802.1x with ACL

From: Edouard Zorrilla (ezorrilla@tsf.com.pe)
Date: Mon Jan 26 2009 - 14:43:20 ARST


Hi there,

Do any one was able to complete "802.1x with per-user-acl":

My Config is the next:

Rack1SW2#sh run | in aaa
aaa new-model
aaa authentication login default line
aaa authentication dot1x default group radius
aaa authorization network default group radius
aaa session-id common
Rack1SW2#

Rack1SW2#sh run int fas0/20
Building configuration...

Current configuration : 182 bytes
!
interface FastEthernet0/20
 description Connected-to-PcTest
 switchport mode access
 dot1x pae authenticator
 dot1x port-control auto
end

Rack1SW2#

VLAN assingment works fine but ACL does not. The config inside the ACS are:

[009\001] cisco-av-pair {check}
ip:inacl#1=deny ip 10.0.0.0 0.0.0.255 150.1.0.0 0.0.255.255
ip:inacl#2=permit ip any any.

This is the link I used for:

http://www.cisco.com/en/US/docs/switches/lan/catalyst3550/software/release/12
.2_25_see/configuration/guide/sw8021x.html#wp1170478

Do any one has a link or something that gives me light to acomplish this lab,

Regards

Blogs and organic groups at http://www.ccie.net



This archive was generated by hypermail 2.1.4 : Sun Mar 01 2009 - 09:43:40 ARST