cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
477
Views
5
Helpful
1
Replies

ACS 5.4 indentity group rule condition

Ibrahim Ramku
Level 1
Level 1

Dear All,

I have upgraded from ACS 3.3 to ACS 5.4. I had ASA configured as tacacs client, with several AAA Server Groups referencing to the groups in the ACS local database and mapped groups from AD. Each group was used for diferent services, i.e Remote-Access VPN 1 referencing to group1, Auth-proxy to group2 ect. Now with the new deployment I cannot configure the same enviroment. It seems that identity groups can only be chosen as a condition in authentication policy. Do you have any suggestion?

Regards,

Ibra

1 Reply 1

Ibrahim Ramku
Level 1
Level 1

According to this guide:

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/policy_mod.html#wp1075731

ACS 5.x cannot use identity store elements as conditions for service access selection rules.

I solved the problem by using Radius DAP-Tunnel-Group-Name.

Regards,

Ibra

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: