<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Denying AAA Clients to a specific user group in ACS v4.1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293593#M328605</link>
    <description>&lt;P&gt;Using 4.1 is there a "simple" method of simply denying a usergroup the ability to even login to specific AAA clients?  Customer has a telephony group that they want to allow them to telnet and check into all the voice routers, but no other routers, they have the command sets and all that setup but wanted to see if a way to push that group simply to voice routers only ??&lt;/P&gt;&lt;P&gt;thanks in advance,&lt;/P&gt;&lt;P&gt;dave&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 23:45:13 GMT</pubDate>
    <dc:creator>DAVE GENTON</dc:creator>
    <dc:date>2019-03-10T23:45:13Z</dc:date>
    <item>
      <title>Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293593#M328605</link>
      <description>&lt;P&gt;Using 4.1 is there a "simple" method of simply denying a usergroup the ability to even login to specific AAA clients?  Customer has a telephony group that they want to allow them to telnet and check into all the voice routers, but no other routers, they have the command sets and all that setup but wanted to see if a way to push that group simply to voice routers only ??&lt;/P&gt;&lt;P&gt;thanks in advance,&lt;/P&gt;&lt;P&gt;dave&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293593#M328605</guid>
      <dc:creator>DAVE GENTON</dc:creator>
      <dc:date>2019-03-10T23:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293594#M328606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can set it up using NAR in ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_tech_note09186a0080858d3c.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_tech_note09186a0080858d3c.shtml&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 15:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293594#M328606</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-10-23T15:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293595#M328607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I looked at that, but isn't that just simply "network restriction"  I want them to be able to login to all voice routers and execute the "allowed" commands we have listed, but if they login to a data only router, to get denied access altogether, make sense ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 15:49:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293595#M328607</guid>
      <dc:creator>DAVE GENTON</dc:creator>
      <dc:date>2009-10-23T15:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293596#M328608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why don't you use NAR (Network access restriction)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under the network config &amp;gt; simply create one NDG and assign all the voice router under it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that go to the group/user where you want to put this restriction&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to check that what are we getting in calling station id. If we are getting ip address then &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[1] To accomplish above we would configure the group with following &lt;/P&gt;&lt;P&gt;NAR (network access restriction)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Define IP based Network Access Restriction&lt;/P&gt;&lt;P&gt;Permitted Calling Point&lt;/P&gt;&lt;P&gt;AAA client: VOICE NDG created &lt;/P&gt;&lt;P&gt;Port				*&lt;/P&gt;&lt;P&gt;Src IP Address	*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subit the changes and try.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is more on configuring Network Access Restriction:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;2/user/guide/GrpMgt.html#wp478900&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 15:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293596#M328608</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-10-23T15:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293597#M328609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks I will give that a shot, that's what was hanging me up on the NAR was that it showed CLID/DNIS but they are local telnet users...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 15:53:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293597#M328609</guid>
      <dc:creator>DAVE GENTON</dc:creator>
      <dc:date>2009-10-23T15:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293598#M328610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just checked your reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, you need to go bit tricky, looks like that you have data and voice routers and you want no access to data routers and restricted access to voice routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this::&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create two NDG's one for voice routers and other for data router's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to the group &amp;gt; apply NAR on data routers with action as denied. If we are getting anything apart from valid ip address than you have to use CLI/DNIS based NAR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;since you have command set created with specific commands &amp;gt; on the same group &amp;gt; scroll down to the Shell Command Authorization Set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assign a Shell Command Authorization Set on a per Network Device Group Basis&lt;/P&gt;&lt;P&gt;Here you can map VOICE router's NDG with respective command authorization set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this way we can denied access to data routers and restricted access to voice router's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 16:02:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293598#M328610</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-10-23T16:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293599#M328611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do the stars mean, is it a wild card?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I select deny access and all AAA clients and apply it to a group. Does that mean that they will not have access to the AAA client? ie they will not be able to authenticate and log on to a router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 20:32:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293599#M328611</guid>
      <dc:creator>kwillacey</dc:creator>
      <dc:date>2009-11-09T20:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293600#M328612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it is a wild card.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, if condition is deny for all aaa-client then that group will not have access to all clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 20:45:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293600#M328612</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-11-09T20:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293601#M328613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kelvin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You got it right. * means wildcard and if we use (*) for port and source address then it would assume any port/address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use action as deny for all aaa client then users of that group in ACS will not able to access any device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 20:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293601#M328613</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-11-09T20:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293602#M328614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK thanks that's what I was hoping. One more question, if I have remote access VPN on an ASA and authentication is provided via the ACS and I add the NAR as I described earlier would those users in the group still be able to authenticate?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 20:54:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293602#M328614</guid>
      <dc:creator>kwillacey</dc:creator>
      <dc:date>2009-11-09T20:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293603#M328615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi kelvin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They will be able to connect if you are using ASA for VPN using radius protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 21:50:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293603#M328615</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-11-09T21:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293604#M328616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am guessing if it is using TACACS then it is going to be a problem, am i right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 21:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293604#M328616</guid>
      <dc:creator>kwillacey</dc:creator>
      <dc:date>2009-11-09T21:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293605#M328617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kelvin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct. If we are using tacacs for both the sessions then this would not work because rem_address would be same and that will not allow the vpn users because NAR is there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 21:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293605#M328617</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-11-09T21:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Denying AAA Clients to a specific user group in ACS v4.1</title>
      <link>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293606#M328618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS 3.2 does not have device groups so I cannot separate the devices.... thanks a lot I'm gonna have to think about it some more.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Nov 2009 22:01:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/denying-aaa-clients-to-a-specific-user-group-in-acs-v4-1/m-p/1293606#M328618</guid>
      <dc:creator>kwillacey</dc:creator>
      <dc:date>2009-11-09T22:01:28Z</dc:date>
    </item>
  </channel>
</rss>

