<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allow access to only one device through ACS 4.2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228606#M126309</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're at the right path. Seems issue with NAR settings. Could you please attach the screen shot from the group &amp;gt; NAR section. Also, what protocol is in use, tacacs or radius?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Jun 2013 15:17:45 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-06-26T15:17:45Z</dc:date>
    <item>
      <title>Allow access to only one device through ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228605#M126308</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running ACS4.2 and want to configure a group for access to only specific devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup a group in AD and matched this to a group in ACS. Under Network configuration, I've added the device I want the users to access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In group settings I've added the device under &lt;/P&gt;&lt;P&gt;Network Access Restrictions (NAR)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this correct and anything else I should be doing? When logging into the device I get authorisation failed. We have a group already setup for access to all devices which works fine, but I want this second group to be for only one device. Not sure where I'm going wrong with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authentication is all done through AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228605#M126308</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2019-03-11T03:35:22Z</dc:date>
    </item>
    <item>
      <title>Allow access to only one device through ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228606#M126309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're at the right path. Seems issue with NAR settings. Could you please attach the screen shot from the group &amp;gt; NAR section. Also, what protocol is in use, tacacs or radius?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 15:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228606#M126309</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-26T15:17:45Z</dc:date>
    </item>
    <item>
      <title>Allow access to only one device through ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228607#M126310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sure,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See attached.&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/3/3/143332-ACS.jpg" class="jive-image" /&gt; T&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 15:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228607#M126310</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2013-06-26T15:42:04Z</dc:date>
    </item>
    <item>
      <title>Allow access to only one device through ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228608#M126311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;need some correction there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In AAA client section: clcik on drop down menu and select the device you want to allow access.&lt;/P&gt;&lt;P&gt;In the Port filed: type *&lt;/P&gt;&lt;P&gt;In the address field type *&lt;/P&gt;&lt;P&gt;click enter&lt;/P&gt;&lt;P&gt;hit submit + Restart&lt;/P&gt;&lt;P&gt;try again &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 15:56:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228608#M126311</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-26T15:56:16Z</dc:date>
    </item>
    <item>
      <title>Allow access to only one device through ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228609#M126312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I go to Network Configuration there is already a group setup for what looks to be all devices - *.*.*.*&lt;/P&gt;&lt;P&gt;See attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to add a new group for my single device but it says it overlaps. Am I able to setup more than one group, or how do I configure a second group for just this one device?&lt;/P&gt;&lt;P&gt;Basically at the moment I have an Admin ACS group in AD which has all our admins in it and have access to all devices using *.*.*.*. I now want my restricted AD group to have access to only one device...y.y.y.y but still want the other admins to have access to all devices. Is this easily achieved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;es&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/6/3/143363-ACS2.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 16:28:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228609#M126312</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2013-06-26T16:28:00Z</dc:date>
    </item>
    <item>
      <title>Allow access to only one device through ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228610#M126313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well, that's not a right practise. We should have device cerated either with an ip-range or subnet or single AAA client. With current settings you may not be able to configured NAR.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 16:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228610#M126313</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-26T16:32:08Z</dc:date>
    </item>
    <item>
      <title>Allow access to only one device through ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228611#M126314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate the help. This was setup before my time...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, so do you suggest removing the .*.*.*.* and start adding new groups for individual sets of devices, subnets? I guess this is best practice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 16:43:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228611#M126314</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2013-06-26T16:43:53Z</dc:date>
    </item>
    <item>
      <title>Allow access to only one device through ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228612#M126315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup, your understaning is correct, little time consuming though &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Currently, it's wide open for all/any network devices with shared-secret protected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 16:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228612#M126315</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-26T16:51:44Z</dc:date>
    </item>
    <item>
      <title>Allow access to only one device through ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228613#M126316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Managed to get this working by sorting into groups/subnets so thanks for the help with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I able to limit a group to only have access to certain commands, e.g create ephone-dn's etc..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 14:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228613#M126316</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2013-06-27T14:11:01Z</dc:date>
    </item>
    <item>
      <title>Allow access to only one device through ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228614#M126317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to know. Yup, you can here is a link to configure the same:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS Shell Command Authorization Sets on IOS and ASA/PIX/FWSM Configuration Example&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 14:28:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-access-to-only-one-device-through-acs-4-2/m-p/2228614#M126317</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-27T14:28:59Z</dc:date>
    </item>
  </channel>
</rss>

