<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict access to per user per virtual machine in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/restrict-access-to-per-user-per-virtual-machine/m-p/3921059#M457221</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/834477"&gt;pradeep.r6@tcs.com&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is a VMWare environment then you would be better off granting individual user rights (RBAC) to that user. You can lock down the VM and countless menu options to constrain the user to a VM and its inner workings.&amp;nbsp; This is not a job for RADIUS or TACACS+&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the VPN access, that could involve RADIUS - but it would not necessarily provide the ability to restrict a user to one machine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having said that, if you can explain your scenario in more detail, then we might be able to be more precise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Arne&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2019 10:45:09 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2019-09-09T10:45:09Z</dc:date>
    <item>
      <title>Restrict access to per user per virtual machine</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-access-to-per-user-per-virtual-machine/m-p/3920986#M457216</link>
      <description>&lt;P&gt;Dear members,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know if there is any way to create a policy in ISE to provide access to remote virtual machine for a user. I do not want anyone else accessing the remote virtual machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Requirement:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;User will be connected through VPN and will take remote virtual machine to access the network. I want to create policy to authenticate specific user to a specific virtual machine. Is it possible? Can anyone help me with this?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 07:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-access-to-per-user-per-virtual-machine/m-p/3920986#M457216</guid>
      <dc:creator>pradeep.r6@tcs.com</dc:creator>
      <dc:date>2019-09-09T07:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict access to per user per virtual machine</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-access-to-per-user-per-virtual-machine/m-p/3921059#M457221</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/834477"&gt;pradeep.r6@tcs.com&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is a VMWare environment then you would be better off granting individual user rights (RBAC) to that user. You can lock down the VM and countless menu options to constrain the user to a VM and its inner workings.&amp;nbsp; This is not a job for RADIUS or TACACS+&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the VPN access, that could involve RADIUS - but it would not necessarily provide the ability to restrict a user to one machine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having said that, if you can explain your scenario in more detail, then we might be able to be more precise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Arne&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 10:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-access-to-per-user-per-virtual-machine/m-p/3921059#M457221</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-09-09T10:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict access to per user per virtual machine</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-access-to-per-user-per-virtual-machine/m-p/3921084#M457231</link>
      <description>&lt;P&gt;You can make use of scalable group tags (SGTs). these VMs or server group access&amp;nbsp; with user groups will be defined in the trustsec policy matrix in ISE . you can find many documents online describing this approach.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-24/213616-how-to-configure-cisco-trustsec-sgts-u.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-24/213616-how-to-configure-cisco-trustsec-sgts-u.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 11:34:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-access-to-per-user-per-virtual-machine/m-p/3921084#M457231</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2019-09-09T11:34:31Z</dc:date>
    </item>
  </channel>
</rss>

