cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
235
Views
0
Helpful
2
Replies

ISE dacl differnet than what switch is applying

Chris S
Level 1
Level 1

Deploying ISE and trying to finalize some restrictions.  It seems the DACL defined in ISE is not what the switch is applying to the port. Any ideas why the switch is changing the deny statements? 

  • ISE 3.1 (patch
  • C1000-8FP-E-2G-L

Here is what we have defined in ISE:

ise_dacl.jpg

Here is what the switch is applying:

sw_dacl.jpg

1 Accepted Solution

Accepted Solutions

@Chris S use the wildcard not the subnet mask when configuring the DACL.

RobIngram_0-1704378645343.png

Also you can use Check DACL Syntax to confirm the syntax is correct.

 

View solution in original post

2 Replies 2

@Chris S use the wildcard not the subnet mask when configuring the DACL.

RobIngram_0-1704378645343.png

Also you can use Check DACL Syntax to confirm the syntax is correct.

 

That was it - the syntax was valid against the ISE checker with a standard subnet.