cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
839
Views
0
Helpful
3
Replies

DACL not shown for a NAD

networker4424
Level 1
Level 1

Hello there,

 

I created a NAD profile for Pica8 switch, now when I create an authorization profile I see the ACL and VLAN fields under the common tasks section but there is no DACL field shown. What should I do in my NAD profile to display the DACL field so I can type in my downloadable ACLs.

Thanks!

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

It shows DACL for me when I set Cisco as the vendor in the NAD profile.

Screen Shot 2019-07-20 at 10.31.33.png

View solution in original post

3 Replies 3

hslai
Cisco Employee
Cisco Employee

It shows DACL for me when I set Cisco as the vendor in the NAD profile.

Screen Shot 2019-07-20 at 10.31.33.png

Well it shows DACL for me also when I choose Cisco and vendor but I need DACL to show for a non Cisco device. If any can tell if thats even possible within the Cisco ISE's design would be much apreciated, thanks.
%23%23- Please type your reply above this line -%23%23


________________________________
ali.amjad@pica8.com

This looks by the current design. Downloading DACL entries to the NAD uses Cisco-AVPair, which is a Cisco vendor specific attribute (VSA).

By picking Cisco as the vendor, the NAD profile can still be used by a 3rd-party NAD, but the NAD needs emulate the same Cisco device behavior in order to request for and consume DACLs.