Hi,
Try the Network Access Restrictions (edit Group properties). It is used to permit or deny a group access using an access filter.
- Create users and assign them to Group A & B.
- Create/add network devices (as AAA client) under their respective network device group of switches & routers and MGX.
- Then, under each group, go to :
- Network Access Restrictions (NAR) - Per Group Defined Network Access Restrictions
- Enable checkbox under - Define IP-based access restriction
AAA Client - select AA client group permitted to be access by this user Group.
* Refer to ACS's help under help for "Network Access Restrictions" when you edit the group.
More info at:
http://www.cisco.com/en/US/products/sw/secursw/ps5338/products_user_guide_chapter09186a008023360f.html#wp865760
Rgds,
AK