<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 4.2 authentication issue in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080991#M19286</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/4/6/118644-Authentication%20log.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;hparekh users is member of Group 1 &amp;amp; Group 6 when he login in Wi-Fi he is authenticated through Group 6 &amp;amp; all the users of group 6 is login in Wi-fi since those are not member of any Wi-Fi group. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Dec 2012 03:12:10 GMT</pubDate>
    <dc:creator>hirenparekh12</dc:creator>
    <dc:date>2012-12-13T03:12:10Z</dc:date>
    <item>
      <title>ACS 4.2 authentication issue</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080988#M19283</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have created two ssid on WLC &amp;amp; authentication Via ACS to AD. after that i have configure TACACS+ on same ACS Server but some of the users can login in Wi-Fi which are not in member of Wi-Fi group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the below ACS configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 1 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;nbsp; HIgh managemnet Users&amp;nbsp; " this user can login in SSID 1"&lt;/P&gt;&lt;P&gt;Group 3 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Corporate User&amp;nbsp;&amp;nbsp;&amp;nbsp; "this users can login in SSID 2"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In group configuration i have configure DNIS/CLI based configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA client select&lt;/P&gt;&lt;P&gt;Port *&lt;/P&gt;&lt;P&gt;CLI * &lt;/P&gt;&lt;P&gt;DNIS *SSID1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same configuration for SSID 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after that i have creat two more group for TACACS + for Device authentication (Shell command based) (Authentication through AD)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 5 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Full Access&lt;/P&gt;&lt;P&gt;Group 6 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Read Only Access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but now what ever user are in group 5 &amp;amp; 6 those are login in Wifi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how to stop them?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080988#M19283</guid>
      <dc:creator>hirenparekh12</dc:creator>
      <dc:date>2021-07-04T06:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.2 authentication issue</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080989#M19284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to see what policy these users are hitting. It seems like there is a policy that might be higher that these users are hitting and not what you want to use. Clear the counters and check the log and test. Radius and Tacacs are separate and has nothing to do with each other. You might want to post some screen shots of your ACS so we can see what you have setup.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 12:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080989#M19284</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-12-12T12:33:29Z</dc:date>
    </item>
    <item>
      <title>ACS 4.2 authentication issue</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080990#M19285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; &lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/4/6/118640-Group%201.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configure above setting for SSID 1 in Group 1 &amp;amp; MAP security group (with AD) with Group 1 in external Database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/4/6/118641-Group%202.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configure above setting for SSID 2 in Group 3 &amp;amp; MAP security group (with AD) with Group 3 in external Database.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;P&gt;till the time user maped in Group 3 is not login in group1 SSID.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;P&gt;after that i have configure TACACS + on same server with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 5 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Full Access ( Shell command authorization Set)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group 6 &amp;gt;&amp;gt;&amp;gt;&amp;gt; Read Only Access.( Shell command authorization Set)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exp. hparekh is member of Group 6 &amp;amp; Group 3 but now it is login in Group 1 SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/4/6/118642-Tacacs%2B.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the External database setting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/4/6/118643-Database.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 03:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080990#M19285</guid>
      <dc:creator>hirenparekh12</dc:creator>
      <dc:date>2012-12-13T03:01:31Z</dc:date>
    </item>
    <item>
      <title>ACS 4.2 authentication issue</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080991#M19286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/4/6/118644-Authentication%20log.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;hparekh users is member of Group 1 &amp;amp; Group 6 when he login in Wi-Fi he is authenticated through Group 6 &amp;amp; all the users of group 6 is login in Wi-fi since those are not member of any Wi-Fi group. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 03:12:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080991#M19286</guid>
      <dc:creator>hirenparekh12</dc:creator>
      <dc:date>2012-12-13T03:12:10Z</dc:date>
    </item>
    <item>
      <title>ACS 4.2 authentication issue</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080992#M19287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default any groups is allowed to Wi-Fi unless you explicitly prevent it. For groups 5 &amp;amp; 6 not to connect to any SSID, you need to create CLI/DNIS filter to DENY access to all SSIDs. (or you can try creating an IP-based filter and DENY access to the WLC devices. This only works correctly if you do not use ACS to provide management access to the WLC/WLCs or else the management access will also be denied from the denied groups).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 03:42:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080992#M19287</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-12-13T03:42:45Z</dc:date>
    </item>
    <item>
      <title>ACS 4.2 authentication issue</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080993#M19288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if i am block the SSID in Group 5&amp;nbsp; &amp;amp; 6 then i am unable to connect any SSID which i am member of Group 1 SSID.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 07:31:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080993#M19288</guid>
      <dc:creator>hirenparekh12</dc:creator>
      <dc:date>2012-12-13T07:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.2 authentication issue</title>
      <link>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080994#M19289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean by that? How can a user be a member of two groups at the same time? That is not possible with your version.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2012 10:19:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/acs-4-2-authentication-issue/m-p/2080994#M19289</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-12-13T10:19:38Z</dc:date>
    </item>
  </channel>
</rss>

