I have configured a 350 wireless card and 2-350 AP's for LEAP authentication with ACS 3.1 and all works fine authenticating to both AP's. I want to test the ability to deny access to one of the AP's using NAR's. I have added the NAR to the group I am in and even with the "allowed" AP turned off it still let's me authenticate to the "disallowed" one. The passed authentication log says that all access filters have passed. After that I added the rule to my group to deny access from all IP to all AAA clients and it still let's me authenticate. Any ideas?