cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
614
Views
3
Helpful
2
Replies

ISE dACL when switchport has a phone and a computer

mnkojima
Level 1
Level 1

Hello

we are implementing ISE and we authenticate users through MS AD and phones through MAB. We want to enforce authorization by DACL at the access switch. 

My question is: since the DACL is applied at the physical port, it will affect both voice and data traffic. Since in my ISE policy set I have one authZ rule for users and another for phones, would it be possible to apply different DACL's (one for phone and another for computer) at that switchport?

Thank you

Marcos

2 Accepted Solutions

Accepted Solutions

poongarg
Cisco Employee
Cisco Employee

Hi Marcos,

The dACL is applied per session basis. When you connect both the PC and phone, you will see 2 authentication sessions on the switchport when you run the command "show auth session detail interface <>". So you can push different dACL for phone and PC.

HTH

 

View solution in original post

2 Replies 2

poongarg
Cisco Employee
Cisco Employee

Hi Marcos,

The dACL is applied per session basis. When you connect both the PC and phone, you will see 2 authentication sessions on the switchport when you run the command "show auth session detail interface <>". So you can push different dACL for phone and PC.

HTH