Cisco ASA Microsoft(info) - Cisco-AV-Pair, multiple DACL

Unanswered Question
Jun 12th, 2008


I'm trying to add downloadable ACL's via a LDAP map. I have done a map between the info attribute in Microsoft ActiveDirectory and the Cisco-AV-Pair field.

My problem is that when I add two lines in the configuration i recive an error in the ASA log.

%ASA-3-109032: Unable to install ACL 'AAA-user-nisse-406F160D', downloaded for user nisse; Error in ACE : 'permit ip

ip:inacl#2=permit ip'

%ASA-6-716051: Group <SVC-LDAP-JARLEGREN-POLICY> User <nisse> IP <x.x.x.x> Error adding dynamic ACL for user.

Have anyone managed to get this to work or am I using the wrong syntax for the downloadable acl's

My config looks like this.

ip:inacl#1=permit ip

ip:inacl#2=permit ip

Tanks in advance


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
s-andersson Thu, 06/12/2008 - 00:57


Tanks for the answer but I'm running ASA 8.0 and the system message 716051 is the following error:

%ASA-6-716051: Group group-name User user-name IP IP_address Error adding dynamic ACL for user.

Best regards,


s-andersson Thu, 06/12/2008 - 01:16


Yes I have tried to add the access-list manually and it works fine. So it must be something with syntax


Do you have any ideas around the syntax that could be wrong or is it correct?

The load on the box is aroung 1% and what I know you can't add more memory to the box.

Best regards,



This Discussion