cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1176
Views
5
Helpful
2
Replies

ACS 5.2 Tacacs+ Authorization

stormfidus
Level 1
Level 1

Hi All

I have an ACS 5.2 running, where we have setup Tacacs authentiation on network devices -  switches, routers etc.

It's working fine with external authentication towards a specific AD group for all devices.

Im trying to segment the access based on the device ip subnet, but has only been successfull doing this within Access Policies/Authorization and with the field "Device IP Address" which only can be equal to a specific ip address or not equal to it - not possible to choose a whole subnet.

The goal is to be able to map 2 different AD groups, where the group "full-access" have access to all the devices, and the group "partial-access" only have access to devices located in a specific subnet, such as only 10.30.0.0/16.

Does anybody know how to achieve this ?

1 Accepted Solution

Accepted Solutions

Jatin Katyal
Cisco Employee
Cisco Employee

Have you tried device filter under policy elements > session conditions > network conditions > device filters. Once done, go to access-policy > authorization > clcik on customize tab > move the device filter in the selected section.

Regards,

Jatin Katyal


- Do rate helpful posts -

~Jatin

View solution in original post

2 Replies 2

Jatin Katyal
Cisco Employee
Cisco Employee

Have you tried device filter under policy elements > session conditions > network conditions > device filters. Once done, go to access-policy > authorization > clcik on customize tab > move the device filter in the selected section.

Regards,

Jatin Katyal


- Do rate helpful posts -

~Jatin

Hi Jatin

This was exactly what I was looking for, thanks!