Hi all,

i'm experiencing problems with DACL in my testing environment. I defined
the access list in Configuration -> Switches -> "my switch" -> Role mapping
by Access List.
The test access list mapped to the role is:

deny tcp any 192.168.5.0 255.255.255.0
permit ip any any

The authentication and the role mapping work well, the switch port is
correctly moved to the right vlan but no access list is applied to that
port.

the testing switch is a Cisco C1000-8T-2G-L witch the ios
version 15.2(7)E4. The device tracking is enabled by default and is is
working.

The switch port is configured as following:
 switchport mode access
 authentication order dot1x mab
 authentication priority dot1x mab
 authentication port-control auto
 authentication periodic
 authentication timer reauthenticate 7200
 authentication timer restart 10800
 authentication violation replace
 mab
 no snmp trap link-status
 dot1x pae authenticator
 dot1x timeout quiet-period 2
 dot1x timeout tx-period 3

Could you please help me to trtoubleshoot and address this problem?

Thanks

Mirko
_______________________________________________
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to