08-08-2005 09:03 AM - edited 03-10-2019 02:15 PM
Hello,
I am having an authorization issue with ACS 3.2.3.
This is what I am trying to do: I have 2 Network Device Groups, one called core the other called edge. I have 2 groups of admins. One is Core admins and other is LAN admins. What I am trying to do is set up authorization so that the LAN admins can telnet into into the edge switches that belong to the edge Network Device Group. They will have the enable password for those devices so they can do whatever they need to do.
However, if they telnet into a core device I want the authorization to stop them so that they can't even connect to the device.
So my Lan admins will get full access to edge devices, but zero access to core devices. This is what I am trying to accomplish.
The closest I have come is allowing the LAN people to telnet or ssh to a core device, but not giving the enable password. So they have "read only" access to core devices. I don't even want this. How can I configure ACS to give me this behavior? I already have my aaa config in my network device configs.
08-12-2005 04:08 AM
Here is a document on Setting Network Access Restrictions for a User Group.
http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs31/acsuser/g.htm#81096
08-12-2005 11:25 AM
Perfect! That was an excellent document. Thank you very much.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide