<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time Based Authorization/Authentication on devices :: ACS 5. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/time-based-authorization-authentication-on-devices-acs-5-4/m-p/2284907#M108085</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp; Hi,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Yes. You need to create a date and time policy condition.&lt;/P&gt;&lt;P&gt;Policy Elements -&amp;gt; Session Conditions -&amp;gt; Date and Time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can specify the time there and then you can use the one you created in the authorization policy.&lt;/P&gt;&lt;P&gt;For example, you configure the date time condition to be from 8000 - 2300.&lt;/P&gt;&lt;P&gt;Then you go to the authorization policy and configure if it matches the date time instance then return a authorization profile (read write). otherwise (if not matching) return the authorization profile (read only).&lt;/P&gt;&lt;P&gt;(use shell profile instead if you are using TACACS+).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Aug 2013 14:10:02 GMT</pubDate>
    <dc:creator>Amjad Abdullah</dc:creator>
    <dc:date>2013-08-22T14:10:02Z</dc:date>
    <item>
      <title>Time Based Authorization/Authentication on devices :: ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/time-based-authorization-authentication-on-devices-acs-5-4/m-p/2284906#M108082</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we have any option where we can allow config access to a particular external/internal user for certain time period. Time based device access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've External Identity Store in our environment where user got authenticated via LDAP server. &lt;/P&gt;&lt;P&gt;For Example - There is a user 'X'. I want to grant him config access on devices from 8:00 AM to 11:00 PM daily. After that he should only has Read Only access on the devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if any other information is required from my side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ACS Ver is 5.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;SYED&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:48:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/time-based-authorization-authentication-on-devices-acs-5-4/m-p/2284906#M108082</guid>
      <dc:creator>Jayavel Arumugam</dc:creator>
      <dc:date>2019-03-11T03:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Time Based Authorization/Authentication on devices :: ACS 5.</title>
      <link>https://community.cisco.com/t5/network-access-control/time-based-authorization-authentication-on-devices-acs-5-4/m-p/2284907#M108085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp; Hi,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Yes. You need to create a date and time policy condition.&lt;/P&gt;&lt;P&gt;Policy Elements -&amp;gt; Session Conditions -&amp;gt; Date and Time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can specify the time there and then you can use the one you created in the authorization policy.&lt;/P&gt;&lt;P&gt;For example, you configure the date time condition to be from 8000 - 2300.&lt;/P&gt;&lt;P&gt;Then you go to the authorization policy and configure if it matches the date time instance then return a authorization profile (read write). otherwise (if not matching) return the authorization profile (read only).&lt;/P&gt;&lt;P&gt;(use shell profile instead if you are using TACACS+).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 14:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/time-based-authorization-authentication-on-devices-acs-5-4/m-p/2284907#M108085</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-08-22T14:10:02Z</dc:date>
    </item>
  </channel>
</rss>

