cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
446
Views
0
Helpful
1
Replies

Restricting Access to Group

joe.marcelo9
Level 1
Level 1

Hello

I have ACS 4.0 authentication through external database Windows Active Directory. I want only support group created on ACS to have access rights to AAA client [Routers,Firewall,Switches] for telnet & SSH all members of other group should be denied.

Groups are created.

AAA members are added to ACS

but restricting to specific group not working

1 Reply 1

darpotter
Level 5
Level 5

Assuming you've confirmed that T+ authentications are actually been sent to your ACS, then it should be just a case of adding Windows group mappings:

Support -> ACS Support Group

Default -> NO ACCESS

Group mapping is applied after AD authentication, so even if correct credentials are supplied the user will be mapped to NO ACCESS (ie rejected) if they are not a member of the correct AD group.