<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access Restriction on ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952076#M406805</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls attach the NAR screen shot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Jun 2008 13:50:34 GMT</pubDate>
    <dc:creator>Jagdeep Gambhir</dc:creator>
    <dc:date>2008-06-13T13:50:34Z</dc:date>
    <item>
      <title>Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952070#M406799</link>
      <description>&lt;P&gt;Routers access are authenticated via ACS using Active Directory,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I want only administrator to get access to routers not all Active Directory users. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To acheive this what action is required on ACS??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI ::: &lt;/P&gt;&lt;P&gt;&amp;lt;&amp;gt; I have Administrator group on Active Directory.&lt;/P&gt;&lt;P&gt;&amp;lt;&amp;gt; I have 40 Network-Devices to access some on different subnets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:54:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952070#M406799</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2019-03-10T22:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952071#M406800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not too hard...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Make sure ACS is correctly mapping from Windows group to ACS group (under external authentication page). Basically get admins to map to an ACS admins group and everyone else to a non-admin ACS group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) In the ACS group selected to the be non admins group create an ip based NAR (network access restriction) that is a DENY on "All AAA Clients", port=*, addr=*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This very simple approach lets the admins have total access (you may want to tighten later) and non-admins nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAR filtering is applied during authentication, so the Failed Attempts report should show the user was filtered rather than rejected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2008 09:49:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952071#M406800</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2008-06-13T09:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952072#M406801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are two section in NAR"s.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ist is IP based NAR&lt;/P&gt;&lt;P&gt;2nd is CLI/DNIS based.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So for wireless users you need to apply only IP based NAR. By this wireless uses will NOT be able to ssh/telnet but they can connect to wireless network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So that solve your issue ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out this white paper,&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2008 12:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952072#M406801</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-06-13T12:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952073#M406802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not getting the syntax to &lt;/P&gt;&lt;P&gt;(( DENY on "All AAA Clients", port=*, addr=* ))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to deny access to router(aaa client 192.168.1.100 ) to group "Users" for telnet and ssh only..... and same for AP(Aironet) [[ aaa client 192.168.1.150 ))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2008 13:01:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952073#M406802</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2008-06-13T13:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952074#M406803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Go to acs----&amp;gt;interface configuration----&amp;gt;advanced options---&amp;gt; enable Group-Level Network Access Restrictions--&amp;gt;Submit, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2008 13:44:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952074#M406803</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-06-13T13:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952075#M406804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;P&gt;I had already enabled Group-level-network access.... but blocking the AAA client for non-admin(users group) is not working....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2008 13:49:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952075#M406804</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2008-06-13T13:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952076#M406805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls attach the NAR screen shot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2008 13:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952076#M406805</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-06-13T13:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952077#M406806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the screen-shot..where VPN user-group can ssh/telnet to network devices even the NAR is applied to the group...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2008 14:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952077#M406806</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2008-06-13T14:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952078#M406807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use "*" for port and IP address&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2008 15:09:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952078#M406807</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-06-13T15:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952079#M406808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead of going to each group and defining NAR, Is there a way to allow for one group and deny for all other groups....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2008 15:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952079#M406808</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2008-06-13T15:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Access Restriction on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952080#M406809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately , there is no such option. It can only be defined on individual group or at user level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jun 2008 16:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/access-restriction-on-acs/m-p/952080#M406809</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-06-13T16:14:26Z</dc:date>
    </item>
  </channel>
</rss>

