default-acl

Configures the default ACL for failed, timed-out, or guest user sessions.
Syntax
default-acl { ipv4 | ipv6 } [ acl-id |acl-name ] [ in | out ]
no default-acl { ipv4 | ipv6 } [ acl-id |acl-name ] [ in | out ]
Parameters
ipv4
Specifies an IPv4 AC.
ipv6
Specifies an IPv6 ACL.
acl-id
ID of standard or numbered ACL (IPv4 only).
acl-name
Name or extended name of the ACL.
in
Specifies incoming authentication.
out
Specifies outgoing authentication.
Modes

Flexible-authentication configuration sub-mode

Usage Guidelines

Use the no form of the command to remove the configurable default ACL.

Use the command to configure a default ACL to be applied to users who failed (restricted VLAN), timed out (critical VLAN), or are guests (not capable of dot1x authentication).

Note: Dynamic modification of a default ACL by adding or deleting ACL rules is not supported. To modify a default ACL, you must first clear the session.
Examples

The following example configures the default IPv4 ACL called guests for inbound authentication.

device# configure terminal
device(conf)# authentication
device(conf-authen)# default-acl ipv4 guest in
History
Release version Command history
08.0.70 This command was introduced.