<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.3 Group Mapping based on AD group membership in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888502#M202751</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What patch level of ACS are you on? Please install patch 4 there are a few bug fixes that fix the group retrieval issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are a list of bugs in patch 3 that are fixed: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp223113"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp223113&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are a list of bugs fixed in patch 4 - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp223684"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp223684&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 May 2012 07:32:07 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-05-02T07:32:07Z</dc:date>
    <item>
      <title>ACS 5.3 Group Mapping based on AD group membership</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888501#M202750</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am configuring a new ACS 5.3 system. Part of the rules is that I want to match the users specific AD group membership, and match appropriatly to an identity group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i'm trying to do is say that if the user is a member of the AD Group (G-CRP-SEC-ENG) then associate them with the Identity Group SEC-ENG. The under the access service, authorization portion, i assign shell profiles and command sets based on Identity Group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that the ACS server will not match the AD Group for the user, and it will match the Default of teh Group Mapping portion of the policy every time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried several configuration choices from : AD1:ExternalGroups contains any &amp;lt;string showing in AD&amp;gt;, AD1:memberOf &amp;lt;group&amp;gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something special i need to do in the Group Mapping Policy to get it to match and active directory group and result in assigning the host to an Identity Group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Sami&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888501#M202750</guid>
      <dc:creator>Sami Abunasser</dc:creator>
      <dc:date>2019-03-11T02:03:25Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 Group Mapping based on AD group membership</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888502#M202751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What patch level of ACS are you on? Please install patch 4 there are a few bug fixes that fix the group retrieval issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are a list of bugs in patch 3 that are fixed: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp223113"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp223113&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are a list of bugs fixed in patch 4 - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp223684"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp223684&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 07:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888502#M202751</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-05-02T07:32:07Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 Group Mapping based on AD group membership</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888503#M202752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running the latest code patch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version 5.3.0.40.4&lt;/P&gt;&lt;P&gt;Last Patch : 5-3-0-40-4 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Sami&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 18:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888503#M202752</guid>
      <dc:creator>Sami Abunasser</dc:creator>
      <dc:date>2012-05-02T18:51:35Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 Group Mapping based on AD group membership</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888504#M202753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I'm facing similar issue. In my case, the identity group won't match the authorization profile i defined. Is it a know bug and Cisco is working with a fix with this?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 21:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888504#M202753</guid>
      <dc:creator>cybernetops</dc:creator>
      <dc:date>2012-07-24T21:44:15Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 Group Mapping based on AD group membership</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888505#M202754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So the question is why do you want to use identity groups to accomplish this? You can use the AD groupd directly in the authorization policies and set the levels of access accordingly, bypassing this extra step of identity group mappings. There might be a legit reason why you still need group mapping but if you are hitting a bug then try just going straight to AD for group matches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most people think that ACS 5.x must work the same as 4.x with the group mapping being required when in 5.x its optional.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jim Thomas &lt;BR /&gt;Cisco Security Course Director &lt;BR /&gt;Global Knowledge &lt;BR /&gt;CCIE Security #16674&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 22:53:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888505#M202754</guid>
      <dc:creator>Jim Thomas</dc:creator>
      <dc:date>2012-07-24T22:53:53Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 Group Mapping based on AD group membership</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888506#M202755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, my case is like this.&lt;/P&gt;&lt;P&gt;I use ACS 5.3 for VPN authentication, using AD and an external RSA for token authentication (2 factor authentication)&lt;/P&gt;&lt;P&gt;I didn't add all the VPN users in the ACS, because it will be troublesome, the users authentication will be managed by AD and RSA server.&lt;/P&gt;&lt;P&gt;In some cases where we need to restrict a group of user to only access certain resources, downloadable ACL is used.&lt;/P&gt;&lt;P&gt;Following the Cisco docs, i manage to get downloadable ACL works when the authorization profile matching criteria is username, but when i change the matching criteria to Identity group, the downloadable ACL won't work.&lt;/P&gt;&lt;P&gt;I have a case with Cisco engineer now and still in the middle to sort things out.&lt;/P&gt;&lt;P&gt;The advice from the Cisco engineer is to have the Access Service set to Internal User instead of RSA server, but that will require us(the admin) to import all the VPN users into the ACS database.&lt;/P&gt;&lt;P&gt;Wondering whether there is a fix for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jul 2012 14:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888506#M202755</guid>
      <dc:creator>cybernetops</dc:creator>
      <dc:date>2012-07-25T14:43:23Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 Group Mapping based on AD group membership</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888507#M202756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found a solution for my case -&amp;gt; identity store sequence.&lt;/P&gt;&lt;P&gt;By adjusting the identity store sequence, i manage to fulfill my environment for group level downloadable ACLs.&lt;/P&gt;&lt;P&gt;I'll leave the comment here for other's reference &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jul 2012 18:42:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888507#M202756</guid>
      <dc:creator>cybernetops</dc:creator>
      <dc:date>2012-07-25T18:42:40Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 Group Mapping based on AD group membership</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888508#M202757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Netops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you explain your solution a little bit more? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards / Karsten&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 09:41:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-group-mapping-based-on-ad-group-membership/m-p/1888508#M202757</guid>
      <dc:creator>Karsten Jaschultowski</dc:creator>
      <dc:date>2012-07-31T09:41:20Z</dc:date>
    </item>
  </channel>
</rss>

