cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1201
Views
0
Helpful
4
Replies

ACS - Network Access Restrictions

juamaya
Level 4
Level 4

Hi,

All my users are in Active Directory. I can authenticate users (VPN, RAS and telnet) towards Radius server in ACS and now I need to control what they can access.

Does anyone have tips on how configuring NAR so:

- Net Admin users can telnet/ssh/http network devices

- VPN users can VPN into PIX

- RAS users can dial up with PPP?

In this case, some users profiles overlap. I mean

1. I am the net admin who can telnet/ssh/http the routers and must be able to VPN into the PIX.

2. Office users must be able to VPN in or Dial UP.

3. Remote routers can dial Backup to specific RAS servers.

Any tip about how I can create those "IP-based restrictions" or "CLI/DNIS access restricions" is appreciated.

Thanks!

4 Replies 4

pradeepde
Level 5
Level 5

chandlerbr
Level 1
Level 1

Map the AD users to ACS Groups. As new users log in for the first time, they should get placed in the appropriate ACS group. You can manually move any user that has logged in and is in the ACS Default group.

Then in the ACS Group properties, allow the group to access to individual network devices, or Network Device Groups. You might want to take a look the Shared Profile Components in ACS as well. Pretty good stuff.

hth

Hi Chandler,

I am working on the same requirement. Do you happen to have the detailed configuration which you can share with us ?

Cheers

Create NDGs [network device groups] and map what user/groups have access to what Ndgs