<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Group connection between Cisco switch and ACS server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/group-connection-between-cisco-switch-and-acs-server/m-p/1128747#M364628</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ceriel-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this link, it might help you out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=AAA&amp;amp;topicID=.ee6e1fe&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc25eb6" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=AAA&amp;amp;topicID=.ee6e1fe&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc25eb6&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Nov 2008 14:29:32 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2008-11-24T14:29:32Z</dc:date>
    <item>
      <title>Group connection between Cisco switch and ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/group-connection-between-cisco-switch-and-acs-server/m-p/1128746#M364618</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My name is Ceriel Roland and I have a small problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using Cisco 3560 Switches with 12.2(44)SE2 IOS.&lt;/P&gt;&lt;P&gt;These switches are dot1x enabled with the ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Computers are authenticated trough certificates and it all works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also want to enable login with ACS server, but we dont want all users to have access.&lt;/P&gt;&lt;P&gt;Only the group AD_Admins needs to have access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created the group and added users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the switch I entered the command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login AD_Admins local group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the users cant login to the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i change the command to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default local group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then users can login, but ALL users can login and i only want AD_Admins to be able to login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can i set this up for it to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;Ceriel Roland&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:12:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/group-connection-between-cisco-switch-and-acs-server/m-p/1128746#M364618</guid>
      <dc:creator>CerielRoland</dc:creator>
      <dc:date>2019-03-10T23:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Group connection between Cisco switch and ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/group-connection-between-cisco-switch-and-acs-server/m-p/1128747#M364628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ceriel-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this link, it might help you out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=AAA&amp;amp;topicID=.ee6e1fe&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc25eb6" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=AAA&amp;amp;topicID=.ee6e1fe&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc25eb6&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Nov 2008 14:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/group-connection-between-cisco-switch-and-acs-server/m-p/1128747#M364628</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-11-24T14:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Group connection between Cisco switch and ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/group-connection-between-cisco-switch-and-acs-server/m-p/1128748#M364635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Collin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried it but the problem is that the ACS server also allows clients to authenticate trough dot1x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i adjust that setting, the users cant use the network anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried to achieve it trough Network Access Profiles to allow clients to communicate trough Radius and allow users to login with TACACS, but i cant define TACACS access in the NAP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ceriel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Nov 2008 14:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/group-connection-between-cisco-switch-and-acs-server/m-p/1128748#M364635</guid>
      <dc:creator>CerielRoland</dc:creator>
      <dc:date>2008-11-24T14:46:02Z</dc:date>
    </item>
  </channel>
</rss>

