<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authorization, restrict commands in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authorization-restrict-commands/m-p/2090646#M205448</link>
    <description>&lt;P&gt;Hello all, I have a problem, I am using ACS 5.3 I have a two set of DeviceGroups (router &amp;amp; switch) and two set of users (G1,G2), here is my question, how can I achieve this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;G1: can hace full access to DeviceGroup1 and DeviceGrup2 --&amp;gt; This works&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here comes the tricky part for me.... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;G2: can have "read only" access to DeviceGroup1 but full access to DeviceGroup2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have anyone asked this before or is there any document&amp;nbsp; on how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:45:35 GMT</pubDate>
    <dc:creator>cgarcia02</dc:creator>
    <dc:date>2019-03-11T02:45:35Z</dc:date>
    <item>
      <title>Authorization, restrict commands</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-restrict-commands/m-p/2090646#M205448</link>
      <description>&lt;P&gt;Hello all, I have a problem, I am using ACS 5.3 I have a two set of DeviceGroups (router &amp;amp; switch) and two set of users (G1,G2), here is my question, how can I achieve this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;G1: can hace full access to DeviceGroup1 and DeviceGrup2 --&amp;gt; This works&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here comes the tricky part for me.... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;G2: can have "read only" access to DeviceGroup1 but full access to DeviceGroup2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have anyone asked this before or is there any document&amp;nbsp; on how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-restrict-commands/m-p/2090646#M205448</guid>
      <dc:creator>cgarcia02</dc:creator>
      <dc:date>2019-03-11T02:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization, restrict commands</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-restrict-commands/m-p/2090647#M205449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Hello Cesar-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;You can definitely do this in ACS. When you are creating your authorization policies you can be very flexible with the way you grant and deny access to your devices. For your example, you can build rules that are based on:&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;1. The end user identity group (this can be both internal or AD)&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;2. The devices type (Switches, routers, etc)&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;3. The device location (Campus A, Campus B, etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;So for example, if the user is in the network admin group then he/she will be given full access regardless of device location/type (1st screen shot) but if the user is let's say a "switch admin" then that user will be given full access to switches (2nd screen shot) but only read only access to routers (3rd screen shot)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I hope this makes sense!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;Thank you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2012 23:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-restrict-commands/m-p/2090647#M205449</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-11-09T23:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization, restrict commands</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-restrict-commands/m-p/2090648#M205450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Neno, thanks a lot this is what I was looking for, it worked !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2012 17:25:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-restrict-commands/m-p/2090648#M205450</guid>
      <dc:creator>cgarcia02</dc:creator>
      <dc:date>2012-11-12T17:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization, restrict commands</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-restrict-commands/m-p/2090649#M205451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to hear and glad I could help! &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2012 18:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-restrict-commands/m-p/2090649#M205451</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-11-12T18:31:00Z</dc:date>
    </item>
  </channel>
</rss>

