<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Some ACS5.3 issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961963#M202103</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Not sure if your description is clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access Service Selection Rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is evaluated top down. If there is a match on a certain rule the result will be applied which will be an access service&lt;/P&gt;&lt;P&gt;if there is no match you should move to the next Rule , there will be a comparison and if there is no match you keep going &lt;/P&gt;&lt;P&gt;untill you hit the default rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customizing certain conidtions and results in the authorization policy depends on what you want to configure and have in your production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you be more specific what is your issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the meantime i recommend you to read more abotu the policy based model in ACS 5 which is detailed in the ACS user guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Don't forget to rate correct answers &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Jun 2012 12:01:33 GMT</pubDate>
    <dc:creator>maldehne</dc:creator>
    <dc:date>2012-06-22T12:01:33Z</dc:date>
    <item>
      <title>Some ACS5.3 issues</title>
      <link>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961962#M202102</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trying to work out how to get these access policies on ACS 5.3 to work &lt;/P&gt;&lt;P&gt;one after the other and other issues with access policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1, If i go to Access policies/Access services/Service selection rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then the rules seem to be hit from the top down.&lt;/P&gt;&lt;P&gt;However if you are not permitted in the top rule you just seem to be dropped&lt;/P&gt;&lt;P&gt;How can i make it so that if the first service selection rule is not matched&lt;/P&gt;&lt;P&gt;it goes to the next one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. On these policies i need to modify the authorisations using customize -&lt;/P&gt;&lt;P&gt;why cant i modify the customize results on these ?&lt;/P&gt;&lt;P&gt;i cant see how i can point these at a shell profile otherwise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:13:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961962#M202102</guid>
      <dc:creator>steve switzer</dc:creator>
      <dc:date>2019-03-11T02:13:24Z</dc:date>
    </item>
    <item>
      <title>Some ACS5.3 issues</title>
      <link>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961963#M202103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Not sure if your description is clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access Service Selection Rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is evaluated top down. If there is a match on a certain rule the result will be applied which will be an access service&lt;/P&gt;&lt;P&gt;if there is no match you should move to the next Rule , there will be a comparison and if there is no match you keep going &lt;/P&gt;&lt;P&gt;untill you hit the default rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customizing certain conidtions and results in the authorization policy depends on what you want to configure and have in your production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you be more specific what is your issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the meantime i recommend you to read more abotu the policy based model in ACS 5 which is detailed in the ACS user guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Don't forget to rate correct answers &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2012 12:01:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961963#M202103</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2012-06-22T12:01:33Z</dc:date>
    </item>
    <item>
      <title>Some ACS5.3 issues</title>
      <link>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961964#M202104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i want is to have a service selection policy consisting of a numbetr of rules&lt;/P&gt;&lt;P&gt;For instance&amp;nbsp; &lt;/P&gt;&lt;P&gt;1. For admin access to all network devices&lt;/P&gt;&lt;P&gt;2. One for the service desk to only access lobby ambassador&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately if i hit the service desk rule first i get the following error -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left; padding-left: 5pt; padding-top: 1pt;"&gt;TACACS+ requests can only be processed by Access Services that are of type Device Administration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left; padding-left: 5pt; padding-top: 1pt;"&gt;and&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left; padding-left: 5pt; padding-top: 1pt;"&gt;Verify that the Service Selection Policy rules are correct&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left; padding-left: 5pt; padding-top: 1pt;"&gt;I have a rule called Default admin - but how do&amp;nbsp; i know the access services&lt;/P&gt;&lt;P style="text-align: left; padding-left: 5pt; padding-top: 1pt;"&gt;are of that type.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left; padding-left: 5pt; padding-top: 1pt;"&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2012 13:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961964#M202104</guid>
      <dc:creator>steve switzer</dc:creator>
      <dc:date>2012-06-22T13:01:22Z</dc:date>
    </item>
    <item>
      <title>Some ACS5.3 issues</title>
      <link>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961965#M202105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This means that the access policy that applies for the login is not of a device administration type, but rather network access, for example,&amp;nbsp; a vpn user trying to authenticate to get access to the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jatin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2012 13:09:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961965#M202105</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2012-06-22T13:09:26Z</dc:date>
    </item>
    <item>
      <title>Some ACS5.3 issues</title>
      <link>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961966#M202106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sorry if i seem a bit dense but how do you determine which acicess policy is a device admin type and which network&lt;/P&gt;&lt;P&gt;that is which exact setting - does it have to be using the default device admin service for instance...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2012 13:17:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961966#M202106</guid>
      <dc:creator>steve switzer</dc:creator>
      <dc:date>2012-06-22T13:17:51Z</dc:date>
    </item>
    <item>
      <title>Some ACS5.3 issues</title>
      <link>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961967#M202107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sir there are two default access services ( network and device admin )&lt;/P&gt;&lt;P&gt; ACS uses by default the protocol as condition to select certain access service.&lt;/P&gt;&lt;P&gt;If the protocol is Tacacs+ , certain service is selected&lt;/P&gt;&lt;P&gt;if it is RADIUS a nother one is selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need to be more granular just customize your conditions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Please Don't Forget to rate correct answer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2012 13:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961967#M202107</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2012-06-22T13:37:21Z</dc:date>
    </item>
    <item>
      <title>Some ACS5.3 issues</title>
      <link>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961968#M202108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;TACACS+ requests can only be handled by access services with the Service Type set to "Device Administration". You need to check if this is what you have selected. User Selected Service Type&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would help you understanidng it.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.ciscopress.com/articles/article.asp?p=1671906&amp;amp;seqNum=5"&gt;http://www.ciscopress.com/articles/article.asp?p=1671906&amp;amp;seqNum=5&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2012 14:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961968#M202108</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2012-06-22T14:19:30Z</dc:date>
    </item>
    <item>
      <title>Some ACS5.3 issues</title>
      <link>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961969#M202109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help by the way it is greatly appreciated !!&lt;/P&gt;&lt;P&gt;Well i have sorted that out now and the top 2 service&lt;/P&gt;&lt;P&gt;selection rules are both Device administration.&lt;/P&gt;&lt;P&gt;However when i try and access the device with a user who&lt;/P&gt;&lt;P&gt;is referenced in AD in the second rule down it doesn work &lt;/P&gt;&lt;P&gt;and i just hit the default on the authorisation of the first&lt;/P&gt;&lt;P&gt;rule .&lt;/P&gt;&lt;P&gt;Shouldnt i then hit the second service selection rule ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2012 14:43:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961969#M202109</guid>
      <dc:creator>steve switzer</dc:creator>
      <dc:date>2012-06-22T14:43:32Z</dc:date>
    </item>
    <item>
      <title>Some ACS5.3 issues</title>
      <link>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961970#M202110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the link&amp;nbsp; just had a read it seems to suggest that in the&lt;/P&gt;&lt;P&gt;service selection rules you need one service for TACACS and one for&lt;/P&gt;&lt;P&gt;Radius.&lt;/P&gt;&lt;P&gt;I was trying to have 2 services of TACACS - if not found in the first&lt;/P&gt;&lt;P&gt;Service then goes to the second - but thats not how it works - is it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2012 15:10:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/some-acs5-3-issues/m-p/1961970#M202110</guid>
      <dc:creator>steve switzer</dc:creator>
      <dc:date>2012-06-22T15:10:56Z</dc:date>
    </item>
  </channel>
</rss>

