<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS3.1 + NDS external database in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119207#M437931</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, if thats the case, it will not work.  In the case, of NT domain you have the option to allow/disallow user authentication when you create the user in NT domain database.  In the case of the NDS, there is no such option to the best of my knowledge.  Sorry !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Jul 2003 17:28:46 GMT</pubDate>
    <dc:creator>mhoda</dc:creator>
    <dc:date>2003-07-03T17:28:46Z</dc:date>
    <item>
      <title>ACS3.1 + NDS external database</title>
      <link>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119202#M437920</link>
      <description>&lt;P&gt;We purchased ACS3.1 and will like to use NDS as the external database for authenticating dialing-users. This configuration is working fine, but now how can  I restrict a specific dialing-users from authenticating to NDS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119202#M437920</guid>
      <dc:creator>ovillaci</dc:creator>
      <dc:date>2019-03-10T14:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: ACS3.1 + NDS external database</title>
      <link>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119203#M437923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ACS you need to configure NAR (Network Access Restrictions).  Here is the procedure -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a0080102174.html#536615" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a0080102174.html#536615&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a0080102173.html#224846" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a0080102173.html#224846&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jul 2003 19:57:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119203#M437923</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-07-02T19:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACS3.1 + NDS external database</title>
      <link>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119204#M437925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mynul, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I meant is how can I resrict dialing-users/remote-users/vpn-users to authenticate to NDS. Below are three scenarios that we have in production and we are planning to migrate to ACS. At this time authentication is being done using each device's local database. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpn users----&amp;gt;VPN3000---&amp;gt;ACS3.1---&amp;gt;NDS(external database)&lt;/P&gt;&lt;P&gt;dialing-users--&amp;gt;Shiva----&amp;gt;VPN3000---&amp;gt;ACS3.1---&amp;gt;NDS(external database)&lt;/P&gt;&lt;P&gt;pptp-users----&amp;gt;WatchGuard(FBII)---&amp;gt;ACS3.1---&amp;gt;NDS(external database)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jul 2003 20:31:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119204#M437925</guid>
      <dc:creator>ovillaci</dc:creator>
      <dc:date>2003-07-02T20:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACS3.1 + NDS external database</title>
      <link>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119205#M437928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if I understand your question correctly.  It appears that you are looking for seperating the users for different  traffic (VPN, dialup, PPTP) and make sure that VPN users cannot connect for dialup and vice versa.  If thats the case, then you need to create three different group in NDS and 3 groups in ACS and then MAP the corresponding ACS group with the NDS group.  Finally you need to apply NAR described earlier in every group and allow or disallow the devices.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pl. let me know if this answers your question.  Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jul 2003 22:02:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119205#M437928</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-07-02T22:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACS3.1 + NDS external database</title>
      <link>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119206#M437930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that's the idea. But how can I restrict 2 users out of  5 that are members of the same group from authenticating to NDS. When I map a NDS group to ACS group, everyone within the NDS container are able to authenticate. &lt;/P&gt;&lt;P&gt; I do not have a problem setting restrictions for users to access devices, this works fine.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2003 17:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119206#M437930</guid>
      <dc:creator>ovillaci</dc:creator>
      <dc:date>2003-07-03T17:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACS3.1 + NDS external database</title>
      <link>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119207#M437931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, if thats the case, it will not work.  In the case, of NT domain you have the option to allow/disallow user authentication when you create the user in NT domain database.  In the case of the NDS, there is no such option to the best of my knowledge.  Sorry !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2003 17:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs3-1-nds-external-database/m-p/119207#M437931</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-07-03T17:28:46Z</dc:date>
    </item>
  </channel>
</rss>

