<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, If you use per in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515076#M236116</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you use per-useroverride option, then you have to define everything on the auto/dynamic acl attributes you set in ACS/Radius server.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do not use the per-user-override option then you need to have both interface ACL and Downloadable ACL as same... say it has to have all the 7 permit statements..... on ACL &amp;amp; ACS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;</description>
    <pubDate>Thu, 31 Jul 2014 10:57:34 GMT</pubDate>
    <dc:creator>nkarthikeyan</dc:creator>
    <dc:date>2014-07-31T10:57:34Z</dc:date>
    <item>
      <title>User Authentication with Downloadable ACLs</title>
      <link>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515073#M236109</link>
      <description>&lt;P&gt;I have config on ASA 9.1.3 with User Authentication via RADIUS ACS 5.5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On one ASA interface i have 5 permits inbound&lt;/P&gt;&lt;P&gt;permit ip dest A&lt;/P&gt;&lt;P&gt;permit ip dest B&lt;/P&gt;&lt;P&gt;permit ip dest C&lt;/P&gt;&lt;P&gt;permit ip dest D&lt;/P&gt;&lt;P&gt;permit ip dest E&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the ACS i have two downloadable ACEs for a user :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;permit ip dest F&lt;/P&gt;&lt;P&gt;permit ip dest G&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case i do not use per-user override option in access-group syntax, a packet needs to be&amp;nbsp;&lt;/P&gt;&lt;P&gt;matched on interface AND on downloadable ACL.&lt;/P&gt;&lt;P&gt;In my case dest A to G will not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case i do use per -user override option in access-group syntax, a packet needs to be&amp;nbsp;&lt;/P&gt;&lt;P&gt;matched only on downloadable ACL.&lt;/P&gt;&lt;P&gt;In my case dest F and G will work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did not find a way to merge both interface and downloadable ACL.&lt;/P&gt;&lt;P&gt;Requirement would be that without User Auth, A to E works.&lt;/P&gt;&lt;P&gt;In case User authenticates F and G work in ADDITION to A and E.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:33:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515073#M236109</guid>
      <dc:creator>owalter</dc:creator>
      <dc:date>2019-03-12T04:33:05Z</dc:date>
    </item>
    <item>
      <title>Hello, How they work is : </title>
      <link>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515074#M236111</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How they work is :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Without the user-override option:&lt;/P&gt;&lt;P&gt;Both ACLs (Configured on the FW and the ACS) will need to permit the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-With the user-override option:&lt;/P&gt;&lt;P&gt;Only the ACS downloable ACL is check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jcarvaja&lt;/P&gt;&lt;P&gt;CCIE 42930, 2xCCNP, JNCIS-SEC&lt;/P&gt;&lt;P&gt;For inmediate support http://iNetworks.cr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 23:57:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515074#M236111</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-07-30T23:57:08Z</dc:date>
    </item>
    <item>
      <title>Hello Jcarvaja,i did</title>
      <link>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515075#M236113</link>
      <description>&lt;P&gt;Hello Jcarvaja,&lt;/P&gt;&lt;P&gt;i did understand what the per user override means and how it works.&lt;/P&gt;&lt;P&gt;Unfortunately it does not give me a solution for my requirement in both options.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My intention was to ask about if there is a possibility to cover my requirement :&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;I did not find a way to merge both interface and downloadable ACL.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Requirement would be that without User Auth, A to E works.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;In case User authenticates F and G work in ADDITION to A and E.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 10:37:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515075#M236113</guid>
      <dc:creator>owalter</dc:creator>
      <dc:date>2014-07-31T10:37:41Z</dc:date>
    </item>
    <item>
      <title>Hi, If you use per</title>
      <link>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515076#M236116</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you use per-useroverride option, then you have to define everything on the auto/dynamic acl attributes you set in ACS/Radius server.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do not use the per-user-override option then you need to have both interface ACL and Downloadable ACL as same... say it has to have all the 7 permit statements..... on ACL &amp;amp; ACS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 10:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515076#M236116</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-07-31T10:57:34Z</dc:date>
    </item>
    <item>
      <title>Hello</title>
      <link>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515077#M236118</link>
      <description>Hello 

Well thats what I am telling you.

You only have those options

You would have to construct the acl on the acá as you require</description>
      <pubDate>Thu, 31 Jul 2014 12:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515077#M236118</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-07-31T12:24:26Z</dc:date>
    </item>
    <item>
      <title>Hello Karthik,thanks for your</title>
      <link>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515078#M236122</link>
      <description>&lt;P&gt;Hello Karthik,&lt;/P&gt;&lt;P&gt;thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: rgb(247, 247, 247);"&gt;&lt;FONT color="#777777"&gt;&lt;SPAN style="font-size: 14px;"&gt;"If you use per-useroverride option, then you have to define everything on the auto/dynamic acl attributes you set in ACS/Radius server….."&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Yes, but in case I have 500 ACEs on an interface already and need 5 additional per user authentication&lt;/P&gt;&lt;P&gt;i have to hold 505 on the ACS system. This looks very inefficient and is obviously either an ASA&lt;BR /&gt;or RADIUS limitation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px; background-color: rgb(247, 247, 247);"&gt;"If you do not use the per-user-override option then you need to have both interface ACL and Downloadable ACL as same... say it has to have all the 7 permit statements..... on ACL &amp;amp; ACS."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This does not really make sense to me.&lt;/P&gt;&lt;P&gt;In case i have all the 7 permits already on my interface, why should I bother with&amp;nbsp;&lt;/P&gt;&lt;P&gt;User Authentication to download exactly the same 7 permits to this interface ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 12:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515078#M236122</guid>
      <dc:creator>owalter</dc:creator>
      <dc:date>2014-07-31T12:45:13Z</dc:date>
    </item>
    <item>
      <title>Hello jcarvaja,Yes, but in</title>
      <link>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515079#M236123</link>
      <description>&lt;P style="color: rgb(119, 119, 119); font-size: 14px;"&gt;Hello jcarvaja,&lt;/P&gt;&lt;P style="color: rgb(119, 119, 119); font-size: 14px;"&gt;Yes, but in case I have 500 ACEs on an ASA interface already and need 5 additional per user authentication&lt;/P&gt;&lt;P style="color: rgb(119, 119, 119); font-size: 14px;"&gt;i have to hold 505 on the ACS system. This looks very inefficient and is obviously either an ASA&lt;BR /&gt;or RADIUS limitation.&lt;/P&gt;&lt;P style="color: rgb(119, 119, 119); font-size: 14px;"&gt;Best regards&lt;/P&gt;&lt;P style="color: rgb(119, 119, 119); font-size: 14px;"&gt;Oliver&lt;/P&gt;&lt;P style="color: rgb(119, 119, 119); font-size: 14px;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 12:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515079#M236123</guid>
      <dc:creator>owalter</dc:creator>
      <dc:date>2014-07-31T12:47:39Z</dc:date>
    </item>
    <item>
      <title>Hi, Yes. I agree with you for</title>
      <link>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515080#M236124</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes. I agree with you for my second suggestion it was supposed to be or not &amp;amp;....&amp;nbsp; having the same on both doesn't make sense...... But i see those are the limited options.... else you can have the access-restriction on the auth server itself restricted to the 5 hosts NDG/User group... something like that....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2014 13:14:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-authentication-with-downloadable-acls/m-p/2515080#M236124</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-07-31T13:14:48Z</dc:date>
    </item>
  </channel>
</rss>

