<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.2 group mapping with LDAP external identity store in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-group-mapping-with-ldap-external-identity-store/m-p/1720880#M261342</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Suggest to go to "&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;Monitoring &amp;amp; Reports &amp;gt; Reports &amp;gt; Catalog &amp;gt; AAA Protocol"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;Select TACACS Authorization and see the authorizations that occured today&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;If you click on the details icon you should be able to see the actual LDAP groups that were retrieved in processing the request and so can see that the format/contents matches that which you entered&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 May 2011 20:43:56 GMT</pubDate>
    <dc:creator>jrabinow</dc:creator>
    <dc:date>2011-05-19T20:43:56Z</dc:date>
    <item>
      <title>ACS 5.2 group mapping with LDAP external identity store</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-group-mapping-with-ldap-external-identity-store/m-p/1720879#M261314</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a new Cisco Secure ACS 5.2 on a VM. We want to use it to for administrative access to our Cisco equipment&amp;nbsp; with TACACS+. I am trying to map user permissions to different groups of devices based on active directory group membership, however it is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using an LDAP (configured for secure authentication) external identity store. On the directory organization tab, I have confirmed the accuracy of the subject and group search base and the test configuration button shows that it's finding &amp;gt; 100 users and &amp;gt;100 groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the directory groups page I have entered the groups according to the required format.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;cn=groupname1,ou=groups,dc=abc,dc=com&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a rule based result selection under group mapping. I have two rules in the format below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Conditon&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LDAP:Externalgroups groupname1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Result&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Identitygroup1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the default group set to a identity group named other. My problem is, no matter what user attempts to authenticate, the Default rule is applied, and the user is put into the other identity group.This occurs when I log on as a groupname1 user, groupname2 user, or as user that is not a member of either of those groups. LDAP authentication works and the user is able to logon to the device. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't seem to figure out why this is going on.&amp;nbsp; I would greatly appreciate any help in troubleshooting. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-group-mapping-with-ldap-external-identity-store/m-p/1720879#M261314</guid>
      <dc:creator>Andrew Bailey</dc:creator>
      <dc:date>2019-03-11T01:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 group mapping with LDAP external identity store</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-group-mapping-with-ldap-external-identity-store/m-p/1720880#M261342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Suggest to go to "&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;Monitoring &amp;amp; Reports &amp;gt; Reports &amp;gt; Catalog &amp;gt; AAA Protocol"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;Select TACACS Authorization and see the authorizations that occured today&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;If you click on the details icon you should be able to see the actual LDAP groups that were retrieved in processing the request and so can see that the format/contents matches that which you entered&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2011 20:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-group-mapping-with-ldap-external-identity-store/m-p/1720880#M261342</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-05-19T20:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 group mapping with LDAP external identity store</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-group-mapping-with-ldap-external-identity-store/m-p/1720881#M261387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, that is where I am seeing the Identity group assigned is "Other" when it should be "intentitygroup1" or "intentitygroup2"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Other attributes I see all the the external groups that my user account is a member of, including my "grouname1" that I have defined in the LDAP Directory groups tab and that mapped to my identity group in my rule based group mapping. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like this &lt;/P&gt;&lt;P&gt;ExternalGroups=CN=groupname1,OU=Groups,DC=abc,DC=com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So LDAP is looking up my group membership fine... it's just not applying in my group mapping policy. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 May 2011 11:20:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-group-mapping-with-ldap-external-identity-store/m-p/1720881#M261387</guid>
      <dc:creator>Andrew Bailey</dc:creator>
      <dc:date>2011-05-20T11:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 group mapping with LDAP external identity store</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-group-mapping-with-ldap-external-identity-store/m-p/1720882#M261442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I figured out the problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the LDAP directory groups page, my group was not displayed in the first 100 groups shown, so I could not select it and had to type it out. It turns out that it is case sensitive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;This doesn't work: &lt;BR /&gt;cn=groupname1,ou=groups,dc=abc,dc=com&lt;SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this does:&lt;/P&gt;&lt;/SPAN&gt;CN=Groupname1,OU=Groups,DC=abc,DC=com&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 May 2011 11:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-group-mapping-with-ldap-external-identity-store/m-p/1720882#M261442</guid>
      <dc:creator>Andrew Bailey</dc:creator>
      <dc:date>2011-05-20T11:45:26Z</dc:date>
    </item>
  </channel>
</rss>

