<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS5 - Replacement for IP Pools in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs5-replacement-for-ip-pools/m-p/2082871#M150704</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the ASA it's the Attribute 217 "Address-Pools":&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ref_extserver.html#wp1802187"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ref_extserver.html#wp1802187&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 27 Jan 2013 13:46:13 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2013-01-27T13:46:13Z</dc:date>
    <item>
      <title>ACS5 - Replacement for IP Pools</title>
      <link>https://community.cisco.com/t5/network-access-control/acs5-replacement-for-ip-pools/m-p/2082870#M150656</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know ACS 5 lacks the IP Pools of earlier ACS versions. I'm looking at a 4 to 5 migration and was thinking of just configuring the IP Pools on the router ("ip pool local" etc) and sending back a RADIUS Cisco Attribute pair with the name of the pool. (Seemed like a neat fix, needs no extra kit, etc.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could have sworn that attribute pair existed... but I can't find it in ACS5! What's it's name?! Where is it!? Or have I gone mad!? (And, if I have gone mad, how would you go about fixing it?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:01:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs5-replacement-for-ip-pools/m-p/2082870#M150656</guid>
      <dc:creator>Paul Masterton</dc:creator>
      <dc:date>2019-03-11T03:01:02Z</dc:date>
    </item>
    <item>
      <title>ACS5 - Replacement for IP Pools</title>
      <link>https://community.cisco.com/t5/network-access-control/acs5-replacement-for-ip-pools/m-p/2082871#M150704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the ASA it's the Attribute 217 "Address-Pools":&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ref_extserver.html#wp1802187"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/ref_extserver.html#wp1802187&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2013 13:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs5-replacement-for-ip-pools/m-p/2082871#M150704</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-01-27T13:46:13Z</dc:date>
    </item>
    <item>
      <title>ACS5 - Replacement for IP Pools</title>
      <link>https://community.cisco.com/t5/network-access-control/acs5-replacement-for-ip-pools/m-p/2082872#M150746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two attributs regarding the pools:&lt;/P&gt;&lt;P&gt;217&amp;nbsp;&amp;nbsp;&amp;nbsp; cisco-ip-pool-definition&lt;/P&gt;&lt;P&gt;218&amp;nbsp;&amp;nbsp;&amp;nbsp; cisco-assign-ip-pool&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those are configurable in ACS 5.x from ACS GUI:&lt;/P&gt;&lt;P&gt;Policy Elements -&amp;gt; Authorization and Permissions -&amp;gt; Network Access -&amp;gt; Authorization Profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You create the authorization profile then from the "Radius Attributes" tab you choose the directory type = "RADIUS-Cisco".&lt;/P&gt;&lt;P&gt;Then if you press on the "select" button beside "RADIUS Attribute" field it will list you all the cisco attributes where 217 and 218 are included.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2013 06:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs5-replacement-for-ip-pools/m-p/2082872#M150746</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-01-28T06:57:15Z</dc:date>
    </item>
    <item>
      <title>ACS5 - Replacement for IP Pools</title>
      <link>https://community.cisco.com/t5/network-access-control/acs5-replacement-for-ip-pools/m-p/2082873#M150812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So then how do we define the pools? There's a lot of discussion regarding this topic. I'm not exactlly sure why Ciso thought it was a good idea to remove this feature but I know there's a workaround.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The workaround I saw was to use pre defined pools from another device such as a router. That's fine but whats the ACS config to do that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Someone has to know the answer to this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 15:39:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs5-replacement-for-ip-pools/m-p/2082873#M150812</guid>
      <dc:creator>codewize</dc:creator>
      <dc:date>2013-12-12T15:39:59Z</dc:date>
    </item>
  </channel>
</rss>

