
Views
0
Helpful
4
Replies

DNAC - Templates for ACLs

Positron
Level 1
Level 1

Been struggling with DNAC compliance reporting with ACLs. I have a basic sample ACL that deploys successfully but the compliance in DNAC flags the entire ACL ac non-compliant. I can see the ACL in the config on the switch and in the configuration in DNAC associated with the switch. I've waited, re-ran the compliance over and over with the same results. Any guidance here is greatly welcomed. I've tried this on DNAC version 2.3.3.4 and 2.3.3.5 with the same results. The sequence numbers are indented and the compliance failure includes the 'ip access-list' line. I've tried numbered ACLs with the same results. TIA

!
ip access-list standard Blah
10 permit x.x.x.x
20 permit y.y.y.y
30 deny any log
!

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

thanks for the response. Yes, I am attaching the output. Template-Compliance Failure.jpg

Sorry for the necro-posting, but I just ran into this and I think I can shed some light on it. 

It's the exclamation points and the extra space on line 5. The second column of numbers is showing you the lines that are out of compliance in the template. If you edit your template to remove the blank line and the lines with exclamation points, run the compliance check and it will show as compliant. 

Preston Chilcote
Cisco Employee
Cisco Employee

Unless there are some trailing spaces on one of those lines in your template, I can't tell what the problem is.  Please check for spaces and open a TAC case to see if this might be a bug.