Guest

Preview Tool

Cisco Bug: CSCvs68391 - DACL is not applied correctly on switch

Last Modified

Jan 21, 2020

Products (1)

  • Cisco Catalyst 3560-X Series Switches

Known Affected Releases

15.2(2.1) 15.2(4.1.1)

Description (partial)

Symptom:
The DACL pushed by the ISE is not applied correctly on the switch. Destination IP and mask are replaced by "any". 

DACL statements should be:

permit tcp any x.x.x.x x.x.x.x gt 1024

However, when using "show ip access-list" this is the output for the same line:

permit tcp any any gt 1024

Conditions:
ISE Version 2.6 patch 2
 
HW: WS-C3560X-48P 
SW: 15.2(2)E6 and 15.2(4)E9 both tested with same results
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.