cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
472
Views
0
Helpful
3
Replies

Which one will over right the other - DACL

aalshammari
Level 1
Level 1

If I have configured downloadable ACL on ACS group, then one of the users who is belong to same group has assign particular ACL on his profile.

Which one will be pushed to the router is it the group ACL or user ACL

Many Thanks

3 Replies 3

Vivek Santuka
Cisco Employee
Cisco Employee

Hi,

User profile takes precedence over group profile. So user ACL will be pushed.

Regards,

Vivek

magurwara
Level 1
Level 1

aalshammari,

is your DACL working? Is it configured on PIX?

I am trying but getting an error on the PIX like "can't find authorization ACL". I have posted in detailed under topic "Downloadable ACL".

Appreciate any help.

Update.....

I do see in ACS logs that Authentication failed for ACL where username is the ACL name sent by PIX. (#ACSACL#-IP-myACL-45e6c605).

The failure code is "DACL request from device is not acceptable"

I guess ACS is denying but WHY?