<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Same user in different ACS groups? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/same-user-in-different-acs-groups/m-p/740923#M421031</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have this scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A user at home connects via SSL VPN is authenticated by Cisco ACS/RADIUS. User ends up in a specifig SSL VPN group on the ACS. This group is configured with specific properties for SSL VPN.&lt;/P&gt;&lt;P&gt;Now the same user comes to work with his/her private laptop and wants to access the guest wlan which our policy allows. We have a WLC4402 providing the guest wlan. User opens browser and logs in to the guest wlan, gets authenticated on the Cisco ACS/RADIUS and ends up in the same SSL VPN group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is can we configure our ACS 4.1 in such way that it is context sensitive? Knows where the user is coming from and places the user in the right group accordingly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use LDAP group mappings and they are very static. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Rutger&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:05:56 GMT</pubDate>
    <dc:creator>Rutger Blom</dc:creator>
    <dc:date>2019-03-10T22:05:56Z</dc:date>
    <item>
      <title>Same user in different ACS groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/same-user-in-different-acs-groups/m-p/740923#M421031</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have this scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A user at home connects via SSL VPN is authenticated by Cisco ACS/RADIUS. User ends up in a specifig SSL VPN group on the ACS. This group is configured with specific properties for SSL VPN.&lt;/P&gt;&lt;P&gt;Now the same user comes to work with his/her private laptop and wants to access the guest wlan which our policy allows. We have a WLC4402 providing the guest wlan. User opens browser and logs in to the guest wlan, gets authenticated on the Cisco ACS/RADIUS and ends up in the same SSL VPN group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is can we configure our ACS 4.1 in such way that it is context sensitive? Knows where the user is coming from and places the user in the right group accordingly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use LDAP group mappings and they are very static. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Rutger&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:05:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/same-user-in-different-acs-groups/m-p/740923#M421031</guid>
      <dc:creator>Rutger Blom</dc:creator>
      <dc:date>2019-03-10T22:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Same user in different ACS groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/same-user-in-different-acs-groups/m-p/740924#M421032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With ACS v4.1 and NAP, externally authenticated users get a user record for each NAP they authenticate against.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As each NAP may have its own external authenticator config, db mappings and authorisation - it should be totally possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The trick is setting up the NAPs to trigger on RADIUS requests of the appropriate type.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2007 13:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/same-user-in-different-acs-groups/m-p/740924#M421032</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-04-16T13:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Same user in different ACS groups?</title>
      <link>https://community.cisco.com/t5/network-access-control/same-user-in-different-acs-groups/m-p/740925#M421034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't know this was possible using NAPs. Triggering the NAPs could in our case be done by specifying the NAS IP users come from. &lt;/P&gt;&lt;P&gt;I will test with NAPs and come back to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Rutger&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2007 18:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/same-user-in-different-acs-groups/m-p/740925#M421034</guid>
      <dc:creator>Rutger Blom</dc:creator>
      <dc:date>2007-04-16T18:04:09Z</dc:date>
    </item>
  </channel>
</rss>

