ACS 5.1 TACACS+ and an AD group

Answered Question
Sep 7th, 2010
User Badges:

I have joined our ACS5.1 to AD.  I can map a group in the AD section and see that it mapped correctly.


How do I set TACACS+ to authenticate against that group?  I am not able to see that group appear anywhere in group choices.  I am also unable to see the users within that group anywhere.


Thanks.

Correct Answer by Nate Austin about 6 years 10 months ago

Hi burnsidestev,  That is all done from your Access Policies. Goto the Authorization tab of your TACACS  policy (usually Default Device Admin). Then hit the Customize button on that page. It should allow you to add new columns to the Conditions list, one of which should be "AD1: External Groups". Once that is added to the page you should be able to edit any rules and select any of the AD groups you selected under the original AD configuration.  Thanks,  Nate

Posted from my mobile device.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Nate Austin Tue, 09/07/2010 - 14:06
User Badges:
  • Cisco Employee,

Hi burnsidestev,  That is all done from your Access Policies. Goto the Authorization tab of your TACACS  policy (usually Default Device Admin). Then hit the Customize button on that page. It should allow you to add new columns to the Conditions list, one of which should be "AD1: External Groups". Once that is added to the page you should be able to edit any rules and select any of the AD groups you selected under the original AD configuration.  Thanks,  Nate

Posted from my mobile device.

Actions

This Discussion