Same user in different ACS groups?

Unanswered Question
Apr 16th, 2007
User Badges:


We have this scenario:

A user at home connects via SSL VPN is authenticated by Cisco ACS/RADIUS. User ends up in a specifig SSL VPN group on the ACS. This group is configured with specific properties for SSL VPN.

Now the same user comes to work with his/her private laptop and wants to access the guest wlan which our policy allows. We have a WLC4402 providing the guest wlan. User opens browser and logs in to the guest wlan, gets authenticated on the Cisco ACS/RADIUS and ends up in the same SSL VPN group.

My question is can we configure our ACS 4.1 in such way that it is context sensitive? Knows where the user is coming from and places the user in the right group accordingly?

We use LDAP group mappings and they are very static.

Any ideas?

Kind regards,


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 3 (1 ratings)
darpotter Mon, 04/16/2007 - 06:45
User Badges:
  • Silver, 250 points or more

With ACS v4.1 and NAP, externally authenticated users get a user record for each NAP they authenticate against.

As each NAP may have its own external authenticator config, db mappings and authorisation - it should be totally possible.

The trick is setting up the NAPs to trigger on RADIUS requests of the appropriate type.

Rutger Blom Mon, 04/16/2007 - 11:04
User Badges:


I didn't know this was possible using NAPs. Triggering the NAPs could in our case be done by specifying the NAS IP users come from.

I will test with NAPs and come back to you.

Kind regards,



This Discussion