<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS for user in multiple groups in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086421#M152375</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem! I have had issues in the past when the local and the domain user are the same. You can still get around that by defining what identity stores are used (for example, excluding the internal user database) and/or by properly constructing your authorization rules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, do are you using ACS 4.x or 5.x?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Nov 2012 18:53:36 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2012-11-09T18:53:36Z</dc:date>
    <item>
      <title>TACACS for user in multiple groups</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086418#M152297</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Quick question about TACACS and a user that needs to be in more than 1 group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a networkAdmins group that is linked to the AD domain Admins group with a network admin in it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;w then have another group for firewalls which is linked to firewall access group in AD one user is in both groups which have both been created using a manual mapping in TACACS but the user is only showing up in the NetworkAdmin group not in the firewall admin group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas why the user is not showing up or is this even possible&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:45:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086418#M152297</guid>
      <dc:creator>John.Mason1978</dc:creator>
      <dc:date>2019-03-11T02:45:29Z</dc:date>
    </item>
    <item>
      <title>TACACS for user in multiple groups</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086419#M152318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have a user be part of more than one group. You just need to make sure that both of the groups are pulled from AD and then you can build your authorization rules based on that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this makes sense or if you need more details. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 18:51:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086419#M152318</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-11-08T18:51:07Z</dc:date>
    </item>
    <item>
      <title>TACACS for user in multiple groups</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086420#M152343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Neo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the fast reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that makes sense&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so my user for example currently is in the network admins group populated via AD but there are ACS local users in that group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if i remove the local users then the ad should populate both groups with my user&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2012 09:37:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086420#M152343</guid>
      <dc:creator>John.Mason1978</dc:creator>
      <dc:date>2012-11-09T09:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS for user in multiple groups</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086421#M152375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem! I have had issues in the past when the local and the domain user are the same. You can still get around that by defining what identity stores are used (for example, excluding the internal user database) and/or by properly constructing your authorization rules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, do are you using ACS 4.x or 5.x?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2012 18:53:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086421#M152375</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-11-09T18:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS for user in multiple groups</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086422#M152414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I inherrited this system, its version 4 and this excercise has prompted us to redesign the acs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2012 18:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086422#M152414</guid>
      <dc:creator>John.Mason1978</dc:creator>
      <dc:date>2012-11-09T18:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS for user in multiple groups</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086423#M152444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Those are always nice when you inherit these type of systems. I don't know if you have had any experience with 5.x but I highly recommend migrating to it. It is much nicer in terms of building blocks, logging, monitoring etc and it does not run on Windows &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2012 19:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-for-user-in-multiple-groups/m-p/2086423#M152444</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-11-09T19:04:18Z</dc:date>
    </item>
  </channel>
</rss>

