<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS Location Access Control.. How? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-location-access-control-how/m-p/1671108#M233553</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How about something like this ?&lt;/P&gt;&lt;P&gt;If device.location=location1 and if user belongs to group x,y, or z then grant access&lt;/P&gt;&lt;P&gt;If device.location=location and if user belongs to group x only then grant access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in all other cases deny access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use user groups or usernames directly depending on the similarities between users and what's easiest.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 30 Apr 2011 06:18:58 GMT</pubDate>
    <dc:creator>Nicolas Darchis</dc:creator>
    <dc:date>2011-04-30T06:18:58Z</dc:date>
    <item>
      <title>ACS Location Access Control.. How?</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-location-access-control-how/m-p/1671107#M233537</link>
      <description>&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; "&gt;I have spent 2 days trying to get Location based access working and can't figure it out.&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;I have ACS 5.2 installed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; "&gt;My setup is as follows.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; "&gt;6 Locations&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; "&gt;2-3 Administrators per location then 3 Administrators for all locations.&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; "&gt;We want to grant access by Location of the Device to AD Accounts.&amp;nbsp; Then we want 3 Admins to have access to all Locations.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif;"&gt;I have been testing with Riverbeds using TACACS and can get a user working but once I have another user from the All Access group they don't work.&amp;nbsp; I get a 22056 Error.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: arial,helvetica,sans-serif; "&gt;Anyone have something like this working and would not mind explaining to me how to use this convoluted product.&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:02:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-location-access-control-how/m-p/1671107#M233537</guid>
      <dc:creator>rfc791-cisco</dc:creator>
      <dc:date>2019-03-11T01:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Location Access Control.. How?</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-location-access-control-how/m-p/1671108#M233553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How about something like this ?&lt;/P&gt;&lt;P&gt;If device.location=location1 and if user belongs to group x,y, or z then grant access&lt;/P&gt;&lt;P&gt;If device.location=location and if user belongs to group x only then grant access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in all other cases deny access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use user groups or usernames directly depending on the similarities between users and what's easiest.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Apr 2011 06:18:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-location-access-control-how/m-p/1671108#M233553</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-04-30T06:18:58Z</dc:date>
    </item>
  </channel>
</rss>

