ACS 4.2 and dACL on Catalyst switches

Unanswered Question
May 26th, 2010
User Badges:


I have ACS,  3750-48PSS switch with 12.50.SE3 and test PC running Windows XP. PC authenticated by MAB and switch correctly download dACL from ACS. But if dACL contains more than ~10 lines traffic not passed thru port (dACL downloaded correctly). Does anybody know why traffic is blocked or how I can debug this or any restrictions in dACL construction.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Jatin Katyal Wed, 05/26/2010 - 06:25
User Badges:
  • Cisco Employee,

This is what I understand; The port is getting authorized fine, DACL are being sent by the radius server and are getting applied to the concern port but its not taking effect. This is an on going issue..we have seen many cases with this.

As you said uf there are more then 10 lines then only its not working...In that case There is an internal bug on this: CSCsf14450: DACL not consistently downloaded to switch during MAB testing.



Do rate helpful posts-

Jatin Katyal Wed, 05/26/2010 - 07:59
User Badges:
  • Cisco Employee,

Catalyst IOS but finally its declared as Junked bug.


This Discussion