<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NDGs and User group issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941259#M402027</link>
    <description>&lt;P&gt;I have two sets of NDGs&lt;/P&gt;&lt;P&gt;1.  Routers_Switches&lt;/P&gt;&lt;P&gt;2.  UPS_PDU (Power Supplies)&lt;/P&gt;&lt;P&gt;I have two sets of UserGroups&lt;/P&gt;&lt;P&gt;1.  Network Administrators&lt;/P&gt;&lt;P&gt;2.  UPS Support Staff&lt;/P&gt;&lt;P&gt;I only want Network Admins to access the Routers_Switch group and the UPS Support Staff to access the UPS_PDU NDG.  I have users from Usergroup Network Admin accessing the UPS Device Group.  Is there a way to have only the Network Admin group access only the routers_switch ndg and not the UPS_PDU ndg?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:46:49 GMT</pubDate>
    <dc:creator>umamon</dc:creator>
    <dc:date>2019-03-10T22:46:49Z</dc:date>
    <item>
      <title>NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941259#M402027</link>
      <description>&lt;P&gt;I have two sets of NDGs&lt;/P&gt;&lt;P&gt;1.  Routers_Switches&lt;/P&gt;&lt;P&gt;2.  UPS_PDU (Power Supplies)&lt;/P&gt;&lt;P&gt;I have two sets of UserGroups&lt;/P&gt;&lt;P&gt;1.  Network Administrators&lt;/P&gt;&lt;P&gt;2.  UPS Support Staff&lt;/P&gt;&lt;P&gt;I only want Network Admins to access the Routers_Switch group and the UPS Support Staff to access the UPS_PDU NDG.  I have users from Usergroup Network Admin accessing the UPS Device Group.  Is there a way to have only the Network Admin group access only the routers_switch ndg and not the UPS_PDU ndg?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941259#M402027</guid>
      <dc:creator>umamon</dc:creator>
      <dc:date>2019-03-10T22:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941260#M402028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which version of ACS software are you running?&lt;/P&gt;&lt;P&gt;It's pretty much the same idea on ACS 3 or 4 but I can explain in more detail with which version you have&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Apr 2008 00:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941260#M402028</guid>
      <dc:creator>craig.eyre</dc:creator>
      <dc:date>2008-04-13T00:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941261#M402029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah in ACS 3.1 its under the Shared Profile Components page. In ACS 4.1 its directly under the user groups or under SPC page. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to check the box for "define ip based access restriction" and deny access for all other groups to the wireless access points network device group. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS 3.X)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Denied Calling/Point of access restrictions &lt;/P&gt;&lt;P&gt;2. AAA Clients =UPS_PDU (Power Supplies)   &lt;/P&gt;&lt;P&gt;3. Port = just put a * for all &lt;/P&gt;&lt;P&gt;4. Src IP address = just put a * as well&lt;/P&gt;&lt;P&gt;SUBMIT to SAVE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a second one for the other group like so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Denied Calling/Point of access restrictions &lt;/P&gt;&lt;P&gt;2. AAA Clients =Routers_Switches    &lt;/P&gt;&lt;P&gt;3. Port = just put a * for all &lt;/P&gt;&lt;P&gt;4. Src IP address = just put a * as well  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click submit to save it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to the ACS User groups section and select the Network Administrators Group " that don't need access to the UPS's" and apply the NAR you created to that group. Do the same for the other grouping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(ACS 4.X)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go directly under the "user groups" and create the NAR under there. No need to go under the Shared Profile Components section&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps and let me know if you need further assistance or explanation. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Apr 2008 01:02:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941261#M402029</guid>
      <dc:creator>craig.eyre</dc:creator>
      <dc:date>2008-04-13T01:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941262#M402030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running ACS 4.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 02:51:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941262#M402030</guid>
      <dc:creator>umamon</dc:creator>
      <dc:date>2008-04-14T02:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941263#M402031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just select &lt;/P&gt;&lt;P&gt;1.Group Setup&lt;/P&gt;&lt;P&gt;2.Select the Routers_Switches group&lt;/P&gt;&lt;P&gt;3.Ten scroll down to the "per group defined network access restrictions" Enable it with a checkmark.&lt;/P&gt;&lt;P&gt;4. Select deny calling/point&lt;/P&gt;&lt;P&gt;5. AAA client = UPS's&lt;/P&gt;&lt;P&gt;6. Ports = *&lt;/P&gt;&lt;P&gt;7. Address = *&lt;/P&gt;&lt;P&gt;8. Hit enter and the new rule will be added to the window above.&lt;/P&gt;&lt;P&gt;9. Click submit (not submit and restart until you create the other NAR for the other group)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go back and select the UPS_PDU group and do the same steps but,&lt;/P&gt;&lt;P&gt;1. AAA client = routers_switches&lt;/P&gt;&lt;P&gt;2. Port = *&lt;/P&gt;&lt;P&gt;3. Address = *&lt;/P&gt;&lt;P&gt;4. Enter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click submit and restart but remember this will stop authenticating users for the time its restarting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 14:23:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941263#M402031</guid>
      <dc:creator>craig.eyre</dc:creator>
      <dc:date>2008-04-14T14:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941264#M402032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try this as soon as I can figure out why I can't get to the web interface.  I turned on logging friday of last week and now my drive is full, I've compressed files and regain space on my harddrive, but now I still can't get in.  If you have any knowledge to assist with this I will appreciate it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 18:37:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941264#M402032</guid>
      <dc:creator>umamon</dc:creator>
      <dc:date>2008-04-14T18:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941265#M402033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Craig for your help, that worked!!! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 19:35:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941265#M402033</guid>
      <dc:creator>umamon</dc:creator>
      <dc:date>2008-04-14T19:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941266#M402034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I spoke to soon, I've done what you said. The PDU support techs are denied to the routers/switches, but I'm (apart of the Network Admin) and I can still get into the PDU......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2008 21:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941266#M402034</guid>
      <dc:creator>umamon</dc:creator>
      <dc:date>2008-04-14T21:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941267#M402035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need to go under the Network admin Group and create a NAR that denies access to the PDU device group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same steps as 1st one but:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group setup, Network Admin group, edit group, create NAR to deny access to PDU group and put * for port and address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this clears it up a bit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Apr 2008 02:31:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941267#M402035</guid>
      <dc:creator>craig.eyre</dc:creator>
      <dc:date>2008-04-15T02:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941268#M402036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've tried all your steps, recheck and tested, and for some reason, I am still able to get into the PDU devices.  I've tested the deny NAR and it works for the network admin.  I even tested the deny NAR for my network devices, and the rule did in fact deny me.  So I know that is working.  Just for testing purposes, I tested the PDU admin group by denying the PDU devices the rule did not restrict access to the PDU admin users they were stil able to get into the PDU, removed the deny pdu and re added the router/switch NDG, and still the same results.  Perhaps it could be something on the PDU device that has to be configured? Could there be another option in relation to the way these rules work?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2008 05:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941268#M402036</guid>
      <dc:creator>umamon</dc:creator>
      <dc:date>2008-04-16T05:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941269#M402037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are any of the users in the PDU admin group members of other groups that are mapped on the acs? Eg. Is Bob a member of PDU admin and Client Support?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check in the ACS logs to see what group the user is associating to when they connect to the PDU devices. So if Bob logs in and gains access to your PDU devices (with the NAR)what group is the ACS matching him to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2008 14:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941269#M402037</guid>
      <dc:creator>craig.eyre</dc:creator>
      <dc:date>2008-04-16T14:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941270#M402038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For failures... the failed attempts report "Reason" column might give you a clue about which part of the NAR is triggering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im assuming we're talking TACACS+... ACS will choose which type of NAR to use (IP or dial) by looking at the rem_addr attribute. If it sees an ip address it will use ip nars. If not it'll use the ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you could check the T+ accounting report, or run the CSTacacs -z -e service at the command prompt to see incoming packets logs at the console.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 15:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941270#M402038</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2008-04-22T15:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: NDGs and User group issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941271#M402039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my logon to the UPS devices do not fail, i actually get into these devices, and i don't, I wanna be able to restrict users groups to certain network device groups.  can you help me with that&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2008 21:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ndgs-and-user-group-issues/m-p/941271#M402039</guid>
      <dc:creator>umamon</dc:creator>
      <dc:date>2008-04-22T21:53:31Z</dc:date>
    </item>
  </channel>
</rss>

