<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 3.1 group problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-1-group-problem/m-p/203810#M438081</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am using ACS 3.2 with Win2K AD and group mappings to four AD user groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had tried NAR feature but it does not seem to do any sort of filtering. I can still authenticate with users from other mapped groups to all the AAA clients  even though the group NAR specifically permits only certain AAA clients and denies all other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Biju&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 11 Jan 2004 07:38:54 GMT</pubDate>
    <dc:creator>bhameed</dc:creator>
    <dc:date>2004-01-11T07:38:54Z</dc:date>
    <item>
      <title>ACS 3.1 group problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-1-group-problem/m-p/203808#M438078</link>
      <description>&lt;P&gt;I created two groups on ACS 3.1. One is for wireless user ,another group is used for VPN client. I found that when I try to use VPN servece,I can also login with user ID belongs to wireless group and vice versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I  isolate the user id  of  two groups ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-1-group-problem/m-p/203808#M438078</guid>
      <dc:creator>flyan</dc:creator>
      <dc:date>2019-03-10T14:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.1 group problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-1-group-problem/m-p/203809#M438079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAS (Network Access Restriction) Filter is the only options here.  All you need to do is in your VPN group, just allow the AAA client for VPN device and deny rest of the NASes.  Then in Wireless group, just allow the Wireless device as AAA client and deny the rest.  Here are the links that will help you understanding and configuring NAR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a00800d9e6b.html#623269" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a00800d9e6b.html#623269&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a0080102176.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a0080102176.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 May 2003 14:04:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-1-group-problem/m-p/203809#M438079</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-05-29T14:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.1 group problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-1-group-problem/m-p/203810#M438081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am using ACS 3.2 with Win2K AD and group mappings to four AD user groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had tried NAR feature but it does not seem to do any sort of filtering. I can still authenticate with users from other mapped groups to all the AAA clients  even though the group NAR specifically permits only certain AAA clients and denies all other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Biju&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Jan 2004 07:38:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-1-group-problem/m-p/203810#M438081</guid>
      <dc:creator>bhameed</dc:creator>
      <dc:date>2004-01-11T07:38:54Z</dc:date>
    </item>
  </channel>
</rss>

