07-02-2003 10:49 AM - edited 03-10-2019 07:23 AM
We purchased ACS3.1 and will like to use NDS as the external database for authenticating dialing-users. This configuration is working fine, but now how can I restrict a specific dialing-users from authenticating to NDS.
07-02-2003 12:57 PM
Hi,
On ACS you need to configure NAR (Network Access Restrictions). Here is the procedure -
Thanks,
Mynul
07-02-2003 01:31 PM
Mynul,
What I meant is how can I resrict dialing-users/remote-users/vpn-users to authenticate to NDS. Below are three scenarios that we have in production and we are planning to migrate to ACS. At this time authentication is being done using each device's local database.
vpn users---->VPN3000--->ACS3.1--->NDS(external database)
dialing-users-->Shiva---->VPN3000--->ACS3.1--->NDS(external database)
pptp-users---->WatchGuard(FBII)--->ACS3.1--->NDS(external database)
07-02-2003 03:02 PM
Hi,
Not sure if I understand your question correctly. It appears that you are looking for seperating the users for different traffic (VPN, dialup, PPTP) and make sure that VPN users cannot connect for dialup and vice versa. If thats the case, then you need to create three different group in NDS and 3 groups in ACS and then MAP the corresponding ACS group with the NDS group. Finally you need to apply NAR described earlier in every group and allow or disallow the devices.
Pl. let me know if this answers your question. Regards,
Mynul
07-03-2003 10:20 AM
Yes, that's the idea. But how can I restrict 2 users out of 5 that are members of the same group from authenticating to NDS. When I map a NDS group to ACS group, everyone within the NDS container are able to authenticate.
I do not have a problem setting restrictions for users to access devices, this works fine.
Thanks for your help.
07-03-2003 10:28 AM
Hi,
Unfortunately, if thats the case, it will not work. In the case, of NT domain you have the option to allow/disallow user authentication when you create the user in NT domain database. In the case of the NDS, there is no such option to the best of my knowledge. Sorry !
Regards,
Mynul
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: