08-28-2021 12:56 AM - edited 08-28-2021 01:07 AM
My C9800 software 17.3.3 and ISE 2.7p4, then wlc is fabric mode.
I check the Configuration Guide, I have config named authorization network method list.
I test wire connect is noproblan for DACL,But test connect wireless SSID fail,erro log bleow:
Aug 28 14:55:30: %CLIENT_EXCLUSION_SERVER-5-ADD_TO_BLACKLIST_REASON_DYNAMIC: Chassis 1 R0/0: wncmgrd: Client MAC: 9cb6.d093.5251 was added to exclusion list associated with AP Name:10F-AP04, BSSID:MAC: 70f0.xxxx.xxxx, reason:ACL failure
Aug 28 14:55:30: %SESSION_MGR-5-FAIL: Chassis 1 R0/0: wncd: Authorization failed or unapplied for client (9cb6.d093.5251) on Interface capwap_900001a6 AuditSessionID D2C416AC000011E08B8AB8EA. Failure Reason: ACL Failure. Failed attribute name #ACSACL#-IP-DENY_ALL_IPV4_10.86.59.7-61289be5.
This is c9800 config guid:
There are ISE and C9800 config picture in attachment file.
Is this my config issue?
Solved! Go to Solution.
08-28-2021 02:30 AM
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvw89561
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183
M.
08-28-2021 02:30 AM
- FYI : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvw89561
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv16183
M.
08-28-2021 04:24 AM
DACL is not supported officially in 9800 platforms as per TAC.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide