<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 3.3 Access Restriction Question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-3-access-restriction-question/m-p/616482#M422636</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In theory NARs should work for you - depending on what the ASA sticks in its authentication request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For layer 2 authentications ACS applies CLI/DNIS NARs. Traditionally with dial the AAA client would put the calling number and called number into the RADIUS attributes: Calling-Station-Id and Called-Station-Id respectively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With 802.1x devices stick the MAC address of the endpoint into Calling-Station-Id.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the ASA does this to you can create a CLI/DNIS NAR just for this user (in the user record) that has a single permit entry:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA Client = All AAA Clients&lt;/P&gt;&lt;P&gt;Port = *&lt;/P&gt;&lt;P&gt;CLI = &lt;MAC address="" of="" user=""&gt;&lt;/MAC&gt;&lt;/P&gt;&lt;P&gt;DNIS = *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that user level NARs need to be enabled under interface config first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Oct 2006 09:43:02 GMT</pubDate>
    <dc:creator>darpotter</dc:creator>
    <dc:date>2006-10-18T09:43:02Z</dc:date>
    <item>
      <title>ACS 3.3 Access Restriction Question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-access-restriction-question/m-p/616481#M422634</link>
      <description>&lt;P&gt;Hello all. We're currently running ACS 3.3.3 and are wanting to restrict access for a particuler user based up on his MAC address, simply wether or not he can connect or not. It doesn't necessarly need to be the MAC, but something unique to that Host, the hostname, mac address, ect. We can't use the IP as it is DSL and dhcp.  The user will have full rights, but we just want him coming off a particuler machine(laptop).  He would be going through our ASA5520.  Any ideas?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:48:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-access-restriction-question/m-p/616481#M422634</guid>
      <dc:creator>raun.williams</dc:creator>
      <dc:date>2019-03-10T21:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.3 Access Restriction Question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-3-access-restriction-question/m-p/616482#M422636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In theory NARs should work for you - depending on what the ASA sticks in its authentication request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For layer 2 authentications ACS applies CLI/DNIS NARs. Traditionally with dial the AAA client would put the calling number and called number into the RADIUS attributes: Calling-Station-Id and Called-Station-Id respectively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With 802.1x devices stick the MAC address of the endpoint into Calling-Station-Id.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the ASA does this to you can create a CLI/DNIS NAR just for this user (in the user record) that has a single permit entry:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA Client = All AAA Clients&lt;/P&gt;&lt;P&gt;Port = *&lt;/P&gt;&lt;P&gt;CLI = &lt;MAC address="" of="" user=""&gt;&lt;/MAC&gt;&lt;/P&gt;&lt;P&gt;DNIS = *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that user level NARs need to be enabled under interface config first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Oct 2006 09:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-3-access-restriction-question/m-p/616482#M422636</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-10-18T09:43:02Z</dc:date>
    </item>
  </channel>
</rss>

