03-21-2017 10:40 AM
Team,
My customer has 2 times, one for networking handling routing, switching and so on and another team which is security team that handles the firewalls.
The customer wants to provide a kind of role based access meaning they want the security team to check the AAA logs of the ASA and the networking team to have only the AAA logs for the switches
Is this possible?
Please advise
Solved! Go to Solution.
03-21-2017 01:56 PM
If your reffering to authc and authz based on AD groups then yes.
Heres in example:
03-21-2017 11:01 AM
Hi,
Yes it is.
This should give you some good examples and best practice.
03-21-2017 01:13 PM
Hi Danny,
Thanks for your reply
I was really referring to a kind of multi-tenancy, I did not find any document from the link you mentioned with this kind of scenario
Please advise
Kind regards,
Mohamad
——————————————
Mohamad Kabbara
Systems Engineer- Levant
JabberCall Me<https://sjc-jabberc-ext.cisco.com/call/89622133@cisco.com?name=Mohamad%20Kabbara>
browser-based video chat
03-21-2017 01:16 PM
I think I find it, please check the following link
http://www.cisco.com/c/en/us/td/docs/security/ise/2-0/ise_active_directory_integration/b_ISE_AD_integration_20.html
the scenario of multi-tenancy where we define like sub companies, please advise if it is correct as per my understanding
Kind regards,
Mohamad
——————————————
Mohamad Kabbara
Systems Engineer- Levant
JabberCall Me<https://sjc-jabberc-ext.cisco.com/call/89622133@cisco.com?name=Mohamad%20Kabbara>
browser-based video chat
03-21-2017 01:56 PM
If your reffering to authc and authz based on AD groups then yes.
Heres in example:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide