<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs/m-p/70217#M9781</link>
    <description>&lt;P&gt;Anyone can help for the following question ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How many NAS priviledge password or users can be created via the Cisco ACS? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the users can their password for next login. Will it must did it on ACS server or? This provides sense to memorize the password. Please advise. Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 17:58:49 GMT</pubDate>
    <dc:creator>danny_ng</dc:creator>
    <dc:date>2020-02-21T17:58:49Z</dc:date>
    <item>
      <title>Cisco ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs/m-p/70217#M9781</link>
      <description>&lt;P&gt;Anyone can help for the following question ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How many NAS priviledge password or users can be created via the Cisco ACS? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the users can their password for next login. Will it must did it on ACS server or? This provides sense to memorize the password. Please advise. Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:58:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs/m-p/70217#M9781</guid>
      <dc:creator>danny_ng</dc:creator>
      <dc:date>2020-02-21T17:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs/m-p/70218#M9782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The number of users and corresponding password on created on the internal Cisco ACS db, is limited by the hard disk space of the server itself. It could easily handle 100,000 users as per:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/csnt30/user/z.htm#xtocid1276317" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/csnt30/user/z.htm#xtocid1276317&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your second question, could you pls clarify?  If you are after the users being able to change their passwords themselves, you could do this with the UCP as in:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/csnt30/ucp30.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/csnt30/ucp30.htm&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2002 00:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs/m-p/70218#M9782</guid>
      <dc:creator>cjacinto</dc:creator>
      <dc:date>2002-02-22T00:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs/m-p/3347885#M9786</link>
      <description>&lt;P&gt;Assign ACS ver 4.2 and&amp;nbsp; to setup users with limited access to our switchs and routers.&amp;nbsp; Here is what to do?&lt;BR /&gt; 1) Created a user in ACS&lt;BR /&gt; 2) Create Shell command Autorization Set - ReadOnly&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unmatched Commands - Deny&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Commands Added&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; exit&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * this should limit the user to the show and exit command only (correct)?&lt;BR /&gt; &lt;BR /&gt; 3) Created a group - HelpDesk with the following TACACS+ Settings&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Shell (exec) is checked&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priviledge level is check with 15 as the assigned level&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Assign a Shell Command Authorization Set for any network device - selected&lt;BR /&gt; &lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ReadOnly - shell command autorization set seleted&lt;BR /&gt; &lt;BR /&gt; When the user logs on to the router/switch it appears that he has full access.&amp;nbsp; He can enter the enable command, config terminal command, etc.&amp;nbsp; All we want him to be able to do is to issue the show command.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 19:39:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs/m-p/3347885#M9786</guid>
      <dc:creator>sbhadrav@cisco.com</dc:creator>
      <dc:date>2018-03-13T19:39:37Z</dc:date>
    </item>
  </channel>
</rss>

