cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
638
Views
0
Helpful
1
Replies

ACS 5.3 Single Device on multiple NDG Groups

mark.zimmerman
Level 1
Level 1

I have multiple campuses and a Central Admin...I've created Groups for all, except I need a few devices within Central to be available to the Campus Admins... (ie..a Cisco WCS System) How do I allow a device to be put into multiple NDG groups? According to the documentation it should be possible.

Any assistance greatly appreciated..                   

1 Reply 1

Michal Garcarz
Cisco Employee
Cisco Employee

Hi Mark,

It's a hierarhical system. You can create a group Campus and inside that group several other groups like Department1 and Department2. Device can only be assigned to one group, but it will inherit all parent groups.

Example:

Campus

     Department1 (Router1)

     Department2 (Router2)

Then you can write one rule in Access Policies that will be applied only for Department1 or Department2.

Then you can write general rule in Access Policies that will be related to Compus NDG which consists of both routers.

More here:

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/net_resources.html#wp1052534

--

Michal