I created two groups on ACS 3.1. One is for wireless user ,another group is used for VPN client. I found that when I try to use VPN servece,I can also login with user ID belongs to wireless group and vice versa.
NAS (Network Access Restriction) Filter is the only options here. All you need to do is in your VPN group, just allow the AAA client for VPN device and deny rest of the NASes. Then in Wireless group, just allow the Wireless device as AAA client and deny the rest. Here are the links that will help you understanding and configuring NAR.
I am using ACS 3.2 with Win2K AD and group mappings to four AD user groups.
I had tried NAR feature but it does not seem to do any sort of filtering. I can still authenticate with users from other mapped groups to all the AAA clients even though the group NAR specifically permits only certain AAA clients and denies all other.
BenefitsDocumentationPrerequisiteImage Download LinksLimitationsSupported PlatformsLicense RequirementsTopologyStep-By-Step ConfigurationConfigure Virtual ServiceActivate the virtual service and configure guest IPsConfiguring UTD (Service Plane)Configurin...
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...