Dacl on ACS 5.1 and Catalyst switch 3560

Dear all
I have ACS 5.1 and Catalyst switch 3560 with version 12.2(53)SE. I configure a dacl on the ACS and I use it on authorization profile.
This authrization profile is used on access policy.
I tried the authentication but it doesn't work. I checked the ACS logs and I found that the user is authenicated successfuly but the dacl gives this error (The Access-Request for the requested dACL is missing a cisco-av-pair attribute with the value aaa:event=acl-download. The request is rejected)
Steps:
11001  Received RADIUS Access-Request
11017  RADIUS created a new session
11025  The Access-Request for the requested dACL is missing a cisco-av-pair attribute with the value aaa:event=acl-download. The request is rejected
11003  Returned RADIUS Access-Reject
DACL:
deny ip host 1.2.3.4 1.2.3.0 0.0.0.255 log
permit ip any any log
Thanks on advance,

Dear Tiago
I applied the command "radius-server vsa send". Now I can see the dacl is applied but I can't see it on the switch and even the authentication is succueeded ont the ACS logs but it give me unauthoized on the switchport. You can see the logs( started with the username acstest and the access-list is applied but it doesn't work and you can see theat it goes for mab after eap timed out). I hope you can help on this issue.
Dec 13,10 10:29:00.513 AM
00-23-AE-7A-58-A6
00-23-AE-7A-58-A6
Default Network Access
Lookup
Dot1x-3560-Switch
1.2.3.4
FastEthernet0/5
TESTACS
22056 Subject not found in the applicable identity store(s).
Dec 13,10 10:28:29.186 AM
#ACSACL#-IP-Guest-4cfcc14d
Dot1x-3560-Switch
1.2.3.4
TESTACS
Dec 13,10 10:28:28.726 AM
acstest
00-23-AE-7A-58-A6
Default Network Access
PEAP (EAP-MSCHAPv2)
Dot1x-3560-Switch
1.2.3.4
FastEthernet0/5
TESTACS
Thanks,

Similar Messages

  • The difference of the IEEE802.1x Auth between Cisco Routers and Catalyst switches

    Hello
    I am investigating the difference of the IEEE802.1x Auth between Routers and Switches.
    Basically dot1x auth is availlable on Catalyst Switches. however if I want to check to
    PortBased Multi-Auth , MAC address Auth and any certification Auth with this feature,
    Is it possible to integrate into Cisco Router such as Cisco 891F ?
    In my opinion Cisco891F is also available to use basic IEEE802.1x but if it compares with Catalyst switches such as Cat3560X
    I think there might be any unsupported feature on Cisco 891F.
    I appreciate any information. thank you very much in advance.
    Best Regards,
    Masanobu Hiyoshi

    Many time in interviews asked comaprison between cisco  routers and switches that i was answerless bcoz i dont have much knowledge about that.Can anyone provide me the compariosin sheet of the same.how are the cisco devices differ with each other how much Bandwidth each routres support and Etc...
    Ummmm ... The most common question I get is "what is the difference between a router and a switch".
    However, if you get a question like this, then my impression to this line of questioning are:
    1.  The candidate they are looking for has in-depth knowledge of routers and switches.  And I mean IN-DEPTH!;
    2.  They are not looking for a candidate.  They just want to stroke their ego.  There is not alot of people who can give you the "names and numbers" of routers and switches at a snap of a finger.  And if you do happen to know the answer, then and there, then expect a tougher follow-up question. 

  • Open mode (monitor mode) with ise and catalyst switches

    Hi There,
    Anyone know if the following observation is correct ?
    From the TrustSec 2.1 "Monitor Mode" guide i get the idea that Open mode, is not really as zero impact in a data gathering part of an ISE deployment is a was expecting. The guide describes using Profiling to authorize Cisco IP phones for the Voice VLAN.
    - Does this mean that regular methods like using CDP won't work to for this once i enable dot1x on an access switch port interface ?
    - And that i will need to figure out which ports should be set for multi-domain (phone+pc), and which should be set for multi-auth(possibly multiple devices on one port) during the open mode period ?
    Regards
    Jan

    Hello Jan-
    Below is my input to your questions:
    From the TrustSec 2.1 "Monitor Mode" guide i get the idea that Open mode, is not really as zero impact in a data gathering part of an ISE deployment is a was expecting.
    Yes, a device is still allowed on the network even if it fails all authentication methods (MAB, 802.1x, etc). Basically you use monitor mode to perform discovery and see what would have been blocked had ISE been deployed in production.
    The guide describes using Profiling to authorize Cisco IP phones for the Voice VLAN.
    Yes, you can use profiling to do this. Keep in mind that you will need advanced licensing for this. Otherwise, you can either use MAB with static MACs imported/entered in the local database or EAP-TLS with phone certificates
    - Does this mean that regular methods like using CDP won't work to for this once i enable dot1x on an access switch port interface ?
    CDP will still work, in fact some of the profiling happens thanks to CDP, however, the device will simply not going to be allowed to get on the network and the Voice VLAN unless it passes authentication/authorization.
    - And that i will need to figure out which ports should be set for multi-domain (phone+pc), and which should be set for multi-auth(possibly multiple devices on one port) during the open mode period ?
    This really depends on how secure you want your network to be
    Hope this helps!
    Thank you for rating!

  • Etherchannel between stack switches[3750] and standalone switch[3560]

    Hi,
    I have 2*3750 switches in stack as core and 1*3560 switch in access layer. I want to enable ether channel between stack switch[3750A & 3750B] and 3560 switches.
    Have connected  2 links from 3560 switch to stack switch, one link to 3750A and other link to 3750B. Will it work in this way as per my requirement? 
    or i should enabled stacking on 3560 switch too and configure cross-stack ether channel between 3750 stack and 3560 stack. i refered few cisco documents, but the cross stack etherchannel configuration example has 3750 at both end stacks.
    Rgds...
    VikramS

    Hi,
     This should work fine as per you set up, the 3750 stack will be acting as one switch, which means that the ether-channel configuration should be straight forward. There is no need to stack the 3560 for this to work, also the 3560 are not stackable.
    Hope this helps.

  • LMS 3.2 and Catalyst 4500 WS-X4648-RJ45-E module card

    Hi all,
    I have a rpoblem with a specific client with LMS 3.2. We are using LMS 3.2 on Windows 2008 and everything seem to be working OK. The issue is in the CiscoView with the 4500 switches. CiscoView can see the supervisors on all 4500 switches (6); but cannot see the switchcards when the switchcards are WS-X4648-RJ45-E. Find the sh inv output below:
    CSR-D1#sh inventory
    NAME: "Switch System", DESCR: "Cisco Systems, Inc. WS-C4507R-E 7 slot switch "
    PID: WS-C4507R-E       , VID: V01, SN: FOX1152GKR1
    NAME: "Clock Module", DESCR: "Clock Module"
    PID: WS-X4K-CLOCK-E    , VID: V01, SN: JAE120354DD
    NAME: "Linecard(slot 1)", DESCR: "10/100/1000BaseT (RJ45) with 48 10/100/1000 baseT "
    PID: WS-X4648-RJ45-E   , VID: V01, SN: JAE14410NLT
    NAME: "Linecard(slot 2)", DESCR: "6 Dual media SFP or 10/100/1000BaseT (RJ45)V voice power ports (Cisco/IEEE)"
    PID: WS-X4506-GB-T     , VID: V05, SN: JAE120351NC
    NAME: "Linecard(slot 3)", DESCR: "Supervisor 6-E 10GE (X2), 1000BaseX (SFP) with 2 10GE X2 ports"
    PID: WS-X45-SUP6-E     , VID: V01, SN: JAE120576HG
    NAME: "TenGigabitEthernet3/1", DESCR: "10Gbase-LRM"
    PID: FTLX1341E2-C1     , VID: A  , SN: FNS1352175M
    NAME: "TwinGig Converter 3/2", DESCR: "TwinGig Converter Module"
    PID: 800-27645-01      , VID: A0 , SN: CAT1147H2WK
    NAME: "Linecard(slot 4)", DESCR: "Supervisor 6-E 10GE (X2), 1000BaseX (SFP) with 2 10GE X2 ports"
    PID: WS-X45-SUP6-E     , VID: V07, SN: JAE14080NL2
    NAME: "TwinGig Converter 4/2", DESCR: "TwinGig Converter Module"
    PID: 800-27645-01      , VID: A0 , SN: CAT1147H2BV
    NAME: "Linecard(slot 7)", DESCR: "10/100/1000BaseT (RJ45) with 48 10/100/1000 baseT "
    PID: WS-X4648-RJ45-E   , VID: V01, SN: JAE14420A2F
    I have updated the s/w to 12.2(53) SG1 with no luck.
    Any ideas?

    Hi Nicos,
    I have exactly the same issue with LMS 3.2 CiscoView under Windows 2003 and catalyst switch 4506-E.
    4506-E are in IOS 12.2(53)SG2.
    I installed latest 4500IOS V 19.0 ciscoview device package without success.
    Did you fix your problem ?

  • Cisco nexus 9508 Vpc with catalyst switches

    Hi,
        i am karthik.
    we are going to build the nexus 9508 with NX-OS in our data center. in existing we are having 50's of catalyst L2 and L3 switches.
    If we perform the Vpc with 9K and catalyst switches. is there any restrictions on particular model catalyst switches will support Vpc with 9K?
    Kindly clarify my question?
    Thanks in advance for the valuable response!!!!

    Hi,
      i am having 4500 series switches and 6E sup engine.
    Then we are having nexus 9508 and N2232PP. when we try to configure fex between these switches.
    in Nexus 9508 showing unknown features error.
    Current Nx-OS version is n9000-dk9.6.1.2.I2.2.bin.

  • ACS 4.2 and dACL on Catalyst switches

    Hello
    I have ACS 4.2.0.124p14,  3750-48PSS switch with 12.50.SE3 and test PC running Windows XP. PC authenticated by MAB and switch correctly download dACL from ACS. But if dACL contains more than ~10 lines traffic not passed thru port (dACL downloaded correctly). Does anybody know why traffic is blocked or how I can debug this or any restrictions in dACL construction.
    Regards,
    Stanislav

    This is what I understand; The port is getting authorized fine, DACL are being sent by the radius server and are getting applied to the concern port but its not taking effect. This is an on going issue..we have seen many cases with this.
    As you said uf there are more then 10 lines then only its not working...In that case There is an internal bug on this: CSCsf14450: DACL not consistently downloaded to switch during MAB testing.
    HTH
    JK
    Do rate helpful posts-

  • I don't understand correlation between ACL and dACL. If dACL is downloaded to the Catalyst switch what is the status of the ACL

    Understanding  ISE and dACL.
     I don't understand correlation between ACL and dACL.
     If dACL is downloaded to the Catalyst switch what is the status of the ACL attached to physical port. Is dACL appended to the existing ACL? When I typed ‘sh ip access-list int fa0/1’ I can see only dACL for access domain and dACL for voice domain appended to the previous dACL and no ACL lines.
     Regards,
    Vice

    Hi,
    Downloadable ACLs (dACL) are applied from your RADIUS server based on authentication and authorization policies.  It overrides any standard interface ACL.
    Standard interface ACLs are in place to limit traffic on the port before 802.1x or MAB authentication.
    When an authenticated session terminates on the interface the standard ACL will be re-applied until the next authentication.

  • The difference between VTP server and transparent mode on Catalyst Switch.

    Hello 
    I have a question about the difference between VTP server mode and VTP transparent mode on general catalyst switch.
    Basically VTP server mode can create and modify VLAN configuration but  actually there is not any VLAN configuration through running-config, is it true?  When I checked it on Cat3550, certainly there is not VLAN configuration on VTP server mode. But VTP transparent can create VLAN and configuration but does not synchronize with other switch VLAN status. I appreciate any related information and reason of the VTP server mode specification, thank you very much.
    [VTP Transparent mode]
    3550#sh vtp status
    VTP Version                     : 2
    Configuration Revision          : 0
    Maximum VLANs supported locally : 1005
    Number of existing VLANs        : 27
    VTP Operating Mode              : Transparent
    VTP Domain Name                 :
    VTP Pruning Mode                : Disabled
    VTP V2 Mode                     : Disabled
    VTP Traps Generation            : Disabled
    *omit
    3550#
    3550#sh run
    Building configuration...
    *omit
    vlan 99
     name TEST-VLAN
    [VTP Server mode]
    3550#sh vtp status
    VTP Version                     : 2
    Configuration Revision          : 0
    Maximum VLANs supported locally : 1005
    Number of existing VLANs        : 27
    VTP Operating Mode              : Server
    VTP Domain Name                 :
    VTP Pruning Mode                : Disabled
    VTP V2 Mode                     : Disabled
    VTP Traps Generation            : Disabled
    *omit
    3550#
    3550#sh run
    Building configuration...
    *no VLAN like above configuration on VTP transparent mode.
    Best Regards,
    Masanobu Hiyoshi

    Hi mhiyoshi,
    3550#sh vtp status
    VTP Version                     : 2
    Configuration Revision          : 0
    Maximum VLANs supported locally : 1005
    Number of existing VLANs        : 27
    VTP Operating Mode              : Transparent
    VTP Domain Name                 :
    VTP Pruning Mode                : Disabled
    VTP V2 Mode                     : Disabled
    VTP Traps Generation            : Disabled
    *omit
    3550#
    3550#sh run
    Building configuration...
    *omit
    vlan 99
     name TEST-VLAN
    The above out put indicates that Vlan is created and then mode changed to transparent. i.e why revision no is 0.
    3550#sh vtp status
    VTP Version                     : 2
    Configuration Revision          : 0
    Maximum VLANs supported locally : 1005
    Number of existing VLANs        : 27
    VTP Operating Mode              : Server
    VTP Domain Name                 :
    VTP Pruning Mode                : Disabled
    VTP V2 Mode                     : Disabled
    VTP Traps Generation            : Disabled
    *omit
    3550#
    3550#sh run
    Building configuration...
    *no VLAN like above configuration on VTP transparent mode.
    This indicates that vlan never created in server mode nor learnt from another switch as revision no is 0

  • Differences between MSFC1 and MSFC2 in Catalyst switches

    Hi,
    Want to know the differences between MSFC1 and MSFC2 in Catalyst switches.

    Hi,
    There is not much difference between MSFC1 and MSFC2, the main difference is how the MSFCs send the hardware programming to the PFC. The MSFC1 uses MLS to program the hardware by using the first packet of the traffic. While the MSFC2 uses CEF-based MLS to program the PFC so that the supervisor can make the hardware switching of the packet. NOtice the difference if the MSFC1 needs to see the first packet while the MSFC2, in theory will not need to see a first packet as it uses the CEF routing table to program the PFC2. Now, the kicker, if MSFC2 in sup1A , all this CEF-based MLS is not used since it needs PFC2 to be able to do this. Sup1A does not come with PFC2 only Sup2 comes with PFC2. The MSFCs gives the Cat6K a L3 ability and it's important but the switching performance of the switch depends on the PFC.
    Here is a link on MSFC2 data sheet:
    http://www.cisco.com/en/US/products/hw/switches/ps708/products_data_sheet09186a00800887fd.html
    Please rate helpful posts.

  • Video conferencing, voice, VLAN and Catalyst 2950, 3500 and 6500 switches

    We have a Cat6500 with MSFC in the COre/Distribution, mix of 2950 and 3524XL in the closets in the HQ. Every closet will be on one VLAN. There are 5 remote sites on a Frame with 768 CIR. There will be one Polycom VC station in the HQ per closet, one Polycom per remote site. Additionally, every PC everywhere will be using desktop NetMeeting for VC. CallManager and IP Phones will be everywhere. My questions are:
    1. should I put the Polycom on the same VLAN as the PC's with COS set to 4 at layer 2 and IP Precedence set to 4 at layer3? IP Phones are already on a seperate voice VLAN .
    2. Should I put Polycom on it's own VLAN and seperate from the PC VLANs? If I do it this way should I set COS and IP precedence for the PC's with NetMeeting?
    3. any sample config. for the Catalyst switches?
    Thanks!
    Chris

    Chris,
    Check out this IP telephony design guide. Hope it is of some help to you:
    http://www.cisco.com/univercd/cc/td/doc/product/voice/ip_tele/network/

  • Cannot Establish Gigabit Link Between Catalyst Switches and GSR Router

    The GSR Gigabit interface is configured for no negotiation auto and the line protocol goes up when connected to the Catalyst switch.
    The Catalyst switch port remains unconnected even when it is physically attached to the GSR router.

    The flow control settings must match on both sides for the link to come up. It is highly recommended that you configure auto-negotiation to on for both devices. (Auto-negotiation is enabled by default on all Catalyst switches.) Otherwise, if you have a layer 1 problem, the link remains up and a unidirectional link will result.
    The initial software releases that support Gigabit Ethernet on the GSR router do not support gigabit auto-negotiation.
    The following command configures gigabit auto-negotiation on the Catalyst 6000/6500:
    set port negotiation module/port disable|enable

  • VLAN's, subinterface, access-lists and 3560 catalyst switch?

    Hi,
    How can I isolate VLAN 121 from all others?
    I have a cisco 2811 router connected to a 3560 catalyst switch which has 5 VLAN's of which I need to protect IP traffic of 4 from 1.
    The following VLANs configured on the switch:
    VLAN 0 192.168.132.0 /24
    VLAN 135 ..135.0 /24
    VLAN 137 ..137.0 /24
    VLAN 139 ..139.0.24 and lastly,
    VLAN 121 192.168.121.0 /24 which I wish to isolate all IP from VLAN 0, 135, 137, and 139 but have internet out the 2811's other interface. Currently all VLAN's and routing are working perfectly.
    I need some advice please. Here is my plan:  to split the FA0/0 into FA0/0.1 for VLAN 121 using dot1q and apply an access-list to deny 192.168.121.0 to the FA0/0 interface. Since I'm essentially creating VLAN's with the router can or will that interfere with the Switch VLAN configuration? router on a stick vs. a Layer 4 Cisco 3560 Catalyst switch?
    Thank you!

    I will have to assume VLAN 0 is the native VLAN / default interface on the router?  All VLANs are numbered native or not.  Just ensure the VLAN numbering matches between the router and the trunking on the switch.
    Yes, you could create a sub interface on the 2811 and use the router to route the VLAN.  Apply an access list on the other interfaces to block access to the VLAN you want to protect.  If you have routing enabled on the 3560 as well you would complicate the situation a bit more. 
    Please rate helpful posts! :-)

  • TCP delay on catalyst switch

    i experienced a TCP delay on catalyst 4506, avoid the problem when i replaced 4506's with dummy unmanaged switches.
    i used two PCs(PC 1 and PC 2) and two 4506 switches (S1 and S2)
    PC 1 is connected to S1 (fast ethernet port)
    PC 2 is connected to S2 (fast ethernet port)
    S1 is connected to S2 (SFP gigabit ethernet port)
    -I started continuous UDP,TCP,MULTICAST and PING from PC1 to PC2
    -I unplugged link between Switch 1 and Switch 2
    all communication stopped.
    -I plugged link between Switch 1 and Switch 2
    -UDP,MULTICAST and PING started immediately but TCP started with approximately 15 seconds delay. :-(
    I repeated same procedure with unmanaged dummy switches instead of 4506, there wasnt 15 seconds delay. TCP showed up in 1 second.
    How can I avoid TCP delay on catalyst switches? Probably some tuning with configuration would do the job?
    tx for helping

    hi gp and thank you very much for responding to this unusual problem.
    - switch ports to the PCs are configured as portfast.
    - switch ports between two catalyst switches are not configured (default)
    - i didnt use the 'switchport access' command since they are default layer 2 interfaces. would 'switchport access vlan 1' command make any difference?
    - i looked at the port status and confirmed connection is 100 mbps full duplex.
    unusual issue is; ping, udp, multicast shows up in a very short time after I re-plug the uplink. that proves all ports are in forwarding state. only TCP shows up with delay, which doesnt occur on 200 $ unmanaged switch??
    thanks in advance for any suggestions

  • Can a Catalyst switch terminate a QinQ (double vlan tagged) connection on an SVI?

    Can a Catalyst switch terminate a QinQ connection on an SVI?  Is anything similar possible?
    I know I can pass through QinQ traffic through a switch at L2, but can I take it in at L2 with double tags and terminate it on a L3 SVI somehow?
    Im looking for a simple way of making a WAN lab environment.
    IE I want to do the equivalent of this on a Catalyst such as a 3560/3750:
    interface GigabitEthernet0/0.1
     encapsulation dot1Q 101 second-dot1q 1
     ip vrf forwarding 100101
     ip address 1.1.1.1/24
    interface GigabitEthernet0/0.2
     encapsulation dot1Q 101 second-dot1q 2
     ip vrf forwarding 100102
     ip address 2.2.2.2/24
    thanks in advance.

    Can a Catalyst switch terminate a QinQ connection on an SVI?  Is anything similar possible?
    I know I can pass through QinQ traffic through a switch at L2, but can I take it in at L2 with double tags and terminate it on a L3 SVI somehow?
    Im looking for a simple way of making a WAN lab environment.
    IE I want to do the equivalent of this on a Catalyst such as a 3560/3750:
    interface GigabitEthernet0/0.1
     encapsulation dot1Q 101 second-dot1q 1
     ip vrf forwarding 100101
     ip address 1.1.1.1/24
    interface GigabitEthernet0/0.2
     encapsulation dot1Q 101 second-dot1q 2
     ip vrf forwarding 100102
     ip address 2.2.2.2/24
    thanks in advance.

Maybe you are looking for