cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1574
Views
7
Helpful
4
Replies

Authorization Profiles

sajid231088
Beginner
Beginner

Hi All,

 

I am confused in, When to use dACL, ACL, VLAN and Airespace ACL.

 

Can anyone explain use of all above, I know what is ACL, What is VLAN etc etc but confused in when and what should use.

 

Regards

Sajid

2 Accepted Solutions

Accepted Solutions

Hi,
An ACL is statically configured on a switch, you would create an Authorization rule to apply the statically configured ACL to a users sessions. This is not scalable as the same ACL would need to be defined on all switches (which could be 100s or 1000s). However a DACL (Downloadable ACL) is configured once on ISE, this DACL is defined in an Authorization Profile, downloaded to the switch and applied to a users session. This means you do not need to create the same ACL on all switches.

Airespace ACL is related to WLC, this does not support DACL so you have to reference the Airespace ACL in the Authorization Profile.

HTH

View solution in original post

Aravind Ravichandran
Participant
Participant

Hi Sajid,

Dynamic VLAN Assignment: One of the traditional means of limiting network access is by putting endpoints in different VLANs based on their role.ISE can authorize endpoints to specific VLANs either by the VLAN name or number. 
IP Access Control Lists (ACLs): ACLs can be used to control network access at the port level. ACLs can either be downloaded to the network from ISE or be configured locally on the switch and be referenced by ISE during authorization. Named ACL authorization can be done with RADIUS standard attribute called the ‘Filter-ID’ with the ACL name. For ACL downloads, either Per-User-ACL or Downloadable ACL (dACLs) can be used. Both these ACL download options use Cisco custom RADIUS Attribute Value Pair (AVP). The per-User ACL is limited by a size of 4000 characters, while downloadable ACLs do not have a limit on its size. However the practical recommendation for dACLs are 64 Access Control Entries (ACE)s.

Airespace ACL: These ACLs can be used to control network access at Wireless endpoints & these acls are need to configured at WLC.Named Airespace ACL authorization can be done with RADIUS standard attribute called the ‘Airespace ACL’ with the ACL name.However Airespace ACL are limited to 64 ACL entries.

Note: DACLs are applicable with switches & Firewalls not with Wireless controller.

-Aravind

View solution in original post

4 Replies 4

Hi,
An ACL is statically configured on a switch, you would create an Authorization rule to apply the statically configured ACL to a users sessions. This is not scalable as the same ACL would need to be defined on all switches (which could be 100s or 1000s). However a DACL (Downloadable ACL) is configured once on ISE, this DACL is defined in an Authorization Profile, downloaded to the switch and applied to a users session. This means you do not need to create the same ACL on all switches.

Airespace ACL is related to WLC, this does not support DACL so you have to reference the Airespace ACL in the Authorization Profile.

HTH

Hi,

 

Thanks for your prompt response.

Now i have a clarity on this.

 

 

Aravind Ravichandran
Participant
Participant

Hi Sajid,

Dynamic VLAN Assignment: One of the traditional means of limiting network access is by putting endpoints in different VLANs based on their role.ISE can authorize endpoints to specific VLANs either by the VLAN name or number. 
IP Access Control Lists (ACLs): ACLs can be used to control network access at the port level. ACLs can either be downloaded to the network from ISE or be configured locally on the switch and be referenced by ISE during authorization. Named ACL authorization can be done with RADIUS standard attribute called the ‘Filter-ID’ with the ACL name. For ACL downloads, either Per-User-ACL or Downloadable ACL (dACLs) can be used. Both these ACL download options use Cisco custom RADIUS Attribute Value Pair (AVP). The per-User ACL is limited by a size of 4000 characters, while downloadable ACLs do not have a limit on its size. However the practical recommendation for dACLs are 64 Access Control Entries (ACE)s.

Airespace ACL: These ACLs can be used to control network access at Wireless endpoints & these acls are need to configured at WLC.Named Airespace ACL authorization can be done with RADIUS standard attribute called the ‘Airespace ACL’ with the ACL name.However Airespace ACL are limited to 64 ACL entries.

Note: DACLs are applicable with switches & Firewalls not with Wireless controller.

-Aravind

Hi Aravind,

 

Thanks for your detailed explanation, Now i have more clarity on this.

 

Regards

Sajid

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: