cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
406
Views
0
Helpful
1
Replies

Downloadable ACL Question

kendo.igor
Level 1
Level 1

I have a few questions regarding Downloadable ACL. We are using PIX 515E in conjuction with Cisco ACS 3.0.2

1. Can we implements downloadable acl with TACACS+

2. Usually access lists are bound to an interface. Which interface does the downloadable acl bind to? Since there is no access-group command for it.

3. If a downloadable acl is associated with a user, does the other regular ACLs on the PIX apply to the authenticated user, or the downloadable ACLs will become the sole ACL being applied to that user?

Thanks.

1 Reply 1

bosoro
Cisco Employee
Cisco Employee

To answer your questions:

1. According to 6.2 docs, No... RADIUS only

2. It is bound in the direction of which the user was authenticated/authorized.

i.e. An inside user going outside that gets authenticated going outside, will have his ACL applied to the inside interface, essentially.

3. The per-user ACL overwrites the existing ACL's that are on the PIX for the duration of the users session

Hope that helps

-Bryan