<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.1 questions in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-questions/m-p/1579924#M258421</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find answers inline:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;1) Is it possible&amp;nbsp; to generate report for the users who are inactive for say last 30 days?&amp;nbsp; Customer is looking to audit these users to see if they really need&amp;nbsp; access to any device.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[ANS] You can generate user reports using several items including reports for the last 30 days:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/9/7/9799-User_Reports.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;2)&amp;nbsp; Are there any known issues while assigning the priviligaes level to&amp;nbsp; users. In current implementation of this customer users are always&amp;nbsp; logged into priv 1 though they are assigning the priv level of 5. I&amp;nbsp; understand with ACS 4.x we can enable the exec process and assign the&amp;nbsp; priv under user/group policy. What are the configurations that customer&amp;nbsp; might be possiby missing in this case?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[ANS] You can do exactly the same implementation in ACS 5.x. Simply create Authorization profiles to apply to the users that succesfully authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;3)&amp;nbsp; Is there any SNMP or other notification available in ACS 5.1 where&amp;nbsp; admin can be notified at the time a particulat set of user logs in. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[ANS] You can create "Alarms" that will send notification via e-mail and/or to a syslog server:&lt;/P&gt;&lt;TABLE border="0" cellspacing="0" class="cuesBreadcrumbTable" id="cuesBreadcrumbTable"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;Monitoring and Reports&lt;/SPAN&gt; &amp;gt; &lt;/TD&gt;&lt;TD class="cuesBreadcrumbMore" style="display: none;"&gt;... &amp;gt; &lt;/TD&gt;&lt;TD title="Alarms"&gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;Alarms&lt;/SPAN&gt; &amp;gt; &lt;/TD&gt;&lt;TD title="Thresholds"&gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;Thresholds&lt;/SPAN&gt; &amp;gt; &lt;/TD&gt;&lt;TD&gt;&lt;SPAN class="cuesBreadcrumbLast"&gt;Add&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Dec 2010 09:45:23 GMT</pubDate>
    <dc:creator>Tiago Antunes</dc:creator>
    <dc:date>2010-12-28T09:45:23Z</dc:date>
    <item>
      <title>ACS 5.1 questions</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-questions/m-p/1579923#M258409</link>
      <description>&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Acs Experts,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Need quick answers to few questions related to ACS 5.1 for a customer. I have not used the ACS5.1 yet so watch out for the easy questions &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;1) Is it possible to generate report for the users who are inactive for say last 30 days? Customer is looking to audit these users to see if they really need access to any device.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;2) Are there any known issues while assigning the priviligaes level to users. In current implementation of this customer users are always logged into priv 1 though they are assigning the priv level of 5. I understand with ACS 4.x we can enable the exec process and assign the priv under user/group policy. What are the configurations that customer might be possiby missing in this case?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;3) Is there any SNMP or other notification available in ACS 5.1 where admin can be notified at the time a particulat set of user logs in. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:40:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-questions/m-p/1579923#M258409</guid>
      <dc:creator>sjhamb</dc:creator>
      <dc:date>2019-03-11T00:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 questions</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-questions/m-p/1579924#M258421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find answers inline:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;1) Is it possible&amp;nbsp; to generate report for the users who are inactive for say last 30 days?&amp;nbsp; Customer is looking to audit these users to see if they really need&amp;nbsp; access to any device.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[ANS] You can generate user reports using several items including reports for the last 30 days:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/9/7/9799-User_Reports.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;2)&amp;nbsp; Are there any known issues while assigning the priviligaes level to&amp;nbsp; users. In current implementation of this customer users are always&amp;nbsp; logged into priv 1 though they are assigning the priv level of 5. I&amp;nbsp; understand with ACS 4.x we can enable the exec process and assign the&amp;nbsp; priv under user/group policy. What are the configurations that customer&amp;nbsp; might be possiby missing in this case?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[ANS] You can do exactly the same implementation in ACS 5.x. Simply create Authorization profiles to apply to the users that succesfully authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;3)&amp;nbsp; Is there any SNMP or other notification available in ACS 5.1 where&amp;nbsp; admin can be notified at the time a particulat set of user logs in. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[ANS] You can create "Alarms" that will send notification via e-mail and/or to a syslog server:&lt;/P&gt;&lt;TABLE border="0" cellspacing="0" class="cuesBreadcrumbTable" id="cuesBreadcrumbTable"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;Monitoring and Reports&lt;/SPAN&gt; &amp;gt; &lt;/TD&gt;&lt;TD class="cuesBreadcrumbMore" style="display: none;"&gt;... &amp;gt; &lt;/TD&gt;&lt;TD title="Alarms"&gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;Alarms&lt;/SPAN&gt; &amp;gt; &lt;/TD&gt;&lt;TD title="Thresholds"&gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;Thresholds&lt;/SPAN&gt; &amp;gt; &lt;/TD&gt;&lt;TD&gt;&lt;SPAN class="cuesBreadcrumbLast"&gt;Add&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 09:45:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-questions/m-p/1579924#M258421</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-28T09:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 questions</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-questions/m-p/1579925#M258446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry to bring this post back but I was looking at the ACS 5.x doc and I could not find where I can control the size of the database used on this report. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ACS 4.x if I go to system configuration &amp;gt; logging &amp;gt; TACACS+ Accounting I can tell the ACS what is the size I allow it to keep, but could not find it on ACS 5.x. I need to keep enough for 90 days &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 21:21:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-questions/m-p/1579925#M258446</guid>
      <dc:creator>Rodrigo Gurriti</dc:creator>
      <dc:date>2013-02-15T21:21:46Z</dc:date>
    </item>
  </channel>
</rss>

