<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Seperate AD users to different authorization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/seperate-ad-users-to-different-authorization/m-p/2001669#M182106</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If there is no group or attribute in AD to define the conditions then need to create conditions based on username&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two attributes that can use&lt;/P&gt;&lt;P&gt;- User-Name attribute in RADIUS IETF dictionary; this is username as presented in original RADIUS request&lt;/P&gt;&lt;P&gt;- UserName attribute in System dictionary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For protocol like PAP this will be the same; however for protocols where for example the initial username is presented as anonymous then the UserName attribute will contain the actual user name after all the prococol negociation and session establishment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in general is always best to use the attribute in the system dictionary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can select this as a contion by pressing "Customize" and selecting "System:UserName" as the condition&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There needs to be one rule per user; with large numbers does not scale as well as group or attribute based rules&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Jun 2012 15:41:15 GMT</pubDate>
    <dc:creator>jrabinow</dc:creator>
    <dc:date>2012-06-01T15:41:15Z</dc:date>
    <item>
      <title>Seperate AD users to different authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/seperate-ad-users-to-different-authorization/m-p/2001668#M182100</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my another question after the command set. How to seperate the AD users for different authorization instead of using AD group? i currently do now is using AD group to control a few users for the authorization on the switch. However, customer requested for different AD users need have different authorization. Any idea for this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks and regards&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/seperate-ad-users-to-different-authorization/m-p/2001668#M182100</guid>
      <dc:creator>siangyankhoo</dc:creator>
      <dc:date>2019-03-11T02:09:18Z</dc:date>
    </item>
    <item>
      <title>Seperate AD users to different authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/seperate-ad-users-to-different-authorization/m-p/2001669#M182106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If there is no group or attribute in AD to define the conditions then need to create conditions based on username&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two attributes that can use&lt;/P&gt;&lt;P&gt;- User-Name attribute in RADIUS IETF dictionary; this is username as presented in original RADIUS request&lt;/P&gt;&lt;P&gt;- UserName attribute in System dictionary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For protocol like PAP this will be the same; however for protocols where for example the initial username is presented as anonymous then the UserName attribute will contain the actual user name after all the prococol negociation and session establishment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in general is always best to use the attribute in the system dictionary&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can select this as a contion by pressing "Customize" and selecting "System:UserName" as the condition&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There needs to be one rule per user; with large numbers does not scale as well as group or attribute based rules&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 15:41:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/seperate-ad-users-to-different-authorization/m-p/2001669#M182106</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2012-06-01T15:41:15Z</dc:date>
    </item>
  </channel>
</rss>

