<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACS 5.3 - How to only allow specific AD groups to login in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066722#M205464</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you.&amp;nbsp; I found the problem with your assistance.&amp;nbsp; Had the permit set. Then set it to DenyAccess.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Nov 2012 17:28:42 GMT</pubDate>
    <dc:creator>jeff.ortega</dc:creator>
    <dc:date>2012-11-08T17:28:42Z</dc:date>
    <item>
      <title>Cisco ACS 5.3 - How to only allow specific AD groups to login</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066720#M205457</link>
      <description>&lt;P&gt;Can anyone help me figure out what I have wrong or have missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured three specific AD groups, Admin, Storage, and HelpDesk, with their own commands sets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems to be working fine, but everyone can log into everything, but they can't do anything except exit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goal is to not allow anyone to login that is not part of the three AD groups I have specified with the respective command sets.&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/8/3/9/110938-11-5-2012%2011-02-03%20AM.jpg" alt="11-5-2012 11-02-03 AM.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the logins hit the Admin account, even though the id in AD is not in the that AD group.&amp;nbsp; I have something screwed up.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066720#M205457</guid>
      <dc:creator>jeff.ortega</dc:creator>
      <dc:date>2019-03-11T02:44:53Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 - How to only allow specific AD groups to login</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066721#M205462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check your authorization rules, make sure the default rule isnt set to Permit. Group Mapping is only mapping AD groups to internal ACS groups, we need to check your authorization rules to see which policies they users are hitting, you may want to reset the hit count and test to see which policy is allowing access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2012 21:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066721#M205462</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-11-05T21:42:56Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 - How to only allow specific AD groups to login</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066722#M205464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you.&amp;nbsp; I found the problem with your assistance.&amp;nbsp; Had the permit set. Then set it to DenyAccess.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 17:28:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066722#M205464</guid>
      <dc:creator>jeff.ortega</dc:creator>
      <dc:date>2012-11-08T17:28:42Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 - How to only allow specific AD groups to login</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066723#M205467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a similar setup but i do not see a deny access authorization profile to use for the default. can you explain how you set the default to deny access&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 01:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066723#M205467</guid>
      <dc:creator>dpatzold1979</dc:creator>
      <dc:date>2013-01-30T01:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.3 - How to only allow specific AD groups to logi</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066724#M205473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Under authorization, check the check box for default, click on Edit and select the deny access profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/3/2/127230-Untitled.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Minakshi (do rate the helpful post)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 01:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066724#M205473</guid>
      <dc:creator>minkumar</dc:creator>
      <dc:date>2013-01-30T01:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.3 - How to only allow specific AD groups to logi</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066725#M205475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Somthing must be broken for my install of 5.4 because i do not have a deny access authorization profile.. only permit access &lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/3/2/127232-2013-01-29_174554.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 01:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066725#M205475</guid>
      <dc:creator>dpatzold1979</dc:creator>
      <dc:date>2013-01-30T01:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.3 - How to only allow specific AD groups to logi</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066726#M205482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;UG never mind.. you have to acctually click on select button to see the deny access profile which does not show up in the policy elements..&amp;nbsp; thanks man it worked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 01:58:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-how-to-only-allow-specific-ad-groups-to-login/m-p/2066726#M205482</guid>
      <dc:creator>dpatzold1979</dc:creator>
      <dc:date>2013-01-30T01:58:46Z</dc:date>
    </item>
  </channel>
</rss>

