<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACS Authentication/Authorization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-authorization/m-p/2594698#M74935</link>
    <description>&lt;P&gt;I have ACS 5.6 running and have it integrated with Active Directory.&amp;nbsp; It is also connected to a cloud based radius server for 2-factor auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i would like to be able to do is when a user tries to log into a network device(router/switch/etc.) they would type in their AD username and their 2-factor password.&amp;nbsp; This would get authenticated against the cloud radius server and either pass or fail authentication, but I would also like to be able to allow access based on AD group membership.&amp;nbsp; This would be to allow some staff access to some devices, but not others, and some users would have access to all devices?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:22:29 GMT</pubDate>
    <dc:creator>smolz</dc:creator>
    <dc:date>2019-03-11T05:22:29Z</dc:date>
    <item>
      <title>Cisco ACS Authentication/Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-authorization/m-p/2594698#M74935</link>
      <description>&lt;P&gt;I have ACS 5.6 running and have it integrated with Active Directory.&amp;nbsp; It is also connected to a cloud based radius server for 2-factor auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i would like to be able to do is when a user tries to log into a network device(router/switch/etc.) they would type in their AD username and their 2-factor password.&amp;nbsp; This would get authenticated against the cloud radius server and either pass or fail authentication, but I would also like to be able to allow access based on AD group membership.&amp;nbsp; This would be to allow some staff access to some devices, but not others, and some users would have access to all devices?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-authorization/m-p/2594698#M74935</guid>
      <dc:creator>smolz</dc:creator>
      <dc:date>2019-03-11T05:22:29Z</dc:date>
    </item>
    <item>
      <title>If the integration between</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-authorization/m-p/2594699#M74936</link>
      <description>&lt;P&gt;If the integration between ACS 5.6 and Cloud based radius / AD has been done then the next step is to :&lt;/P&gt;&lt;P&gt;1. Active Directory &amp;gt; Directory Groups &amp;gt; Select the AD groups you want to use for in your authorization conditions.&lt;/P&gt;&lt;P&gt;2. create an identity source sequence with Cloud based radius server selected inside the authentication section and AD inside additional attribute retrieval say RSA-AD&lt;/P&gt;&lt;P&gt;3. While creating the authorization rule in access-policies use External AD group in condition to accomplish your goal.&lt;/P&gt;&lt;P&gt;Access Policies &amp;gt; Default Network Access &amp;gt; Authorization &amp;gt; Customize &amp;gt; Move "AD1:External Groups" from Available to selected section &amp;gt; ok&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: Don't forget to call RSA-AD in identity under default network access.&lt;/P&gt;&lt;P&gt;4. test the authentication and report back if needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jatin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2015 15:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-authorization/m-p/2594699#M74936</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2015-01-24T15:57:51Z</dc:date>
    </item>
  </channel>
</rss>

