Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

ACS limit connections

Good morning.

We have the ACS Security Appliance and it is on version4.1(1) Build 23 Patch 4.

I am in the process of setting up a couple of NDGs. One of the NDGs I would like to have for our key routers and the other for our switches. The switches will have a command authorization set that allows our desktop personal to bring up and down ports.

Currently I have it for the routers that desktop can not issue any commands and no level when they log in but I would like to stop them from even being able to log in. Is this feasible?


Re: ACS limit connections


What you are trying to achive can be done using Network access restriction.

A condition specified in NAR needs to be met before a user can access any device in the network. Please refer to the link given below for more information on implementing NAR's in ACS :

*Setting Network Access Restrictions for a User Group*

*Network Access Restrictions White Paper*

Hope that helps !

Community Member

Re: ACS limit connections

I will definately check that out. Thank you!!!

Community Member

Re: ACS limit connections

Reading through the documentation is there a way to do it by a group?

For example, I have a group called Desktop and desktop can only access NDG A and B but not NDG C and my group Full_Access has access to A,B, and C.

Re: ACS limit connections

Yes, you can set it up on group level,

1) On ACS go to Group Desktop.

2) Edit Group

3) Jump to Access Restriction

4) On Per Group Defined Network Access Restrictio, enable IP based access restriction.

5)On aaa-clients drop down choose your NDG ( the one your want user should have access ie NDG a , b )

6)For Port and IP address use *

7)Choose condition Permit.

Now Desktop group will ONLY have access to A, B NDG. Rest all is denied.

For admin group do not set any NAR, so that they can browse whole network.


Community Member

Re: ACS limit connections

Again thank you very much!

Thankfully found out they needed this done before go live date.

CreatePlease to create content