<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Downloadable ACL for users only? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/downloadable-acl-for-users-only/m-p/2379594#M89205</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do this by following these steps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Set a user defined dictionary attribute under System Administration &amp;gt; Dictionary &amp;gt; Identity &amp;gt;Internal Users name it what you want and make sure the value is string&lt;/P&gt;&lt;P&gt;2. Create the DACL in Named Permission Objects under the policy elements section&lt;/P&gt;&lt;P&gt;3. Under the user account you will now see a filed for the dictionary name you called in step 1, make sure the filed matches the dacl you created in step 2&lt;/P&gt;&lt;P&gt;4. Create your authorization profile under "common tasks" Set Dynamic as the DACL drop down select Internal Users and set the value to the attribute you created in step1.&lt;/P&gt;&lt;P&gt;5 map the authorization policy to the access policy using the conditions that will give you these results.&lt;/P&gt;&lt;P&gt;6. test and you should have what you are looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Dec 2013 02:43:11 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2013-12-20T02:43:11Z</dc:date>
    <item>
      <title>Downloadable ACL for users only?</title>
      <link>https://community.cisco.com/t5/network-access-control/downloadable-acl-for-users-only/m-p/2379593#M89204</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in ACS 5.4 I need customized ACL for users only. &lt;/P&gt;&lt;P&gt;My scenario:&lt;/P&gt;&lt;P&gt;There is a way to use some "Downloadable ACLs" in authorization profile but I want to define specific ACLs for some exeptions. For example: User A and user B get autorization profile "X". But user B is not allowed to access on a host. This "Deny rule" I will configure with custom attributes in the internal user store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that possible? How can I implement this rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Stefan&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:12:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/downloadable-acl-for-users-only/m-p/2379593#M89204</guid>
      <dc:creator>vita_user</dc:creator>
      <dc:date>2019-03-11T04:12:03Z</dc:date>
    </item>
    <item>
      <title>Downloadable ACL for users only?</title>
      <link>https://community.cisco.com/t5/network-access-control/downloadable-acl-for-users-only/m-p/2379594#M89205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do this by following these steps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Set a user defined dictionary attribute under System Administration &amp;gt; Dictionary &amp;gt; Identity &amp;gt;Internal Users name it what you want and make sure the value is string&lt;/P&gt;&lt;P&gt;2. Create the DACL in Named Permission Objects under the policy elements section&lt;/P&gt;&lt;P&gt;3. Under the user account you will now see a filed for the dictionary name you called in step 1, make sure the filed matches the dacl you created in step 2&lt;/P&gt;&lt;P&gt;4. Create your authorization profile under "common tasks" Set Dynamic as the DACL drop down select Internal Users and set the value to the attribute you created in step1.&lt;/P&gt;&lt;P&gt;5 map the authorization policy to the access policy using the conditions that will give you these results.&lt;/P&gt;&lt;P&gt;6. test and you should have what you are looking for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Dec 2013 02:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/downloadable-acl-for-users-only/m-p/2379594#M89205</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-12-20T02:43:11Z</dc:date>
    </item>
  </channel>
</rss>

