cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6231
Views
10
Helpful
2
Replies

C9800L ACL Fail when ISE use DACL

Ziv
Level 1
Level 1

My C9800 software 17.3.3  and ISE 2.7p4, then wlc is fabric mode.

I check the Configuration Guide, I have config named authorization network method list.

I test wire connect is noproblan for DACL,But test connect wireless SSID fail,erro log bleow:

Aug 28 14:55:30: %CLIENT_EXCLUSION_SERVER-5-ADD_TO_BLACKLIST_REASON_DYNAMIC: Chassis 1 R0/0: wncmgrd: Client MAC: 9cb6.d093.5251 was added to exclusion list associated with AP Name:10F-AP04, BSSID:MAC: 70f0.xxxx.xxxx, reason:ACL failure
Aug 28 14:55:30: %SESSION_MGR-5-FAIL: Chassis 1 R0/0: wncd: Authorization failed or unapplied for client (9cb6.d093.5251) on Interface capwap_900001a6 AuditSessionID D2C416AC000011E08B8AB8EA. Failure Reason: ACL Failure. Failed attribute name #ACSACL#-IP-DENY_ALL_IPV4_10.86.59.7-61289be5.

 

This is c9800 config guid:

https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_conf_ipv4_acl_ewlc.html

 

There are ISE and C9800 config picture in attachment file.

Is this my config issue?

 

 

 

 

 

1 Accepted Solution

Accepted Solutions

marce1000
Hall of Fame
Hall of Fame

 

 - FYI https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvw89561

           https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

View solution in original post

2 Replies 2

marce1000
Hall of Fame
Hall of Fame

 

 - FYI https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvw89561

           https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Arshad Safrulla
VIP Alumni
VIP Alumni

DACL is not supported officially in 9800 platforms as per TAC.

Review Cisco Networking for a $25 gift card