<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 3.0 overlapping device groups  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-0-overlapping-device-groups/m-p/92708#M9709</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Often times complex configuration/troubleshooting issues are best addressed in an interactive session with one of our trained technical assistance engineers.  While other forum users may be able to help, it&amp;#146;s often difficult to do so for this type of issue.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To utilize the resources at our Technical Assistance Center, please visit &lt;A class="jive-link-custom" href="http://www.cisco.com/tac" target="_blank"&gt;http://www.cisco.com/tac&lt;/A&gt; and to open a case with one of our TAC engineers, visit &lt;A class="jive-link-custom" href="http://www.cisco.com/tac/caseopen" target="_blank"&gt;http://www.cisco.com/tac/caseopen&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone else in the forum has some advice, please reply to this thread.&lt;/P&gt;&lt;P&gt;	&lt;/P&gt;&lt;P&gt;Thank you for posting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 May 2002 00:57:39 GMT</pubDate>
    <dc:creator>ciscomoderator</dc:creator>
    <dc:date>2002-05-29T00:57:39Z</dc:date>
    <item>
      <title>ACS 3.0 overlapping device groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-0-overlapping-device-groups/m-p/92707#M9704</link>
      <description>&lt;P&gt;Trying to restrict users to a single device group e.g. 172.17.*.*.  I can get it to work fine using "Network Configuration-&amp;gt; Network Device Groups"but I can't set up overlapping NDGs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I can't get NAR to restrict access.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** My NAR call "172.17-Europe" looks like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Define IP-based access restrictions - ticked&lt;/P&gt;&lt;P&gt;Table defines = Permitted Calling/Point of Access Locations&lt;/P&gt;&lt;P&gt;AAA Client = "All AAA Clients"&lt;/P&gt;&lt;P&gt;Port = *&lt;/P&gt;&lt;P&gt;Src IP Address = 172.17.*.*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** My group looks like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only allow network access when - ticked&lt;/P&gt;&lt;P&gt;Any one selected NAR results in permit - selected&lt;/P&gt;&lt;P&gt;Selected-NARs=172.17-Europe&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I attempt to telnet and login to any 172.17 device, Failed Attempts.csv reports....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message Type = Authen failed&lt;/P&gt;&lt;P&gt;Authen Failure Code = User Access Filtered&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I can get this woirking I then want to create additional NAR which are subsets of the 172.17 domain e.g. 172.17.20-London or 172.17.*.1-Europe-routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:00:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-0-overlapping-device-groups/m-p/92707#M9704</guid>
      <dc:creator>ed.tarento</dc:creator>
      <dc:date>2020-02-21T18:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.0 overlapping device groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-0-overlapping-device-groups/m-p/92708#M9709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Often times complex configuration/troubleshooting issues are best addressed in an interactive session with one of our trained technical assistance engineers.  While other forum users may be able to help, it&amp;#146;s often difficult to do so for this type of issue.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To utilize the resources at our Technical Assistance Center, please visit &lt;A class="jive-link-custom" href="http://www.cisco.com/tac" target="_blank"&gt;http://www.cisco.com/tac&lt;/A&gt; and to open a case with one of our TAC engineers, visit &lt;A class="jive-link-custom" href="http://www.cisco.com/tac/caseopen" target="_blank"&gt;http://www.cisco.com/tac/caseopen&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone else in the forum has some advice, please reply to this thread.&lt;/P&gt;&lt;P&gt;	&lt;/P&gt;&lt;P&gt;Thank you for posting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2002 00:57:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-0-overlapping-device-groups/m-p/92708#M9709</guid>
      <dc:creator>ciscomoderator</dc:creator>
      <dc:date>2002-05-29T00:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.0 overlapping device groups</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-0-overlapping-device-groups/m-p/92709#M9712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some trial and error in the lab proved successful.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA Clients cannot overlap&lt;/P&gt;&lt;P&gt;NDGs cannot overlap&lt;/P&gt;&lt;P&gt;BUT NARs can overlap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a bit messy but works, on to the next problem, applying priv levels to diff user in diff groups on diff over lapping device groups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2002 11:32:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-0-overlapping-device-groups/m-p/92709#M9712</guid>
      <dc:creator>ed.tarento</dc:creator>
      <dc:date>2002-05-30T11:32:06Z</dc:date>
    </item>
  </channel>
</rss>

