DACL dont apply

For some user create dACL
only_default_router
permit icmp any host 192.168.100.1
permit tcp any host 192.168.100.1
deny ip any any
After user log in windows i found logs on switch
001867: *Mar 16 22:03:58.196: %PARSER-5-CFGLOG_LOGGEDCMD: User:console  logged command:ip access-list extended xACSACLx-IP-only_default_router-51ded09c
001868: *Mar 16 22:03:58.204: %PARSER-5-CFGLOG_LOGGEDCMD: User:console  logged command:permit icmp any host 192.168.100.1
001869: *Mar 16 22:03:58.221: %PARSER-5-CFGLOG_LOGGEDCMD: User:console  logged command:ip access-list extended xACSACLx-IP-only_default_router-51ded09c
001870: *Mar 16 22:03:58.229: %PARSER-5-CFGLOG_LOGGEDCMD: User:console  logged command:permit tcp any host 192.168.100.1
001871: *Mar 16 22:03:58.254: %PARSER-5-CFGLOG_LOGGEDCMD: User:console  logged command:ip access-list extended xACSACLx-IP-only_default_router-51ded09c
001872: *Mar 16 22:03:58.254: %PARSER-5-CFGLOG_LOGGEDCMD: User:console  logged command:deny ip any any
001873: *Mar 16 22:03:58.405: %AUTHMGR-5-SUCCESS: Authorization succeeded for client (000c.29d6.02a6) on Interface Gi1/0/2 AuditSessionID C0A8641E00000034511FC4B0
001874: *Mar 16 22:03:58.422: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/2, changed state to up
001875: *Mar 16 22:03:59.429: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/2, changed state to up
But on interface apply Auth-Default-ACL and what is why all traffic block.
And on interface I found
ISE-SWITCH#show ip interface gigabitEthernet 1/0/2
GigabitEthernet1/0/2 is up, line protocol is up
  Inbound  access list is Auth-Default-ACL
Why my dACL not apply?

Hello Alexey,
check if the IOS version and hardware platform (switch) you're using is mentioned in TrustSec document (page 6):
http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/TrustSec_2.0/trustsec_2.0_dig.pdf
I  had the same problem and it turned out that I had to upgrade the  switch, because the IOS version I used wasn't fully supported. The  minimum IOS version to use with ISE should be 12.2(55), but generally  it's better to use 15.x.
Also,  check if you have configured everything that is recommended for switch  devices in TrustSec (page 59), including "ip device tracking".
There's also a very nice document for troubleshooting:
"Cisco TrustSec How-To Guide: Failed Authentications and Authorizations"
http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns744/docs/howto_81_troubleshooting_failed_authc.pdf

Similar Messages

  • Standby database dont  apply the logs

    Hi,
    since we had a power failure, the standby database dont
    apply the logs. Can someone advise me plaese.
    Thanks

    Fetching gap sequence for thread 1, gap sequence 41018-41054
    Trying FAL server: DB1
    Failed to request gap sequence. Thread #: 1, gap sequence: 41018-41054
    All FAL server has been attempted.
    Attempt to start background Managed Standby Recovery process
    MRP0 started with pid=14
    MRP0: Background Managed Standby Recovery process started
    Starting datafile 1 recovery in thread 1 sequence 41018
    Datafile 1: '/oracle/DB1/database/data/DB1_SYSTEM01.dbf'
    Starting datafile 2 recovery in thread 1 sequence 41018
    Datafile 2: '/oracle/DB1/database/data/DB1_UNDO01.dbf'
    Starting datafile 3 recovery in thread 1 sequence 41018
    Datafile 3: '/oracle/DB1/database/data/DB1_D01_DATA01.dbf'
    Starting datafile 4 recovery in thread 1 sequence 41018
    Datafile 4: '/oracle/DB1/database/data/DB1_I01_DATA01.dbf'
    Starting datafile 5 recovery in thread 1 sequence 41018
    Datafile 5: '/oracle/DB1/database/data/DB1_D01_DATA02.dbf'
    Wed Aug 12 17:08:13 2009
    Completed: alter database recover managed standby database di
    Wed Aug 12 17:08:13 2009
    Media Recovery Waiting for thread 1 seq# 41018
    Fetching gap sequence for thread 1, gap sequence 41018-41054
    Trying FAL server: DB1
    Wed Aug 12 17:09:54 2009
    Restarting dead background process QMN0
    QMN0 started with pid=9
    Wed Aug 12 17:10:59 2009
    Failed to request gap sequence. Thread #: 1, gap sequence: 41018-41054
    All FAL server has been attempted.
    Wed Aug 12 17:15:06 2009
    Restarting dead background process QMN0

  • Apple Mail Rules dont apply when mail is READ on other devices!

    Hi,
    I use IMAP settings on Apple Mail (v4.5) and also check my emails on the iPhone (iPhone also set up with IMAP). However if i have read an email on the iPhone then when i switch my computer on the incoming Apple Mail Rule that applies to that sender does not seem to work. It keeps the mail within my Inbox and does not transfer the mail/message to the desired folder.
    However, if the same sender sends me an email which i do not read on the iPhone and then switch my Apple Mail ON, then the mail is automatically transferred to the desired folder.
    It looks like the problem is only with READ mail and not UNREAD mail. 
    Is there a fix for this? There seems to be a lot of people having the same issue and was wondering if there is any work around on this?
    Would really appreciate any help from anyone on this.
    Regards,
    Jay
    PS: I recently moved from Outlook 2011 on MAC to Apple Mail as i heard is a far superior mail application and works smoothly. So far everything about Apple Mail has been correct, it is a fantastic app, however this Rule problem is pretty basic and surprised that Apple still has not fixed this.

    Hi Glenn,
    Many thanks for this. Unfortunately i dont have this facility on the server as we are using a simple opensource mail delivery and storage service, so the rules would have to be set up on the computer.
    I was using Outlook 2011 and prior that was using Entourage 2008 and both worked well with the IMAP rules. Nothing was ommitted and everything READ or UNREAD was imported and the rules applied. It's only in Apple Mail that these rules dont seem to work.
    Is there no other work around? No Apple Mail Add-Ins? I see quite a number of people complaining about the same problem and i'm surprise that Apple has not found a solution for this.
    Anyway, thank you soo much for your reply. Much appreciated.
    Regards,
    Jay

  • ICACLS permissions set... but dont apply without change something in the ACL by hand

    Hello guys,
    I wrote a script for setting up permission on fileserver resources.
    icacls \\server\Client1 /grant "Browsing Group":(S,RD,X,RA,REA,R)
    icacls \\server\Client1\Supervisor /grant "Special Permission This folder only Group":(X,RD,RA,REA,WD,AD,WA,WEA,DC,RC)
    icacls \\server\Client1\Supervisor /grant "Special Permission Subfolder and files
    Group":(OI)(CI)(IO)(M,DC)
    So browsing rights working fine... But the user can´t see the folder Supervisor...(I see the applied perissions on the ACL on folder Supervisor)
    If I add a  custom group/user by hand to the ACL on Supervisor the user are able to see the folder and also have the needed permissions.
    I can also uncheck one special perission from a applied group, add it again and click on OK... then the user are able to see the folder and also have the needed permissions.
    Thank you in advance.
    Kind regards,
    Tim
    MCITP, MCTS, MCSA
    http://directoryadmin.blogspot.com
    This posting is provided 'AS IS' with no warranties or guarantees and confers no rights.
    "If this thread answered your question, please click on "Mark as Answer"

    Hi Tim,
    Would you please tell us how many users have this issue?
    I suggest you uncheck all the permissions on this folder manually, then use
    icacls command to test again.
    If some other groups contain some specific users, and these groups are assigned
    Deny access permissions, then these users cannot access the file. That’s because
    Deny permissions’ precedence is higher than Allow, also,
    explicit permissions’ precedence is higher than inherited ones.
    Therefore, please check other groups and the explicit permissions on this folder.
    Here are some related links below:
    How Permissions Work
    http://technet.microsoft.com/en-us/library/cc783530(v=WS.10).aspx
    How IT worksNTFS Permissions
    http://technet.microsoft.com/en-us/magazine/2005.11.howitworksntfs.aspx
    Best Regards,
    Amy Wang

  • NTFS permission dont apply

    Hi Everyone
    So, i have been having this weird issue where i simply haven't been able to find a reason or acceptable workaround.
    So the problem is as follow, we use DFS to share a bunch of folders in the company, this works like a charm, The share permissions are usually "domain users" or "Everyone" and then controlled at the NTFS permission level. On NTFS permission
    level the group "Domain Admins" are allowed Full Control in the root of the share and the different groups are given the permission they require.
    So far, so good, everything works:
    Now let's say i hire a new employee for the IT department, i add the user to Domain Admin (the group that already have the Full Control permission on the folder). I then go to properties to check on the effective Access permissions for this specifik new user,
    and everything looks great. However, when he tries to access to folder the following error shows.
    "Windows Cannot access \\<share>
    You do not have permissions to access <share>, contact your network administrator to request access"
    This applies to every new user created after the permissions are set. Have anyone seen an issue like this before? Or have an idea on how this can be fixed?
    All the help is highly appreciated.
    Yours Faithfully Martin

    Hello Martin,
    This is a forum for SQL Server - Security, you should post your question to a more Windows related Forum.
    And beside NTFS permissions we have additional permission on the share itself:
    Olaf Helper
    [ Blog] [ Xing] [ MVP]

  • DACL does not get downloaded to Cisco Switch from ISE

    Hello,
    I have a cisco switch with ios: c3550-ipbasek9-mz.122-44.SE6.bin
    I am trying to push dACL fro my ISE device into the switch, but it is not getting applied to switch.   dynamic vlan assignment workds fine, but dACL doesnot apply
    Any instruction plz?

    Hi Jatin,
    ISE is properly configured for dACL,   i think there is some compatibility issue on cisco switch ios.
    following is the debug output>>
    06:36:43: dot1x-packet:Received an EAP packet on interface FastEthernet0/11
    06:36:43: EAPOL pak dump rx
    06:36:43: EAPOL Version: 0x1  type: 0x0  length: 0x0006
    06:36:43: dot1x-packet:Received an EAP packet on the FastEthernet0/11 from mac 0019.b981.e812
    06:36:43: dot1x-sm:Posting EAPOL_EAP on Client=1D68028
    06:36:43:     dot1x_auth_bend Fa0/11: during state auth_bend_request, got event 6(eapolEap)
    06:36:43: @@@ dot1x_auth_bend Fa0/11: auth_bend_request -> auth_bend_response
    06:36:43: dot1x-sm:Fa0/11:0019.b981.e812:auth_bend_response_enter called
    06:36:43: dot1x-ev:dot1x_sendRespToServer: Response sent to the server from 0019.b981.e812
    06:36:43: dot1x-sm:Fa0/11:0019.b981.e812:auth_bend_request_response_action called
    06:36:43: RADIUS/ENCODE(00000049):Orig. component type = DOT1X
    06:36:43: RADIUS(00000049): Config NAS IP: 192.168.2.250
    06:36:43: RADIUS/ENCODE(00000049): acct_session_id: 73
    06:36:43: RADIUS(00000049): sending
    06:36:43: RADIUS(00000049): Send Access-Request to 192.168.2.231:1812 id 1645/99, len 267
    06:36:43: RADIUS:  authenticator 5B 61 1D 64 D3 D5 9F AD - 23 E0 11 11 B3 C3 5C 81
    06:36:43: RADIUS:  User-Name           [1]   6   "test"
    06:36:43: RADIUS:  Service-Type        [6]   6   Framed                    [2]
    06:36:43: RADIUS:  Framed-MTU          [12]  6   1500
    06:36:43: RADIUS:  Called-Station-Id   [30]  19  "00-11-5C-6E-5E-0B"
    06:36:43: RADIUS:  Calling-Station-Id  [31]  19  "00-19-B9-81-E8-12"
    06:36:43: RADIUS:  EAP-Message         [79]  8
    06:36:43: RADIUS:   02 7A 00 06 0D 00                 [ z]
    06:36:43: RADIUS:  Message-Authenticato[80]  18
    06:36:43: RADIUS:   A6 AB 5A CA ED B8 B4 1E 36 00 9D AB 1A F6 B9 E0                [ Z6]
    06:36:43: RADIUS:  Vendor, Cisco       [26]  49
    06:36:43: RADIUS:   Cisco AVpair       [1]   43  "audit-session-id=C0A802FA0000006F016B36D8"
    06:36:43: RADIUS:  NAS-Port-Type       [61]  6   Ethernet                  [15]
    06:36:43: RADIUS:  NAS-Port            [5]   6   50011
    06:36:43: RADIUS:  NAS-Port-Id         [87]  18  "FastEthernet0/11"
    06:36:43: RADIUS:  State               [24]  80
    06:36:43: RADIUS:   33 37 43 50 4D 53 65 73 73 69 6F 6E 49 44 3D 43  [37CPMSessionID=C]
    06:36:43: RADIUS:   30 41 38 30 32 46 41 30 30 30 30 30 30 36 46 30  [0A802FA0000006F0]
    06:36:43: RADIUS:   31 36 42 33 36 44 38 3B 33 35 53 65 73 73 69 6F  [16B36D8;35Sessio]
    06:36:43: RADIUS:   6E 49 44 3D 69 73 65 2D 73 65 72 76 65 72 2D 31  [nID=ise-server-1]
    06:36:43: RADIUS:   2F 31 37 31 30 32 35 39 38 38 2F 32 34 3B    [ /171025988/24;]
    06:36:43: RADIUS:  NAS-IP-Address      [4]   6   192.168.2.250
    06:36:43: %LINK-3-UPDOWN: Interface FastEthernet0/11, changed state to up
    06:36:43: RADIUS: Received from id 1645/99 192.168.2.231:1812, Access-Challenge, len 1134
    06:36:43: RADIUS:  authenticator 78 36 A3 38 30 1C F0 7A - 19 83 93 81 B4 6B FF 9E
    06:36:43: RADIUS:  State               [24]  80
    06:36:43: RADIUS:   33 37 43 50 4D 53 65 73 73 69 6F 6E 49 44 3D 43  [37CPMSessionID=C]
    06:36:43: RADIUS:   30 41 38 30 32 46 41 30 30 30 30 30 30 36 46 30  [0A802FA0000006F0]
    06:36:43: RADIUS:   31 36 42 33 36 44 38 3B 33 35 53 65 73 73 69 6F  [16B36D8;35Sessio]
    06:36:43: RADIUS:   6E 49 44 3D 69 73 65 2D 73 65 72 76 65 72 2D 31  [nID=ise-server-1]
    06:36:43: RADIUS:   2F 31 37 31 30 32 35 39 38 38 2F 32 34 3B    [ /171025988/24;]
    06:36:43: RADIUS:  EAP-Message         [79]  255
    06:36:43: RADIUS:   4D 5D 13 47 FC 46 16 EE 62 76 40 09 77 48 31 B6 01 6B 5E 52 33 56 A2 1E 34  [M]GFbv@wH1k^R3V4]
    06:36:43: RADIUS:   02 32 39 FA 4D CA 79 18 4A 42 A2 4E 5C BD AE 29 D2 3D D1 5A FC C2 ED 3E E5 FB C6 B8 D8 DE A8 75 EB 3A A5 7D 02 03 01 00 01 A3 81 CD 30  [29MyJBN\)=Z>u:}0]
    06:36:43: RADIUS:   81 CA 30 0B 06 03 55 1D 0F 04 04 03 02 01 86 30 0F 06 03 55 1D 13 01 01 FF 04 05 30 03 01 01 FF 30 1D 06 03 55 1D 0E 04 16 04 14 C4 56 80 A7 C9 18 50 92 EE CC 91 D4 E1 EC DB AD E7 1E 70 A8 30 79 06 03 55 1D 1F 04 72 30 70  [0U0U00UVPp0yUr0p]
    06:36:43: RADIUS:   30 6E A0 6C A0 6A 86 32 68 74 74 70 3A 2F 2F 73 79 73 6C  [0nlj2http://sysl]
    06:36:43: RADIUS:   6F 67 2D 73 65 72 76 65 72 2F 43 65 72 74 45 6E  [og-server/CertEn]
    06:36:43: RADIUS:   72 6F 6C 6C 2F 46 4D 46 42 5F 54 72 75 73 74 65  [roll/FMFB_Truste]
    06:36:43: RADIUS:   64 43 41 2E 63 72 6C 86 34 66 69 6C 65 3A 2F 2F 5C  [dCA.crl4file://\]
    06:36:43: RADIUS:   5C 73 79 73 6C 6F 67 2D 73 65 72 76 65 72 5C 43  [\syslog-server\C]
    06:36:43: RADIUS:   65 72 74 45 6E 72 6F 6C 6C 5C 46 4D 46 42 5F 54  [ertEnroll\FMFB_T]
    06:36:43: RADIUS:   72 75 73 74 65 64 43 41 2E         [ rustedCA.]
    06:36:43: RADIUS:  EAP-Message         [79]  251
    06:36:43: RADIUS:   63 72 6C 30 10 06 09 2B 06 01 04 01 82 37 15 01 04 03 02 01 00 30 0D 06 09 2A 86 48 86 F7 0D 01 01 05 05 00 03 82 01 01 00 63 BA F8 CE D5 8B 0E 94 77 AE 86 6C 37 AB 2F 36 9A B2 85 D5 4A  [crl0+70*Hcwl7/6J]
    06:36:43: RADIUS:   74 8C 33 F5 93 06 A6 57 8D 39 56 8F 02 08 97 CB C6 08 70 8C 22 1E 5D 1F A8 26 6D 60 1F 05 62 D1 24 AB 03 8C 41 F8 1C F1 F8 C2 87 8B 97 02 71 FC 6A  [t3W9Vp"]&m`b$Aqj]
    06:36:43: RADIUS:   EB 12 FC DD 8C 5C 9C 2D AF D2 C4 1C 18 1B 40 BE 78 B0 54 55 59 89 03 1B B7 FB 91 85 EE CA C0 18 1C 78 5D 4D BA FA 9E 44 D3 45 53 A3 BE 46 8A FB 81 BD F1 4C B3 3B  [\-@xTUYx]MDESFL;]
    06:36:43: RADIUS:   D6 66 7E 5B 79 9F 83 53 5E 49 92 B5 7F E5 1A E2 86 8C 83 96 7D 75 A5 1D 08 4E 32 C3 5E EC BF 28 53 EC 53 8A C3 E0 36  [f~[yS^I}uN2^(SS6]
    06:36:43: RADIUS:   82 EE AA 0D 38 3E BA 9C 1D D9 24 BD 48 A6 EE 44 BD 95 68 85 CA 8C 44 F8 E8 A2 FB 94 BC 6F 7C F2 06 91 6C A0 A6 BB 7B 7F 56 BD 15 32 A4     [ 8>$HDhDo|l{V2]
    06:36:43: RADIUS:  Message-Authenticato[80]  18
    06:36:43: RADIUS:   DD 82 F7 10 3F C7 B5 62 9B 2A BB 24 16 A7 59 33            [ ?b*$Y3]
    06:36:44: RADIUS(00000049): Received from id 1645/99
    06:36:44: RADIUS/DECODE: EAP-Message fragments, 253+253+253+249, total 1008 bytes
    06:36:44: dot1x-packet:Received an EAP request packet from EAP for mac 0019.b981.e812
    06:36:44: dot1x-sm:Posting EAP_REQ on Client=1D68028
    06:36:44:     dot1x_auth_bend Fa0/11: during state auth_bend_response, got event 7(eapReq)
    06:36:44: @@@ dot1x_auth_bend Fa0/11: auth_bend_response -> auth_bend_request
    06:36:44: dot1x-sm:Fa0/11:0019.b981.e812:auth_bend_response_exit called
    06:36:44: dot1x-sm:Fa0/11:0019.b981.e812:auth_bend_request_enter called
    06:36:44: dot1x-packet:dot1x_mgr_send_eapol :EAP code: 0x1  id: 0x7B length: 0x03F0 type: 0xD  data: @Cfui[ab2,Jt1){                                                                                                                              2]g&GZ1pIbu;+Ga;iF"jy#
    oohuV.aFZ4_|
    P0`At   )B
    06:36:44: dot1x-ev:FastEthernet0/11:Sending EAPOL packet to group PAE address
    06:36:44: dot1x-ev:dot1x_mgr_pre_process_eapol_pak: Role determination not required on FastEthernet0/11.
    06:36:44: RADIUS:  Message-Authenticato[80]  18
    06:36:44: RADIUS:   F5 B0 56 D3 C6 87 BD 10 6E C7 4A 72 5B 5C 60 C5           [ VnJr[\`]
    06:36:44: RADIUS:  Vendor, Cisco       [26]  49
    06:36:44: RADIUS:   Cisco AVpair       [1]   43  "audit-session-id=C0A802FA0000006F016B36D8"
    06:36:44: RADIUS:  NAS-Port-Type       [61]  6   Ethernet                  [15]
    06:36:44: RADIUS:  NAS-Port            [5]   6   50011
    06:36:44: RADIUS:  NAS-Port-Id         [87]  18  "FastEthernet0/11"
    06:36:44: RADIUS:  State               [24]  80
    06:36:44: RADIUS:   33 37 43 50 4D 53 65 73 73 69 6F 6E 49 44 3D 43  [37CPMSessionID=C]
    06:36:44: RADIUS:   30 41 38 30 32 46 41 30 30 30 30 30 30 36 46 30  [0A802FA0000006F0]
    06:36:45: dot1x-ev:FastEthernet0/11:Sending EAPOL packet to group PAE address
    06:36:45: dot1x-ev:dot1x_mgr_pre_process_eapol_pak: Role determination not required on FastEthernet0/11.
    06:36:45: dot1x-registry:registry:dot1x_ether_macaddr called
    06:36:45: dot1x-ev:dot1x_mgr_send_eapol: Sending out EAPOL packet on FastEthernet0/11
    06:36:45: EAPOL pak dump Tx
    06:36:45: EAPOL Version: 0x2  type: 0x0  length: 0x0039
    06:36:45: EAP code: 0x1  id: 0x7E length: 0x0039 type: 0xD
    06:36:45: dot1x-packet:dot1x_txReq: EAPOL packet sent to client (0019.b981.e812)
    06:36:45: dot1x-sm:Fa0/11:0019.b981.e812:auth_bend_response_request_action called
    06:36:46: dot1x-ev:dot1x_mgr_pre_process_eapol_pak: Role determination not required on FastEthernet0/11.
    06:36:46: dot1x-packet:dot1x_mgr_process_eapol_pak: queuing an EAPOL pkt on Authenticator Q
    06:36:46: dot1x-ev:Enqueued the eapol packet to the global authenticator queue
    06:36:46: EAPOL pak dump rx
    06:36:46: EAPOL Version: 0x1  type: 0x0  length: 0x0006
    06:36:46: dot1x-ev:
    dot1x_auth_queue_event: Int Fa0/11 CODE= 2,TYPE= 13,LEN= 6
    06:36:46: dot1x-packet:Received an EAPOL frame on interface FastEthernet0/11
    06:36:46: dot1x-ev:Received pkt saddr =0019.b981.e812 , daddr = 0180.c200.0003,
                        pae-ether-type = 888e.0100.0006
    06:36:46: dot1x-ev:dot1x_auth_process_eapol: EAPOL flag status of the port  Fa0/11 is TRUE

  • Dacl on ACS 5.1 and Catalyst switch 3560

    Dear all
    I have ACS 5.1 and Catalyst switch 3560 with version 12.2(53)SE. I configure a dacl on the ACS and I use it on authorization profile.
    This authrization profile is used on access policy.
    I tried the authentication but it doesn't work. I checked the ACS logs and I found that the user is authenicated successfuly but the dacl gives this error (The Access-Request for the requested dACL is missing a cisco-av-pair attribute with the value aaa:event=acl-download. The request is rejected)
    Steps:
    11001  Received RADIUS Access-Request
    11017  RADIUS created a new session
    11025  The Access-Request for the requested dACL is missing a cisco-av-pair attribute with the value aaa:event=acl-download. The request is rejected
    11003  Returned RADIUS Access-Reject
    DACL:
    deny ip host 1.2.3.4 1.2.3.0 0.0.0.255 log
    permit ip any any log
    Thanks on advance,

    Dear Tiago
    I applied the command "radius-server vsa send". Now I can see the dacl is applied but I can't see it on the switch and even the authentication is succueeded ont the ACS logs but it give me unauthoized on the switchport. You can see the logs( started with the username acstest and the access-list is applied but it doesn't work and you can see theat it goes for mab after eap timed out). I hope you can help on this issue.
    Dec 13,10 10:29:00.513 AM
    00-23-AE-7A-58-A6
    00-23-AE-7A-58-A6
    Default Network Access
    Lookup
    Dot1x-3560-Switch
    1.2.3.4
    FastEthernet0/5
    TESTACS
    22056 Subject not found in the applicable identity store(s).
    Dec 13,10 10:28:29.186 AM
    #ACSACL#-IP-Guest-4cfcc14d
    Dot1x-3560-Switch
    1.2.3.4
    TESTACS
    Dec 13,10 10:28:28.726 AM
    acstest
    00-23-AE-7A-58-A6
    Default Network Access
    PEAP (EAP-MSCHAPv2)
    Dot1x-3560-Switch
    1.2.3.4
    FastEthernet0/5
    TESTACS
    Thanks,

  • I don't understand correlation between ACL and dACL. If dACL is downloaded to the Catalyst switch what is the status of the ACL

    Understanding  ISE and dACL.
     I don't understand correlation between ACL and dACL.
     If dACL is downloaded to the Catalyst switch what is the status of the ACL attached to physical port. Is dACL appended to the existing ACL? When I typed ‘sh ip access-list int fa0/1’ I can see only dACL for access domain and dACL for voice domain appended to the previous dACL and no ACL lines.
     Regards,
    Vice

    Hi,
    Downloadable ACLs (dACL) are applied from your RADIUS server based on authentication and authorization policies.  It overrides any standard interface ACL.
    Standard interface ACLs are in place to limit traffic on the port before 802.1x or MAB authentication.
    When an authenticated session terminates on the interface the standard ACL will be re-applied until the next authentication.

  • Adding filters or adjustments to an image of noise does not apply (some do work???)

    Steps to reproduce
    open new image
    add noise
    now try to add unsharpen mask or curves (there are other that dont apply as well but.....)
    you can see the effects in preview
    click OK and the changes do not apply

    Mylenium is right, though actually they're applied correctly, they're just not SEEN correctly in the preview.  If you look at the data closely you'll see that your effects indeed are applied to the document, but maybe not as aggressively as they appeared on the document preview in Photoshop.
    This is because the preview display is optimized for speed and the effects are applied to the zoomed-out preview as closely as possible.  Not all effects can be scaled perfectly using fractional numbers. 
    In short, Adobe figures you'd rather see a facsimile of the effect quickly than wait ages to see it rendered perfectly.
    However, if you'd really, really like to see it rendered accurately, and don't mind waiting (and some possibility of destabilization), you can change the Cache Levels to 1 in your Performance preferences then restart Photoshop.  With that setting, all effects are composited at 100% original size then the result is resampled for display on your screen.  If you try this, you'll find it can get pretty sluggish.
    -Noel

  • My mac wont let me open an application after it download

    so once i have downloaded an application such as a music download site it successfully downloads but when i try to open it to install it this is exactly what it says(Safari can’t open the file “BlubsterSetup.exe” because no available application can open it.) blubster is the name of the site i tried to download...and then when i click help this is what pops up..
    #1.Safari can open a downloaded file only if it's in the download location specified in the General pane of Safari preferences. If you move the file or change the download location after downloading a file, Safari cannot open it.
    #2.Safari can open a downloaded file only if there is an application available to open it. Mac OS X includes applications that open many types of files including text, image, sound, and PDF files. However, to open some files you might need to install the application used to create the files on your computer.
    #3.The file is still downloading. Wait for the file to finish downloading, then try opening it.
    The file didn't finish downloading because you stopped the download. Resume downloading the file, then try opening it.
    The file didn't download completely because of a problem or the file was damaged. Try downloading the file again.
    i think it may be #2 cause all the others dont apply......thanks

    .EXE files are not very easy to open on Macs with Mac OS X 10.4.3 or earlier. They typically require an emulation program to run Windows.
    See my FAQ*:
    http://www.macmaps.com/macosxnative.html#WINTEL
    Newer Macs are more capable of running Windows, and can do so natively. You can attempt to find a 10.3.9 compatible alternative compatible application as well. Audio and video files don't play very well on emulation, but work fine in Windows native compatible Macs.
    - * Links to my pages may give me compensation.

  • WVC80N - AVI recorded files cannot be viewed in Quicktime or Windows Media Player

    I have tried on two seperate PCs and the AVI files will not load. I have inspected the AVI files to be ISO MPEG-4 Video V1 standard and therefore should be able to be played by Windows Media Player and Quicktime but they both complain they cannot be played. Anyone else ran into this? I should have the specific codecs by default. The error message from quicktime is that there is required software needed to play this file and I get redirected to a generic page of possible plug ins. Windows Media player gives me a generic error with a link to some random troubleshooting steps that dont apply.
    As a side note Nero Showtime can open the file and play it...
    Message Edited by JKru on 12-10-2009 09:33 PM

    To Download VLC Software, Go to http://www.videolan.org/vlc/ and download and Install the VLC Media Player on your computer. Once the Installation is completed then you will be able to play the Video Files using VLC Player.

  • How to include text items in a block...urgent please.

    I have one form, basically at the first level, it in turns calls other forms too. However, I have add two columns i.e. sales_no, and date_closed at job level. The form is at project level. When the user apply ENTER_QUERY mode on project, then all the projects already closed should display sales_no and date_closed otherwise leave them bank. Project comes from project_master and sales_no, date_closed comes from job and both are linked via project_no, and entity. Could anyone help please?

    Hi Jhon,
    You have my thanks for your reply and then let me explain the stuff I am doing. The method you have suggested, I am already applying the same techniques. The items are there in the block along with other items. However, when I add my two text items which comes from another table which has relationship with the table being used by the block, though the block is couple of other inter-related tables too. Now when I add my text items I dont apply any triggers, but when I run the form it gives me error, invalid field item. My question is where I can add the triggers for the two items, and how can it be successfully embedded inside the block. I dont know if that makes sense. I'll appreciate your help in this matter. Thanks
    Zahir

  • Telnet problem

    Hello.
    I have Cisco Router 876 Series, and have problem with telnet. i cant connect via telnet from remote office to my router. does anybody know how to solve that problem.
    I have two vlan, vlan 1 is a nativ vlan and it is config for inside network, and vlan 2 for outside.
    and fa0, fa1, and fa2 interface is in vlan1, while fa3 is in vlan2.
    Anybody please!!

    you stated you have it configured for ssh. does ssh work? i would suggest using that anyway. perhaps you have it only configured to use telnet from inside not outside aswell.
    you will need something like this
    telnet 10.1.2.0 255.255.255.0 outside
    regardless of what you have in acl if you dont apply telnet to ouside it just wont work.
    http://www.cisco.com/en/US/customer/docs/security/pix/pix62/configuration/guide/sysmgmt.html#wpmkr1065324

  • How to create a back up disc in itunes 11?

    i need to know how to create a back up disc in the latest version of i tunes the directions in  the article dont apply to  my version it says to go to file then library then to back up to disc from the menu but back up to disc doesnt  appear  in my menu

    Hi and welcome to Forum!
    You should learn RMAN (Recovery Manager) to do your backup with Oracle suggested way
    Then you can restore and recover this backup in any instance
    For more information, you can refer to below listed documentations :
    [Backup and Recovery Basics|http://download.oracle.com/docs/cd/B19306_01/backup.102/b14192/toc.htm]
    [Backup and Recovery Quick Start Guide|http://download.oracle.com/docs/cd/B19306_01/backup.102/b14193/toc.htm]
    [Backup and Recovery Reference|http://download.oracle.com/docs/cd/B19306_01/backup.102/b14194/toc.htm]
    Kamran Agayev A. (10g OCP)
    http://kamranagayev.wordpress.com

  • S_PROJECTS auth object

    I am trying to create a role for IMG display access only
    I made ACTVT in all the Auth objects "03" or "display"
    but in S_PROJECTS auth object, in "activity" there is no "display" , how do I make ACTVT in S_PROJECTS object "display"
    Thanks
    Message was edited by:
            Jackofalltrades

    Hi,
    First of all all activities dont apply to all auth objects.(for example generate activity might not be applicable for all auth objects)
    So SAP proposed what activities might be relevant to a particular Auth Object.
    This information is in TACTZ Tables.
    So perhaps u can verfiy the table and u would find that the entries displayed in ur Activity for S_PROJECTS would be the same values as are in S_PROJECTS values in TACTZ table.
    HoweverYou can maintain 03 for this object too.
    Select the pencil button for the activity field.
    It will take u to a dialog box which contains activity fields.
    Now if u dont find the 03 field there. Then right click on the screen and select more values option.
    It would display all the activities.
    However if the 03 field is not mentioned as a proposed activity for that Object by SAP (u can see this info in TACTZ) then make sure that u actually need this object for doing any display activites.
    Hope this helps
    Manohar

Maybe you are looking for

  • Using dbms_xmlsave

    I am trying to save contents of xml file into database tables. I know I have to use dbms_xmlsave.insertxml, but it does not allow you to work with multiple tables, so I created a view to join 2 tables together. But when I try to insert into the view

  • Volume too low on 6300, and listening to podcasts

    I believe this question has been asked so many times, but is there ANY way to make the allowable volume any higher on headsets? I'd like to listen to music while riding my bicycle and even the sound of the damn tires on the road is louder than the ma

  • HT1296 cannot sync my own music to my i-pod

    Cannot sync my own music to my i-pod touch

  • Why are purchased Audiobooks and Movies not downloadable in the Cloud?

    When I took a look at the new Purchased section in iTunes and found that movies and audiobooks were not there.  Is there a reason for this or is it Apple launching an incomplete servic?

  • Pictures lost in ipod

    I spent a few days in Athens and took about 300 pictures. I transferred them with the camera connector on my 20Go ipod (bought in august). Of course, I erased the compact flash. And then, while trying to transfer them to my ibook: 200 pictures lost.