<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS Group Mapping in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935921#M376554</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to set up group mapping in acs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS---&amp;gt;Ext db---&amp;gt;Group mapping---&amp;gt;windows---&amp;gt;choose domain---&amp;gt; add mapping----&amp;gt; choose NT group and pick one acs group--&amp;gt;submit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now you will see the mapping. Now on rest of the user groups, you need to set up NAR , with condition , not allowing them wireless nas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See this link,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Apr 2008 13:33:34 GMT</pubDate>
    <dc:creator>Jagdeep Gambhir</dc:creator>
    <dc:date>2008-04-11T13:33:34Z</dc:date>
    <item>
      <title>ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935920#M376553</link>
      <description>&lt;P&gt;I am trying to implement LEAP authentication on Access Point. I have a Cisco ACS 3.1 which is integrated into Active Directory. I would like to use group mapping feature for authentication. Ie:- I have created a NT group in active directory and added some users into that group. I want only those userls who are listed in this group to use Wirelss LAN. How can I go about this?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935920#M376553</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2019-03-10T22:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935921#M376554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to set up group mapping in acs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS---&amp;gt;Ext db---&amp;gt;Group mapping---&amp;gt;windows---&amp;gt;choose domain---&amp;gt; add mapping----&amp;gt; choose NT group and pick one acs group--&amp;gt;submit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now you will see the mapping. Now on rest of the user groups, you need to set up NAR , with condition , not allowing them wireless nas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See this link,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Apr 2008 13:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935921#M376554</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-04-11T13:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935922#M376555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I could create NT Group Mapping. Where to create NAR? I could find only the below settings under Shared Profile Components.&lt;/P&gt;&lt;P&gt;Shell Command Authorization Set&lt;/P&gt;&lt;P&gt;PIX Command Authorization Set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Apr 2008 21:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935922#M376555</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2008-04-12T21:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935923#M376556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah in ACS 3.1 its under the Shared Profile Components page. In ACS 4.1 its directly under the user groups or under SPC page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to check the box for "define ip based access restriction" and deny access for all other groups to the wireless access points network device group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the NAR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Denied Calling/Point of access restrictions&lt;/P&gt;&lt;P&gt;2. AAA Clients = Wireless access points(whatever u called your network device group for wireless)&lt;/P&gt;&lt;P&gt;3. Port = just put a * for all&lt;/P&gt;&lt;P&gt;4. Src IP address = just put a * as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click submit to save it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to the ACS User groups section and select all the group " that don't need access to wireless" and apply the NAR you created to that group. The section is called Network Access Restrictions (NAR) under the group area.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps and let me know if you need further assistance or explanation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Apr 2008 00:50:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935923#M376556</guid>
      <dc:creator>craig.eyre</dc:creator>
      <dc:date>2008-04-13T00:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935924#M376557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently I have configured my ACS with Active Directory. Users who has set Dialin Permissions can connect to Access Points.&lt;/P&gt;&lt;P&gt;Now I have created a Windows group in domain with 5 members in it and I have mapped that group in ACS to group 10.&lt;/P&gt;&lt;P&gt;Now I want only the members of the group to connect to Access point. How do I do that?&lt;/P&gt;&lt;P&gt;I tried the NAR settings but did not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Apr 2008 12:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935924#M376557</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2008-04-15T12:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935925#M376558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm pretty sure that NAR's will work for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to deny all other groups access to the access points. So if you have 9 other groups other than the "group 10", you need to apply the deny NAR to each group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Groups 1-9 create a NAR to deny calling/point to the access points (network device group) and just put * for port and address. You'll need to submit and restart for the changes to take affect. The box will no allow authentications at the time of the restart so do it when the system is not busy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I understood your question right, but if not just let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Apr 2008 13:55:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935925#M376558</guid>
      <dc:creator>craig.eyre</dc:creator>
      <dc:date>2008-04-15T13:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935926#M376559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Therea are 500 default ACS groups and its not a practical solution to add NAR to all the 500 groups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Apr 2008 23:19:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935926#M376559</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2008-04-15T23:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935927#M376560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry that I couldn't have a better answer for you right now. If I come across another fix I'll post it on the forum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2008 14:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935927#M376560</guid>
      <dc:creator>craig.eyre</dc:creator>
      <dc:date>2008-04-16T14:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935928#M376561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With ACS v3.1 you do not have much options, but if you upgrade to ACS v4.1 you can implement Network Access Profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by this you can authorize a group to particular network devices and deny access to other groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;following link can give more detail:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/NAPs.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/NAPs.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Rohit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2008 14:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935928#M376561</guid>
      <dc:creator>rochopra</dc:creator>
      <dc:date>2008-04-16T14:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935929#M376562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;assign  group-mappings to associated NT group and scroll down to group name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In group name, go to "Per Group Defined Network Access Restrictions", Check the box to implement group NAR, assign the access points to the to this group with AP1 * *.  .  Scroll down to Denied Calling/Point of Access Location.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dwane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2008 20:08:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935929#M376562</guid>
      <dc:creator>dpatkins</dc:creator>
      <dc:date>2008-04-16T20:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Group Mapping</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935930#M376563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using ACS 3.1 so can not use Network Access Profile. I used the following method which works fine for me. Correct me if I am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Edit the ACS "0 default group" settings. Under NAR, select the check box, Only allow network access when--but do not add any NAR. Please go thru the attachment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Define a NAR to permit access for Network device group "Wireless Access Point"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Map a Windows group to ACS group and add that NAR to the group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Apr 2008 05:34:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-group-mapping/m-p/935930#M376563</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2008-04-17T05:34:24Z</dc:date>
    </item>
  </channel>
</rss>

