cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2743
Views
0
Helpful
1
Replies

3850 command to show wireless user dACL

Mason Tu
Level 1
Level 1

Hi,

I am using 3850 and 5760 with converged access mode.

There is also ISE to provide dACL for wireless user.

In 3850, I can issue "show access-list" to see the dACL from ISE.

But I can't be sure which ACL apply to which user when there are more than one dACL.

I have tried command like "show wireless client mac-address MAC detail" but didn't see anything related.

I can only achieve that by checking logs on ISE.

Is there any command I can do for this purpose?

3850 and 5760 version : 3.3.0

ISE version : 1.2

Thanks!!!

1 Accepted Solution

Accepted Solutions

Patrick Meyer
Level 1
Level 1

Hi Mason,

I know that for switch IOS the command "show authentication session interface INTERFACE" shows the dACL that is applied to this port. I think the new command for the IOSXE devices is "show access-session mac H.H.H detail" is the corresponding one which should show the dACL that was applied to that MAC-address.

 

Please see if that works for you.

 

Best regards,

Patrick Meyer

View solution in original post

1 Reply 1

Patrick Meyer
Level 1
Level 1

Hi Mason,

I know that for switch IOS the command "show authentication session interface INTERFACE" shows the dACL that is applied to this port. I think the new command for the IOSXE devices is "show access-session mac H.H.H detail" is the corresponding one which should show the dACL that was applied to that MAC-address.

 

Please see if that works for you.

 

Best regards,

Patrick Meyer

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card