cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2312
Views
0
Helpful
4
Replies

LMS 2.5 and TACACS user authentication

rodom
Level 1
Level 1

I just switched from local to ACS for my CiscoWorks user authentication. It seems to work, but I can't seem to limit beyond what I could do with a local user.

I wanted to limit what machines a user could access via CiscoView, but I can't, even though the configuration options imply you could limit the access by TACACS network groups.

I tried stopping all CiscoView using None and that didn't stop access either.

Anyone else attempting to use TACACS for user authentication into CW? Any luck limiting a user's view (not change authority - just which machines they can access).

4 Replies 4

smahbub
Level 6
Level 6

ACS can be used to authenticate users but not assign roles. User must have an account in Ciscoworks assigned with the proper roles. This account must be identical to the Ciscoworks account or the authenticated user will get guest access.

LMS 2.5 does have permission roles within ACS exceeding the granularity of local user. However, you have to restart LMS when switching between local and TACACS.

It is now working correctly and I can use ACS network groups to separate who can access which devices in CiscoWorks.

Can you provide some more details on how you got that working. I am able to setup the ACS integration but I can't limit or allow who sees wat

Chapter 5 of the Common Services 3.0 White Paper might be of help:

http://www.cisco.com/en/US/products/sw/cscowork/ps2425/prod_white_papers_list.html