07-01-2016 02:35 PM - edited 03-10-2019 11:54 PM
Is there a size limitation on DACLs? Is there a way to create something like an object group within DACLs so they are not so large?
07-02-2016 01:11 AM
There are different limitations that can apply based on RADIUS and the switch-model:
07-05-2016 10:09 AM
Thank you both very much. This is great information.
06-18-2024 06:32 AM
While I don't make a normal practice of correcting old entries in the Cisco community, I discovered the info provided in this thread is not correct and appears to be the predominant response still returned by some search engines when asking the question about dACL size limits.
For additional references on this topic, see:
07-02-2016 07:37 AM
To add to the the great info already provided by Karsten:
- The DACLs should be kept short and simple. I have done many ISE deployments and 99% of the time the DACLs did not exceed 4 lines
- If DACLs start growing out of control then you should consider TrustSect/SGA/SGT
- Also, while not ideal, you can use VLAN override and then perform restriction(s) on a distribution type switch, Firewall, etc.
I hope this helps!
Thank you for rating helpful posts!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide