<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 3.3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-3/m-p/817952#M420598</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, I want to allow some users to (5 users) to access telnet only to subnet like 10.9.x.x and 10.8.x.x. and other users to access everything.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 May 2007 13:57:23 GMT</pubDate>
    <dc:creator>nawas</dc:creator>
    <dc:date>2007-05-30T13:57:23Z</dc:date>
    <item>
      <title>ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3/m-p/817950#M420594</link>
      <description>&lt;P&gt;I'm using ACS 3.3 and I'm trying to restrict telnet access to some subnets only. Is there any option in the ACS that can be accomplished with?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:23:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3/m-p/817950#M420594</guid>
      <dc:creator>nawas</dc:creator>
      <dc:date>2019-03-26T00:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3/m-p/817951#M420596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nawas,&lt;/P&gt;&lt;P&gt;You mean to restrict ONLY telnet access or you want to deny access using all modes like telnet, SSH, HTTP/s etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to deny all modes to a specific AAA Clients, then you can use NAR's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs33/user/c.htm#wp697095" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs33/user/c.htm#wp697095&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2007 13:50:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3/m-p/817951#M420596</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-05-30T13:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3/m-p/817952#M420598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, I want to allow some users to (5 users) to access telnet only to subnet like 10.9.x.x and 10.8.x.x. and other users to access everything.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2007 13:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3/m-p/817952#M420598</guid>
      <dc:creator>nawas</dc:creator>
      <dc:date>2007-05-30T13:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3/m-p/817953#M420600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still the answer is NAR,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to apply NAR on per user basis, for those 5 users, and nothing on rest of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Resulting, Rest of them will have full access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And under IP based NAR for these 5 users on user basis, restrict them to subnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use Shared Profile component section,s NAF and NAR together, and then apply it on user level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.9.*.* (Create a NAF for this)&lt;/P&gt;&lt;P&gt;Port : *&lt;/P&gt;&lt;P&gt;Address : *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.8.*.* (Create a NAF for this)&lt;/P&gt;&lt;P&gt;Port : *&lt;/P&gt;&lt;P&gt;Address : *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAF : Available on 4.x, else if you have 3.x, then it depends on how you have created your NDG, else it depends on how you have created AAA clients on ACS, lots of combinations possible. To summarize it all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to play with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2007 23:55:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3/m-p/817953#M420600</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-01T23:55:52Z</dc:date>
    </item>
  </channel>
</rss>

