cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
837
Views
0
Helpful
2
Replies

ACS 5.2 AD authentication restriction failure

ferran
Level 1
Level 1

I've my ACS linked with AD to give administration access to few network devices and I've created an access policy to link my AD groups with those network devices and command sets.

Unfortunately I found I can use any user from my AD to login to my devices. Only LOGIN, the authorization definition is restricting the command set for those users.

How can I restrict the LOGIN to an specific AD group?

Thanks in advance.

1 Accepted Solution

Accepted Solutions

Nicolas Darchis
Cisco Employee
Cisco Employee

Can you detail your policy configuration ?

Are you doing radius or tacacs ?

If you return an authorization profile "deny access" it should be good enough in radius. Not sure about tacacs though.

View solution in original post

2 Replies 2

Nicolas Darchis
Cisco Employee
Cisco Employee

Can you detail your policy configuration ?

Are you doing radius or tacacs ?

If you return an authorization profile "deny access" it should be good enough in radius. Not sure about tacacs though.

You were right in my policy the default rule had a permit access insted of deny. I can confirm it works now and I'm using TACACS by the way.

Thanks a lot!!!!