<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS User Groups in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-user-groups/m-p/127967#M9400</link>
    <description>&lt;P&gt;I have an issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 2 groups which are created in ACS, Group 1: Tacacs Access, and Group 2:Radius Access. The 1st group has individuals that have been created on the ACS server itself. The 2nd group is dynamic users who are being enabled access through User Manager for Domains. We do not want to have the 2nd group to be able to access our routers and switches with their Microsoft Accounts, which they currently can, atleast as far as to the enable prompt. I would like to have the 2 groups be totally independent of one another. Our 1st group is only used for our administrators to access all our network devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure that some type of filtering or allowing of a certain group of IP addresses could be implemented on the ACS, but I am unsure where, if this is the case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please help! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:07:55 GMT</pubDate>
    <dc:creator>matt.austin</dc:creator>
    <dc:date>2020-02-21T18:07:55Z</dc:date>
    <item>
      <title>ACS User Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-groups/m-p/127967#M9400</link>
      <description>&lt;P&gt;I have an issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 2 groups which are created in ACS, Group 1: Tacacs Access, and Group 2:Radius Access. The 1st group has individuals that have been created on the ACS server itself. The 2nd group is dynamic users who are being enabled access through User Manager for Domains. We do not want to have the 2nd group to be able to access our routers and switches with their Microsoft Accounts, which they currently can, atleast as far as to the enable prompt. I would like to have the 2 groups be totally independent of one another. Our 1st group is only used for our administrators to access all our network devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure that some type of filtering or allowing of a certain group of IP addresses could be implemented on the ACS, but I am unsure where, if this is the case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please help! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-groups/m-p/127967#M9400</guid>
      <dc:creator>matt.austin</dc:creator>
      <dc:date>2020-02-21T18:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: ACS User Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-groups/m-p/127968#M9402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to set up Network Access Restrictions (NAR), restricting Group 2 to not be able to access the routers/switches.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure Group-Level NAR is checked under Interface Config - Advanced Options.  Then go under Group 2, to the NAR section, check the "Define IP-based access restrictions" box, select Table defines "Denied calling points", then select each of the routers/switches, using an * for Port and Address and add them to the table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will deny anyone in Group 2 from authenticating to any of the routers/switches.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2003 05:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-groups/m-p/127968#M9402</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-08-07T05:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: ACS User Groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-groups/m-p/127969#M9404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your expertise!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution you recommended worked great!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate your assistance, good luck in your endeavors!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2003 08:47:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-groups/m-p/127969#M9404</guid>
      <dc:creator>matt.austin</dc:creator>
      <dc:date>2003-08-07T08:47:24Z</dc:date>
    </item>
  </channel>
</rss>

