12-23-2018 11:25 AM
Hi,
I have a Cisco 3850 switch doing dot1x authentication on ports. In the posture unknown state I am pushing a redirect acl and a DACL from the ISE once the user moves to posture unknown state. I have noticed that in the posture unknown state the DACL am is not taking effect. The switch version is 3.6.8. Please help.
Thanks
Solved! Go to Solution.
01-10-2019 07:39 PM
Can you share plz the output of show authe sess int gx/x/x detail?
I had same issue for CWA. You can do a quick test by doing a ping from your machine to 8.8.8.8.
I believe your ACL is blocking ICMP and there just to redirect traffic to posture, am I right?
If ping works even if ACL is blocking, I highly suggest to open a TAC.
In my case, we're pushing the redirect acl (already configured on the switch) + dACL. The switch doesn't take into consideration any acl when it comes to do some kind of redirect. However, if you push an acl on a normal dot1x or mab authentication, then this acl is enforced.
12-23-2018 06:28 PM
Hi Shabeeb,
Refer to the below link and let me know if that helps..
12-23-2018 11:59 PM
12-31-2018 03:09 AM
Take debug epm all debug from the switch & check whether dacl is applied or not.
01-10-2019 06:43 PM
Do you have a base_acl configured on the port that will be overridden by your dacl? Also, ensure that you have enabled device tracking.
01-10-2019 07:39 PM
Can you share plz the output of show authe sess int gx/x/x detail?
I had same issue for CWA. You can do a quick test by doing a ping from your machine to 8.8.8.8.
I believe your ACL is blocking ICMP and there just to redirect traffic to posture, am I right?
If ping works even if ACL is blocking, I highly suggest to open a TAC.
In my case, we're pushing the redirect acl (already configured on the switch) + dACL. The switch doesn't take into consideration any acl when it comes to do some kind of redirect. However, if you push an acl on a normal dot1x or mab authentication, then this acl is enforced.
08-25-2019 09:10 PM
Guys, how did you resolve the issue?
we are having the same issue.
please share workaround! Thanks
08-26-2019 12:13 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide