cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
549
Views
0
Helpful
3
Replies

ACS 5.2 Access Policy processing

jlhainy
Level 2
Level 2

I have created two Access Services... One for VPN, one for wireless.  The VPN access policy is the first in the list and the Wireless one is the second.  Every time I try to authentication using the wireless policy, my vpn policy is the one that actually process the request.  Now because both of the Access Services use Radius, does that mean I cannot have More than 2 Radius Access services?  Do I need to combine these into one?

1 Accepted Solution

Accepted Solutions

Federico Lovison
Cisco Employee
Cisco Employee

Hi,

Sure that you can have more than one Access Service using RADIUS.

You need to make sure that RADIUS is not the only condition on the Service Selection Policy though.

You may want to add a condition to the Service Selection Policy matching the Network Device Group, and of course you would have to assign the Wireless and VPN devices to different NDGs.

Check the "customize" button on the SSP config in order to add more conditions:

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/access_policies.html#wp1052733

I hope this helps.

Regards,

Federico

--
If this answers your question please mark the question as "answered" and rate it, so other users can easily find it.

View solution in original post

3 Replies 3

Federico Lovison
Cisco Employee
Cisco Employee

Hi,

Sure that you can have more than one Access Service using RADIUS.

You need to make sure that RADIUS is not the only condition on the Service Selection Policy though.

You may want to add a condition to the Service Selection Policy matching the Network Device Group, and of course you would have to assign the Wireless and VPN devices to different NDGs.

Check the "customize" button on the SSP config in order to add more conditions:

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/access_policies.html#wp1052733

I hope this helps.

Regards,

Federico

--
If this answers your question please mark the question as "answered" and rate it, so other users can easily find it.

Yeah, I found that before I got your post.  It works well!  I am finally getting the hang of ACS 5.2 policies.... it took me a while though.

Great!

Thanks for confirming this is solved now :-)

Regards,

Federico