A method is disclosed for creating and storing troubleshooting information
for providing access control information to a network device. A
provisioning of one or more access control lists, and one or more
associations of the access control lists to users of the network device,
are received. As part of authenticating a user login request, a name of a
first access control list is provided to the network device, selected
from among the one or more access control lists that based on the
associations. A request is received from the network device for a first
access control list that is associated with a user of the network device.
The request includes the name of the access control list. The first
access control list is sent to the network device in response to the
request. Embodiments may use RADIUS packets for communicating ACLs from
an authentication server to a firewall, and a de-fragmentation approach
is disclosed for downloading ACLs that exceed the maximum RADIUS packet
size. Further, using an ACL renaming approach the firewall is forced to
update its cache when a user subsequently logs in and the corresponding
ACL has changed in the interim.