<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Multiple Active Directory Group Membership Mapping in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568029#M335868</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see that few users in AD belong to both group, follow the below steps to meet your criteria&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;Here we assume the two groups on AD are Wireless and VPN &lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;Please follow the below suggestion: &lt;BR /&gt; &lt;BR /&gt;To achieve this &lt;BR /&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp; we can create 3 groups on the ACS (1) Wireless , 2) &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN 3) Wireless+VPN, &lt;BR /&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp; then in Windows group mapping &lt;BR /&gt;&amp;nbsp; Wireless+VPN (on ACS) MAPs to two groups Wireless on AD and VPN on AD, &lt;BR /&gt; then Wireless(ACS) maps to (Wireless on AD),&lt;BR /&gt; VPN (ACS) maps to (VPN) on AD, &lt;BR /&gt;&lt;BR /&gt;3) Ensure that the Mapping order should be in the following order:&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 1) Wireless+VPN group (on ACS) MAPs to two groups on AD Wireless on AD and VPN on AD.&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 2) Wireless(ACS) maps to (Wireless on AD).&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 3) VPN (ACS) maps to (VPN) on AD&lt;BR /&gt; &lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Nov 2010 01:35:42 GMT</pubDate>
    <dc:creator>aneelaka</dc:creator>
    <dc:date>2010-11-12T01:35:42Z</dc:date>
    <item>
      <title>User Multiple Active Directory Group Membership Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568028#M335852</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We got ACS 4.2 and two types of user access to our network :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1_&amp;nbsp; We got some users in&amp;nbsp; "CiscoAdmins" Active Directory Group, corresponding mapped Cisco ACS group is "Switch Admins".&lt;/P&gt;&lt;P&gt;2_&amp;nbsp; We also have some users in "VPN_Users" Active Directory Group, corresponding mapped Cisco ACS group is "VPN_Users". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In "Order mapping" page on Cisco ACS 4.2, we put tte "CiscoAdmins" Active Directory Group Mapping on top of "VPN_Users" Active Directory Group mapping. So what happens is, if a user belongs to both "CiscoAdmins" and "VPN_Users" groups in Active Directory, the users always goes into "Switch_Admins" group in Cisco ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However for some users (who belong&amp;nbsp; to both groups in Active Directory)&amp;nbsp; we need to apply some IP assignment and specific authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestiongs are welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dumlu&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:34:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568028#M335852</guid>
      <dc:creator>dumlutimuralp</dc:creator>
      <dc:date>2019-03-11T00:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: User Multiple Active Directory Group Membership Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568029#M335868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see that few users in AD belong to both group, follow the below steps to meet your criteria&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;Here we assume the two groups on AD are Wireless and VPN &lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;Please follow the below suggestion: &lt;BR /&gt; &lt;BR /&gt;To achieve this &lt;BR /&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp; we can create 3 groups on the ACS (1) Wireless , 2) &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN 3) Wireless+VPN, &lt;BR /&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp; then in Windows group mapping &lt;BR /&gt;&amp;nbsp; Wireless+VPN (on ACS) MAPs to two groups Wireless on AD and VPN on AD, &lt;BR /&gt; then Wireless(ACS) maps to (Wireless on AD),&lt;BR /&gt; VPN (ACS) maps to (VPN) on AD, &lt;BR /&gt;&lt;BR /&gt;3) Ensure that the Mapping order should be in the following order:&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 1) Wireless+VPN group (on ACS) MAPs to two groups on AD Wireless on AD and VPN on AD.&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 2) Wireless(ACS) maps to (Wireless on AD).&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 3) VPN (ACS) maps to (VPN) on AD&lt;BR /&gt; &lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 01:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568029#M335868</guid>
      <dc:creator>aneelaka</dc:creator>
      <dc:date>2010-11-12T01:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: User Multiple Active Directory Group Membership Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568030#M335891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for getting back. Havent tried your suggestion so far, but curious, how does it work if I map two different AD groups ("wireless", "vpn" to the same ACS group (wireless+vpn). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought when AD sends an authenticaton result message to ACS, it also sends the AD group names which that user belongs to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So ACS receives that , that specific user is a member of "wireless" , and also member of&amp;nbsp; "vpn" AD group. Whichever group name ACS reads first, that user should belong to the corresponding ACS group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But what you are actually saying is if I map a specific ACS group ("wireless+vpn") to two different AD groups, ACS checks the authentication result message from AD server for both group names ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I getting this correct ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dumlu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 17:42:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568030#M335891</guid>
      <dc:creator>dumlutimuralp</dc:creator>
      <dc:date>2010-11-12T17:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: User Multiple Active Directory Group Membership Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568031#M335907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, ACS check for user group membership, and it can determine if user is member of multiple groups and then map it corrosponding ACS group. Few extra material on ACS group mapping&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMap.html#wp940538#wp940538"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMap.html#wp940538#wp940538&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Note: Please rate the answer if it helped&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 21:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568031#M335907</guid>
      <dc:creator>aneelaka</dc:creator>
      <dc:date>2010-11-12T21:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: User Multiple Active Directory Group Membership Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568032#M335935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well apparently I havent done my homework. thanks a lot aneelaka. youve been great help !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dumlu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 21:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-multiple-active-directory-group-membership-mapping/m-p/1568032#M335935</guid>
      <dc:creator>dumlutimuralp</dc:creator>
      <dc:date>2010-11-12T21:37:36Z</dc:date>
    </item>
  </channel>
</rss>

