<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Local Username Database in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/local-username-database/m-p/2778903#M41359</link>
    <description>&lt;P&gt;Dear Friends,&lt;/P&gt;
&lt;P&gt;I'm struggling with an issue.&lt;/P&gt;
&lt;P&gt;I've set up an ssl vpn (Anyconnect) on a cisco 2811 router. Because of certain limitations I can't setup a radius or tacacs server.&lt;/P&gt;
&lt;P&gt;my VTY line authentication is aaa login local&lt;/P&gt;
&lt;P&gt;I have some questions:&lt;/P&gt;
&lt;P&gt;1- can I set up accounts on the local database that can't login to the router (just be able to use the VPN)&lt;/P&gt;
&lt;P&gt;2- can I create an aaa authentication list that contain just some of the local usernames not all of them so I can limit the logins&lt;/P&gt;
&lt;P&gt;3- can I assign an access-list to a specific username? (username **** access-class ) didn't work for me when the user connects the anyconnect client! (WebVPN ACL applies)&lt;/P&gt;
&lt;P&gt;Please help me I'm struggling!!!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:19:26 GMT</pubDate>
    <dc:creator>shahab.66</dc:creator>
    <dc:date>2019-03-11T06:19:26Z</dc:date>
    <item>
      <title>Local Username Database</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database/m-p/2778903#M41359</link>
      <description>&lt;P&gt;Dear Friends,&lt;/P&gt;
&lt;P&gt;I'm struggling with an issue.&lt;/P&gt;
&lt;P&gt;I've set up an ssl vpn (Anyconnect) on a cisco 2811 router. Because of certain limitations I can't setup a radius or tacacs server.&lt;/P&gt;
&lt;P&gt;my VTY line authentication is aaa login local&lt;/P&gt;
&lt;P&gt;I have some questions:&lt;/P&gt;
&lt;P&gt;1- can I set up accounts on the local database that can't login to the router (just be able to use the VPN)&lt;/P&gt;
&lt;P&gt;2- can I create an aaa authentication list that contain just some of the local usernames not all of them so I can limit the logins&lt;/P&gt;
&lt;P&gt;3- can I assign an access-list to a specific username? (username **** access-class ) didn't work for me when the user connects the anyconnect client! (WebVPN ACL applies)&lt;/P&gt;
&lt;P&gt;Please help me I'm struggling!!!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database/m-p/2778903#M41359</guid>
      <dc:creator>shahab.66</dc:creator>
      <dc:date>2019-03-11T06:19:26Z</dc:date>
    </item>
    <item>
      <title>Hello,1. As far as I know you</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database/m-p/2778904#M41360</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;1. As far as I know you can only specify for VPN user privilege level 0 so user then can connect to router but will have only "enable" command and without enable password he can do nothing.&lt;/P&gt;
&lt;P&gt;I don´t know to answer on 2. and 3. question. But I think that you can have only one local database with usernames and also you cannot assign access list to username.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2015 08:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database/m-p/2778904#M41360</guid>
      <dc:creator>Milos Megis</dc:creator>
      <dc:date>2015-12-15T08:11:07Z</dc:date>
    </item>
    <item>
      <title>Thanks for the help,</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database/m-p/2778905#M41361</link>
      <description>&lt;P&gt;Thanks for the help,&lt;/P&gt;
&lt;P&gt;I Finally did it, using aaa attribute lists I set policies to user groups and my problem is solved!&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2015 20:36:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database/m-p/2778905#M41361</guid>
      <dc:creator>shahab.66</dc:creator>
      <dc:date>2015-12-20T20:36:03Z</dc:date>
    </item>
    <item>
      <title>Can you give a code snippet,</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database/m-p/2778906#M41362</link>
      <description>&lt;P&gt;Can you give a code snippet, how do you have configured the aaa attribute list and the policies to user groups?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2016 22:04:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database/m-p/2778906#M41362</guid>
      <dc:creator>Carsten Peukert</dc:creator>
      <dc:date>2016-05-30T22:04:50Z</dc:date>
    </item>
  </channel>
</rss>

