@GIdenJoe I believe you are referring to the Group Policy ACL feature. From my understanding its still in closed beta, although it was announced 6+ months ago. As you state it uses the filter-ID RADIUS attribute to specify a Group Policy for an 802.1x session, and applies the firewall rules in that policy as a stateless ACL. I'm not sure that it applies anything else from the policy, although haven't tried it and so can't be sure. With regard to switches, its slated to only be available on the current MS210+ models, so not the MS120 or MS125.
... View more