<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to have different Roles on different VDC's? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-have-different-roles-on-different-vdc-s/m-p/2153161#M138278</link>
    <description>&lt;P&gt;I have ACS 5.3 running TACACS+ and Nexus 7K with 2 x non-default VDC's, VDC-OTV and VDC-CR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want my TACACS account to have role "vdc-admin" on VDC-CR, and "vdc-operator" on VDC-OTV.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way to achieve this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried putting the VDC's into different Network Device Groups, with VDC-CR being in an Authorization Rule that associated the Device Group with the "vdc-admin" Shell Profile. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I'm getting the same roles on both VDC's--both get whatever the role in the Shell Profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's possible I'm not organizing the Devices and Network Device Groups correctly. It seems to me when I add a new Device, it knows about all the Device Groups, and the IP range and exclude syntax seems to be a pain. I have existing Device Groups, one with a 10.10.*.* IP range, and I'm trying to isolate these two VDC's out of that IP range into their own individual Device Groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:10:04 GMT</pubDate>
    <dc:creator>000node000</dc:creator>
    <dc:date>2019-03-11T03:10:04Z</dc:date>
    <item>
      <title>How to have different Roles on different VDC's?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-have-different-roles-on-different-vdc-s/m-p/2153161#M138278</link>
      <description>&lt;P&gt;I have ACS 5.3 running TACACS+ and Nexus 7K with 2 x non-default VDC's, VDC-OTV and VDC-CR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want my TACACS account to have role "vdc-admin" on VDC-CR, and "vdc-operator" on VDC-OTV.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way to achieve this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried putting the VDC's into different Network Device Groups, with VDC-CR being in an Authorization Rule that associated the Device Group with the "vdc-admin" Shell Profile. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I'm getting the same roles on both VDC's--both get whatever the role in the Shell Profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's possible I'm not organizing the Devices and Network Device Groups correctly. It seems to me when I add a new Device, it knows about all the Device Groups, and the IP range and exclude syntax seems to be a pain. I have existing Device Groups, one with a 10.10.*.* IP range, and I'm trying to isolate these two VDC's out of that IP range into their own individual Device Groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:10:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-have-different-roles-on-different-vdc-s/m-p/2153161#M138278</guid>
      <dc:creator>000node000</dc:creator>
      <dc:date>2019-03-11T03:10:04Z</dc:date>
    </item>
    <item>
      <title>How to have different Roles on different VDC's?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-have-different-roles-on-different-vdc-s/m-p/2153162#M138283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Choi:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post us some screenshots from your ACS configuration (policies, autho profiles...etc) so we give them a look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Mar 2013 11:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-have-different-roles-on-different-vdc-s/m-p/2153162#M138283</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-03-17T11:22:39Z</dc:date>
    </item>
  </channel>
</rss>

