<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.3 / Cisco MDS - End Station Filter with ip domain-lookup a in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961298#M201283</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ludovic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is not an easy workaround for this issue. We can remove the PTR records on your dns server (which I am sure is not feasible). Since the packet is originating from the MDS I am pretty sure today that the ACS isn't able to detect and "convert" the remote address attribute via dns (with command authorization this can really bog the box down if a feature like this existed). You can try to open a service request with the MDS product team and see if they can leave ip address in the remote address field. You can try to explore either of these options within Cisco. As far as a workaround it looks like you can remove the ip domain lookup (which you identified), use a pattern if one is present in the workstation, or rename the workstations, if manageable, and create a compound condition that also checks the remote address field. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if all the workstations are named adminpc, adminpc1...adminpcn, then you can use the contains operation and set that to adminpc for the remote address field, combine that with your mds network device groups and then set the proper authorization for the users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Aug 2012 09:48:03 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-08-02T09:48:03Z</dc:date>
    <item>
      <title>ACS 5.3 / Cisco MDS - End Station Filter with ip domain-lookup activated</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961295#M201277</link>
      <description>&lt;P&gt;ACS Version :&lt;STRONG&gt; 5.3.0.40.5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Cisco MDS with system version &lt;STRONG&gt;4.1(3a)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some accounts have a dedicated policy which allows access only from a specific IP address (by using the &lt;STRONG&gt;End Station Filter&lt;/STRONG&gt; on the ACS). But with Cisco MDS boxes, which have "&lt;STRONG&gt;ip domain-lookup&lt;/STRONG&gt;" activated, MDS resolved the IP address and replace it by the name of the server in the TACACS+ packet... the "End Station Filter" doesn't match (IP address expected) and access to the MDS is denied. After digging through NX-OS I didn't find any directive disabling name-resolution for TACACS+ exchanges. Is there a way to make an "End Station Filter" based on domain name on the ACS ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;End Station Filter is configured as follow :&lt;/P&gt;&lt;P&gt;Policy Elements --&amp;gt; Session Conditions --&amp;gt; Network Conditions --&amp;gt; End Station Filters and in the "IP address" tab I add IP address from which access should be granted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961295#M201277</guid>
      <dc:creator>ludovicterrier</dc:creator>
      <dc:date>2019-03-11T02:22:16Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 / Cisco MDS - End Station Filter with ip domain-lookup a</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961296#M201279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ludovic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the pdf of the report that is generated by the MDS entry, or can you post a screenshot?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2012 15:02:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961296#M201279</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-01T15:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.3 / Cisco MDS - End Station Filter with ip domain-look</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961297#M201281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find attached the screenshot showing denied acces for MDS box and content of "Remote address" field.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2012 09:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961297#M201281</guid>
      <dc:creator>ludovicterrier</dc:creator>
      <dc:date>2012-08-02T09:28:05Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 / Cisco MDS - End Station Filter with ip domain-lookup a</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961298#M201283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ludovic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is not an easy workaround for this issue. We can remove the PTR records on your dns server (which I am sure is not feasible). Since the packet is originating from the MDS I am pretty sure today that the ACS isn't able to detect and "convert" the remote address attribute via dns (with command authorization this can really bog the box down if a feature like this existed). You can try to open a service request with the MDS product team and see if they can leave ip address in the remote address field. You can try to explore either of these options within Cisco. As far as a workaround it looks like you can remove the ip domain lookup (which you identified), use a pattern if one is present in the workstation, or rename the workstations, if manageable, and create a compound condition that also checks the remote address field. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if all the workstations are named adminpc, adminpc1...adminpcn, then you can use the contains operation and set that to adminpc for the remote address field, combine that with your mds network device groups and then set the proper authorization for the users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2012 09:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961298#M201283</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-02T09:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.3 / Cisco MDS - End Station Filter with ip domain-look</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961299#M201285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you said, removing PTR record from our DNS servers is not possible. Moreover, deactivating the "ip domain-lookup" isn't possible too (option needed for some other usage), so I'll see with Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2012 14:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961299#M201285</guid>
      <dc:creator>ludovicterrier</dc:creator>
      <dc:date>2012-08-02T14:43:25Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 / Cisco MDS - End Station Filter with ip domain-lookup a</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961300#M201287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Was this ever resolved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're hitting the samthing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 12:24:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961300#M201287</guid>
      <dc:creator>shawn</dc:creator>
      <dc:date>2013-06-13T12:24:36Z</dc:date>
    </item>
    <item>
      <title>I got it to work by adding</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961301#M201289</link>
      <description>&lt;P&gt;I got it to work by adding the DNS name into the CLI/DNSI section of End Station Filters. &amp;nbsp;Check the "remote address" in the&amp;nbsp;ACS logs to make sure you get the exact name that is being sent to ACS from the device. &amp;nbsp;I had to enter in the FQDN for each end station.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2014 20:07:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-cisco-mds-end-station-filter-with-ip-domain-lookup/m-p/1961301#M201289</guid>
      <dc:creator>William Everett</dc:creator>
      <dc:date>2014-11-25T20:07:03Z</dc:date>
    </item>
  </channel>
</rss>

