Cisco ASA Microsoft(info) - Cisco-AV-Pair, multiple DACL

Unanswered Question
Jun 12th, 2008

Hi

I'm trying to add downloadable ACL's via a LDAP map. I have done a map between the info attribute in Microsoft ActiveDirectory and the Cisco-AV-Pair field.

My problem is that when I add two lines in the configuration i recive an error in the ASA log.

%ASA-3-109032: Unable to install ACL 'AAA-user-nisse-406F160D', downloaded for user nisse; Error in ACE : 'permit ip 10.0.2.0 255.255.255.0 192.168.1.0 255.255.255.0

ip:inacl#2=permit ip 10.0.2.0 255.255.255.0 192.168.3.0 255.255.255.0'

%ASA-6-716051: Group <SVC-LDAP-JARLEGREN-POLICY> User <nisse> IP <x.x.x.x> Error adding dynamic ACL for user.

Have anyone managed to get this to work or am I using the wrong syntax for the downloadable acl's

My config looks like this.

ip:inacl#1=permit ip 10.0.2.0 255.255.255.0 192.168.1.0 255.255.255.0

ip:inacl#2=permit ip 10.0.2.0 255.255.255.0 192.168.3.0 255.255.255.0

Tanks in advance

Stefan

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
s-andersson Thu, 06/12/2008 - 00:57

Hi

Tanks for the answer but I'm running ASA 8.0 and the system message 716051 is the following error:

%ASA-6-716051: Group group-name User user-name IP IP_address Error adding dynamic ACL for user.

Best regards,

Stefan

s-andersson Thu, 06/12/2008 - 01:16

Hi

Yes I have tried to add the access-list manually and it works fine. So it must be something with syntax

ip:inacl....

Do you have any ideas around the syntax that could be wrong or is it correct?

The load on the box is aroung 1% and what I know you can't add more memory to the box.

Best regards,

//Stefan

Actions

This Discussion