cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1546
Views
0
Helpful
2
Replies

ISE DACL entry limitation on ASA VPN device?

Attila Horvath
Level 1
Level 1

Hi, 

Is there any limitation for DACL entries (or size) when Cisco ASA 5515 (ver 9.2(4) connect to  ISE 1.4 ?

We saw a 24 (!) entry limit in practice, but cannot found any  written value from cisco.

 

Is there?

 

Attila Horvath

2 Replies 2

Attila Horvath
Level 1
Level 1

Just to note, the trouble caused by a firewall (Zorp) between NAD and ISE node.

Now (we change the rule at firewall to a simplest one) we can see more than 64 entries sent by ISE to NAD.

Can you clarify the workaround was there a firewall between ISE and the ASA you were pushing the dacl to?

Thanks,