02-06-2025 10:30 AM
Does anyone know why 2702 don't download an ACL. The scenario I am working with is 9800 17.9.6 flex connect and ISE. All clients use the same SSID. The ACL is 50 lines long and relates to creating a Quarantine area until the user signs on. The issue I have is that the 2702 don't pick up the Acl and the clients go into the exclusion area with ACL failure
In my test area using AP280 I have no issues. The 2702 are in geographically diverse areas in Australia so swapping them out would be difficult
02-06-2025 10:42 AM - edited 02-06-2025 10:53 AM
Just to make sure, you are using Flexconnect Central Switching in both your lab and production? I don't think dACL are supported in local switching. I did see something about 2700's do not support dACL in Flex, but trying to find a link.
The idea behind this document is to demonstrate dACLs usage on Catalyst 9800 through a basic SSID configuration example, showing how these can be fully customizable.
On Catalyst 9800 wireless controller, downloadable ACLs are
Supported for centralized controller with Local mode Access Points only (or Flexconnect central switching). FlexConnect Local Switching does not support dACL.
02-06-2025 10:59 AM
Thanks Scott I haven't explained my scenario well enough. This is where the ACL is on the controller and ICE specifies to use the ACL. So on the Controller you specify Policy ACL on the site and in Policy for the WLAN you specify WAN ACL. In ISE you specify the Airspace ACL which has to match up with the Policy ACL and WLAN ACL. So when the ISE criterion fits the AP restricts access to the particular client. The ACL is sent to the AP's by the controller. This is supported in 17.9.6
02-06-2025 12:35 PM
Ah okay so you are using the named acl not dACL. Have you tried to open a case with TAC?
02-06-2025 01:40 PM
Yes I just wondered if anyone else has had this. I wil update once TAC has comeback
02-06-2025 03:19 PM
The 2700 APs whilst supported on 17.9 code are restricted to features supported on 17.3 code due to them being EOL.
You will most likely find TAC advise that those APs are not supported. I have had that on a few cases
02-10-2025 02:42 PM
Hi
I found an old 2702 and added it to my Test environment. In my Test environment it worked as expected and recieved the ACL. I will do the change again and try and work out why some don't
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide