<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.1 internal users in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-internal-users/m-p/1543079#M259532</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stevie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, it should work as you are planning to and it is a clever was of achieving it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Oct 2010 09:22:07 GMT</pubDate>
    <dc:creator>Tiago Antunes</dc:creator>
    <dc:date>2010-10-19T09:22:07Z</dc:date>
    <item>
      <title>ACS 5.1 internal users</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-internal-users/m-p/1543077#M259447</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an customer with an ACS config that has an identity store sequence to authenticate agains for tacacs.&amp;nbsp; First the internal database is checked for the user.&amp;nbsp; If they do not exist there they are checked against AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the user is one of the 200+ they have migrated from an ACS 4 config into internal users they want to give them full enable access.&amp;nbsp; If the user is not in the internal database and needs verified via AD they only get priv 1 access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there an easy way to create an Authorization rule in the default device admin service selection rule to do this. ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to test via a compound Condition.&amp;nbsp; The condition matches the Dictionary Internal Users group attribute with a value of All Groups.&amp;nbsp; I cannot connect to AD at the moment to test this as it's in a lab environment but I'm hoping that when this rule is checked then only users that are explicitly in the internal database via the All Groups condition will match.&amp;nbsp; If the user was matched via AD this rule won't match and the next one will come into effect which is a default rule to give priv 1 access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have any thoughts on this method ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks, Stephen.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:30:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-internal-users/m-p/1543077#M259447</guid>
      <dc:creator>StevieOliver_2</dc:creator>
      <dc:date>2019-03-11T00:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 internal users</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-internal-users/m-p/1543078#M259470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Excuse my stupidity.&amp;nbsp; There is an Identity group condi&lt;SPAN style="background-color: #f8fafd;"&gt;tion in the Authorization rules page for this.&amp;nbsp; I don't need and compound condition.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;My intention is to match on Any Group there and apply priv 15 access with a shell profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I will then leave the default rule to catch all others which go to AD for authentication.&amp;nbsp; I assume they will not match the Any Groups Identity Group so will use the default rule.&amp;nbsp; I'll then apply the appropriate shell profile to the default rule.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks, Stephen.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Oct 2010 09:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-internal-users/m-p/1543078#M259470</guid>
      <dc:creator>StevieOliver_2</dc:creator>
      <dc:date>2010-10-19T09:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 internal users</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-internal-users/m-p/1543079#M259532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stevie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, it should work as you are planning to and it is a clever was of achieving it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Oct 2010 09:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-internal-users/m-p/1543079#M259532</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-10-19T09:22:07Z</dc:date>
    </item>
  </channel>
</rss>

