cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
402
Views
0
Helpful
2
Replies

Downloadable ACL Feature

keller.oliver
Level 1
Level 1

Hi all,

this question is about using an ASA with ACS to utilize downloadable per-user ACLs.

I understand that the user-specific ACL gets downloaded from the ACS, but how can I determine to which interface this ACL is bound ?

Is there a default setting, like: the interface the user is connecting to ?

If so, can it be overridden ?

Thanks in advance,

Oliver

1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

Oliver

The acl gets applied to the interface referenced in the following command

aaa authentication include telnet -> inside <- 192.168.3.0 255.255.255.0 0 0 RADIUS

So in the above example the downloadable acl would be applied to the inside interface

aaa authentication include telnet -> outside <- 192.168.3.0 255.255.255.0 0 0 RADIUS

and in this one it would be applied to the outside interface.

Jon

View solution in original post

2 Replies 2

Jon Marshall
Hall of Fame
Hall of Fame

Oliver

The acl gets applied to the interface referenced in the following command

aaa authentication include telnet -> inside <- 192.168.3.0 255.255.255.0 0 0 RADIUS

So in the above example the downloadable acl would be applied to the inside interface

aaa authentication include telnet -> outside <- 192.168.3.0 255.255.255.0 0 0 RADIUS

and in this one it would be applied to the outside interface.

Jon

Jon,

thanks for your fast and accurate reply, it was exactly what I wanted to know.

atb,

Oliver

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card