<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 4.0 Network Device Groups in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-4-0-network-device-groups/m-p/1138565#M364199</link>
    <description>&lt;P&gt;Hey everyone, got a question for you.  I am running ACS 4.0 for windows.  I have several NDGs configured including NETWORK 1 and NETWORK 2.  I also have several user groups including GROUP A, GROUP B, and GROUP C.  GROUP A should have access to all devices on all NETWORKs.  This is configured as Enable Options: Max Priv Level any AAA device = 15; TACACS+ settings Shell checked and Priv Level =15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GROUP B should have full access to NETWORK 1, but no access (or at least no privlidges) for NETWORK 2.  I have this done by Enable Options:  Define max per NDG with NETWORK 1 set to 15, and everything else blank; TACACS+ settings Shell checked;  and Priv Level =15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is that when I do this, they are still able to log into both groups and have full priv on both groups.  If I get get rid of TACACS+ Settings Priv Level, then I can still log into either NETWORK, but just need to put in the local enable password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On each device I have the following:&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know I could do command authorization and it may solve the problem, but some of these sites are low speed sites and I don't want to wait for each command to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 23:17:42 GMT</pubDate>
    <dc:creator>pyrodie18</dc:creator>
    <dc:date>2019-03-10T23:17:42Z</dc:date>
    <item>
      <title>ACS 4.0 Network Device Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-0-network-device-groups/m-p/1138565#M364199</link>
      <description>&lt;P&gt;Hey everyone, got a question for you.  I am running ACS 4.0 for windows.  I have several NDGs configured including NETWORK 1 and NETWORK 2.  I also have several user groups including GROUP A, GROUP B, and GROUP C.  GROUP A should have access to all devices on all NETWORKs.  This is configured as Enable Options: Max Priv Level any AAA device = 15; TACACS+ settings Shell checked and Priv Level =15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GROUP B should have full access to NETWORK 1, but no access (or at least no privlidges) for NETWORK 2.  I have this done by Enable Options:  Define max per NDG with NETWORK 1 set to 15, and everything else blank; TACACS+ settings Shell checked;  and Priv Level =15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is that when I do this, they are still able to log into both groups and have full priv on both groups.  If I get get rid of TACACS+ Settings Priv Level, then I can still log into either NETWORK, but just need to put in the local enable password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On each device I have the following:&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know I could do command authorization and it may solve the problem, but some of these sites are low speed sites and I don't want to wait for each command to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-0-network-device-groups/m-p/1138565#M364199</guid>
      <dc:creator>pyrodie18</dc:creator>
      <dc:date>2019-03-10T23:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.0 Network Device Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-0-network-device-groups/m-p/1138566#M364210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could try group level Network Access Restrictions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way you can actually prevent GROUP B from even logging onto NETWORK 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That would be the simplest approach. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Jan 2009 16:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-0-network-device-groups/m-p/1138566#M364210</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2009-01-21T16:21:45Z</dc:date>
    </item>
  </channel>
</rss>

