06-19-2013 07:47 AM - edited 03-10-2019 08:33 PM
I have the AD authentication working but something funny is going on. Under Identity it is set to AD1 and I have our security group defined under the active directory directory groups but anyone who has a AD account is able to authenticate. Any ideas???
Solved! Go to Solution.
06-19-2013 08:27 AM
What does your default policy say (deny or permit)? If it says deny and other users still have access to devices then please go to tacacs authentication, clcik on the magnifying glass and check what authorization rule is that request going through.
Jatin Katyal
- Do rate helpful posts -
06-19-2013 07:58 AM
What kind of authentication is this?
Ad account can be used to authenticate ACS admin for gui administration and it can also be used for network/device administration as well. For both types we have to call/bind that security group in a rule. What you have done is just a selection of the group from AD.
Jatin Katyal
- Do rate helpful posts -