cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
317
Views
1
Helpful
5
Replies

igmp in ISE DACL syntax check fail

tachyon05
Level 1
Level 1

I get a syntax check error when the ISE DACL has permit igmp any 224.0.0.0 15.255.255.255.  The ACL is accepted and works on a switch if statically configured.  However, ISE syntax check gives the below error.  Any suggestions?

"permit igmp any 224.0.0.0 15.255.255.255", argument #2 "igmp" is not valid. Legal option(s):
icmp
ip
tcp
udp
1
4
6
17

5 Replies 5

marce1000
VIP
VIP

 

 - Similar to these https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&kw=argument%20not%20valid%20dacl&bt=custV&sb=anfr&prdNam=Cisco%20Identity%20Services%20Engine%20Software  it seems lack of functionality : what ISE version are you on ?

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

only change the igmp with IP 
in end you permit IP but this IP is multicast you dont permit any L4 ports

MHM

tachyon05
Level 1
Level 1

ISE 3.2 patch 4.  
Are you saying to use permit IP any 224.0.0.0 15.255.255.255 instead?  I take this is secure because the IGMP IP range is not routable on the public internet, and we don't care about which ports are used, and therefore permitting IP instead of IGMP to this network range allows IGMP traffic but doesn't give end points much of anything else, correct?

Yoh are correct, let me double check

What is SW platform you have and IOS ver. 

MHM

tachyon05
Level 1
Level 1

Version 17.9.4a on C9606R