<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authentication Problem in ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-problem-in-acs/m-p/2080549#M146570</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have created two ssid on WLC &amp;amp; authentication Via ACS to AD. after that i have configure TACACS+ on same ACS Server but some of the users can login in Wi-Fi which are not in member of Wi-Fi group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the below ACS configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 1 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;nbsp; HIgh managemnet Users&amp;nbsp; " this user can login in SSID 1"&lt;/P&gt;&lt;P&gt;Group 3 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Corporate User&amp;nbsp;&amp;nbsp;&amp;nbsp; "this users can login in SSID 2"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In group configuration i have configure DNIS/CLI based configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA client select&lt;/P&gt;&lt;P&gt;Port *&lt;/P&gt;&lt;P&gt;CLI * &lt;/P&gt;&lt;P&gt;DNIS *SSID1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same configuration for SSID 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after that i have creat two more group for TACACS + for Device authentication (Shell command based) (Authentication through AD)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 5 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Full Access&lt;/P&gt;&lt;P&gt;Group 6 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Read Only Access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but now what ever user are in group 5 &amp;amp; 6 those are login in Wifi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how to stop them?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:53:02 GMT</pubDate>
    <dc:creator>hirenparekh12</dc:creator>
    <dc:date>2019-03-11T02:53:02Z</dc:date>
    <item>
      <title>Authentication Problem in ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-problem-in-acs/m-p/2080549#M146570</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have created two ssid on WLC &amp;amp; authentication Via ACS to AD. after that i have configure TACACS+ on same ACS Server but some of the users can login in Wi-Fi which are not in member of Wi-Fi group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the below ACS configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 1 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;nbsp; HIgh managemnet Users&amp;nbsp; " this user can login in SSID 1"&lt;/P&gt;&lt;P&gt;Group 3 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Corporate User&amp;nbsp;&amp;nbsp;&amp;nbsp; "this users can login in SSID 2"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In group configuration i have configure DNIS/CLI based configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA client select&lt;/P&gt;&lt;P&gt;Port *&lt;/P&gt;&lt;P&gt;CLI * &lt;/P&gt;&lt;P&gt;DNIS *SSID1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same configuration for SSID 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after that i have creat two more group for TACACS + for Device authentication (Shell command based) (Authentication through AD)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 5 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Full Access&lt;/P&gt;&lt;P&gt;Group 6 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Read Only Access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but now what ever user are in group 5 &amp;amp; 6 those are login in Wifi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how to stop them?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-problem-in-acs/m-p/2080549#M146570</guid>
      <dc:creator>hirenparekh12</dc:creator>
      <dc:date>2019-03-11T02:53:02Z</dc:date>
    </item>
    <item>
      <title>Authentication Problem in ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-problem-in-acs/m-p/2080550#M146577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your authorization rules is the default rule set to Permit? If so please set it to Deny, when ACS is configured brand new the default policies are always set to permit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is not the case please post screenshots of your policies, and also of the authentication report of the user that was allowed access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2012 04:51:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-problem-in-acs/m-p/2080550#M146577</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-12-14T04:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Problem in ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-problem-in-acs/m-p/2080551#M146584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/4/6/118640-Group%201.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configure above setting for SSID 1 in Group 1 &amp;amp; MAP security group (with AD) with Group 1 in external Database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/4/6/118641-Group%202.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configure above setting for SSID 2 in Group 3 &amp;amp; MAP security group (with AD) with Group 3 in external Database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;till the time user maped in Group 3 is not login in group1 SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after that i have configure TACACS + on same server with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 5 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Full Access ( Shell command authorization Set)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 6 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Read Only Access.( Shell command authorization Set)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exp. hparekh is member of Group 6 &amp;amp; Group 3 but now it is login in Group 1 SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/4/6/118642-Tacacs%2B.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the External database setting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/4/6/118643-Database.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Dec 2012 09:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-problem-in-acs/m-p/2080551#M146584</guid>
      <dc:creator>hirenparekh12</dc:creator>
      <dc:date>2012-12-30T09:10:28Z</dc:date>
    </item>
  </channel>
</rss>

