LMS & ACS Permissions by VLAN

Unanswered Question
Jan 5th, 2009
User Badges:

Using ACS version 4.2 & LMS version 3.1

Multiple catalyst4506 network. One of the vlans in the environment is dedicated to a subsidiary company. The operators in this vlan want to be able to enable/disable and add descriptions to the ports in their vlan. They have one switch which I was able to lock down, however they also have a blade in one of the parent company's switches. Can I limit their access to that specific blade or to their vlan on the switch? Thanks for the help

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Joe Clarke Mon, 01/05/2009 - 09:34
User Badges:
  • Cisco Employee,
  • Hall of Fame,

    Founding Member

The only restricting you can do is with ACS. With ACS, you can restrict certain LMS users to only being able to access certain devices. This is done by creating NDGs within ACS, then attaching the ACS users to those NDGs for LMS roles.

However, you cannot limit access to a specific VLAN or interface on a switch (without using something like VRFs on the device). LMS + ACS will only give you device-level access.


This Discussion