03-22-2012 08:58 AM
Guys,
Is there a way that I can configure authentication using ACS 5.0 to access a certain server farm group only for a specific user?
Sent from Cisco Technical Support iPad App
Solved! Go to Solution.
03-23-2012 02:35 AM
Yes you could using roles & domains. you would initially have to configure a domain on the ACE and add the relevant serverfarm to it.
Then in ACS configure the policy for authentication & authorization and under the Shell Profile / Custom Attributes section add an attribute of shell:
03-26-2012 01:40 AM
To match against an AD attribute, firstly you would need to configure ACS to see your windows domain as a valid External Identity store then your authorization policy would need to make use of what ACS calls 'Group Mappings'.
This is where you tell ACS what attribute to look for in AD and what the resultant internal ID group is. This internal ID group is then used in your authorization policy
If you need any more information, take a look at the ACS guides or ask the experts over in the Security/AAA section.
03-23-2012 02:35 AM
Yes you could using roles & domains. you would initially have to configure a domain on the ACE and add the relevant serverfarm to it.
Then in ACS configure the policy for authentication & authorization and under the Shell Profile / Custom Attributes section add an attribute of shell:
03-25-2012 07:16 AM
Thank you so much , but how can I match this with the group on the AD since I am using the external DB method not the internal?
Sent from Cisco Technical Support iPad App
03-26-2012 01:40 AM
To match against an AD attribute, firstly you would need to configure ACS to see your windows domain as a valid External Identity store then your authorization policy would need to make use of what ACS calls 'Group Mappings'.
This is where you tell ACS what attribute to look for in AD and what the resultant internal ID group is. This internal ID group is then used in your authorization policy
If you need any more information, take a look at the ACS guides or ask the experts over in the Security/AAA section.
03-26-2012 08:33 AM
Thanks Mick, it is working like charm
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide