<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 3.3 - User is assigned more that one group in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874808#M408721</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JG,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not found "Assign a Shell Command Authorization Set on a per Network Device Group Basis" option in group setup. Do I need to enable something for activate it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Ray&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Oct 2007 01:49:01 GMT</pubDate>
    <dc:creator>rccw</dc:creator>
    <dc:date>2007-10-05T01:49:01Z</dc:date>
    <item>
      <title>ACS 3.3 - User is assigned more that one group</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874805#M408718</link>
      <description>&lt;P&gt;I am using ACS 3.3 and would like to assign a privilege to someone who have full right for switch and read-only for router. However, ACS only allow assigned single group in user setup. How can I configure for meet this requirement?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;&lt;P&gt;Ray&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874805#M408718</guid>
      <dc:creator>rccw</dc:creator>
      <dc:date>2019-03-10T22:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 - User is assigned more that one group</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874806#M408719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may categorize network devices (AAA Clients) in two NDG's such as Switches and Routers and set different authroization levels based on NDG's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ahmed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2007 09:44:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874806#M408719</guid>
      <dc:creator>sahmedshahcsd</dc:creator>
      <dc:date>2007-10-04T09:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 - User is assigned more that one group</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874807#M408720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ray,&lt;/P&gt;&lt;P&gt;If you have configured command authorization then you can use option &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Assign a Shell Command Authorization Set on a per Network Device Group Basis "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Define max Privilege on a per network device group basis"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These option are in group set up. However if you don't see it then go to interface configuration----&amp;gt; Tacacs----&amp;gt;Enable advance tacacs options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2007 12:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874807#M408720</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-10-04T12:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 - User is assigned more that one group</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874808#M408721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JG,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not found "Assign a Shell Command Authorization Set on a per Network Device Group Basis" option in group setup. Do I need to enable something for activate it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Ray&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2007 01:49:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874808#M408721</guid>
      <dc:creator>rccw</dc:creator>
      <dc:date>2007-10-05T01:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 - User is assigned more that one group</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874809#M408722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ahmed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some staffs need a full right for all network devices, but I cannot add a same device into the other NDG. It said that IP is conflict with other NDG.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Ray&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2007 01:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874809#M408722</guid>
      <dc:creator>rccw</dc:creator>
      <dc:date>2007-10-05T01:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 - User is assigned more that one group</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874810#M408723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to switch the feature on under interface config... On the TACACS+ sub page enable the shell service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In group setup you should then see the shell command device command authorisation section. You probably need to have some NDGs setup too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its also best to define the shell device command sets (under shared profile components) first. That way when you edit a group all you need to is choose which NDGs are assigned a particular DCS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2007 05:35:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874810#M408723</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-10-05T05:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 - User is assigned more that one group</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874811#M408725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I saw a "Shell Command Authorization" section, but there only have 3 options which are:&lt;/P&gt;&lt;P&gt;1. None&lt;/P&gt;&lt;P&gt;2. Assign a Shell Command Authorization Set for any network device&lt;/P&gt;&lt;P&gt;3. Per Group Command Authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There have not "Assign a Shell Command Authorization Set on a per Network Device Group Basis" option. &lt;/P&gt;&lt;P&gt;Do I missing anything?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Ray &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2007 01:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874811#M408725</guid>
      <dc:creator>rccw</dc:creator>
      <dc:date>2007-10-08T01:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 - User is assigned more that one group</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874812#M408727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure  you go to interface configuration----&amp;gt; Tacacs----&amp;gt;Enable advance tacacs options. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;go to interface configuration----&amp;gt; Advanced option ----&amp;gt; Check all related to NAR---&amp;gt;restrt acs services. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should be there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2007 12:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874812#M408727</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-10-08T12:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 - User is assigned more that one group</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874813#M408729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much. I found it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ray&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2007 00:09:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-user-is-assigned-more-that-one-group/m-p/874813#M408729</guid>
      <dc:creator>rccw</dc:creator>
      <dc:date>2007-10-22T00:09:27Z</dc:date>
    </item>
  </channel>
</rss>

