Introduces the Downloadable ACL feature, detailing its capabilities, feature history, scale considerations, configuration in Cisco ISE and controllers, guidelines and restrictions, explicit authorization server setup, and methods for verifying dACL configuration.
A downloadable ACL is a type of access control list that
-
restricts network access to users or devices based on predefined criteria
-
is specified as a list of Access Control Entries (ACEs), and
-
can be maintained centrally in Cisco ISE and downloaded to controllers.
Supporting reference information
You can easily maintain and update ACLs in Cisco ISE.
Each ACE has a matching condition based on packet header fields:
-
IP addresses
-
ports
-
protocols
-
combination of IP addresses, ports, and protocols
-
Result (permit or deny)
ACLs are applied to each controller on a per-wireless-client basis.
Typically, you can configure ACLs in a controller itself. However, you can also configure ACLs on a connected Cisco ISE server and download them to the controller when a wireless client connects.
These ACLs are referred to as downloadable ACLs, per-user Dynamic ACLs, or dACLs.
You can easily maintain downloadable ACLs because they define or update ACLs in Cisco ISE and can be downloaded to all applicable controllers.
(In Cisco IOS-XE 17.8 and earlier releases, you must configure the name in Cisco ISE and define the ACL individually on each controller.)