Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Same user in different ACS groups?

Hello

We have this scenario:

A user at home connects via SSL VPN is authenticated by Cisco ACS/RADIUS. User ends up in a specifig SSL VPN group on the ACS. This group is configured with specific properties for SSL VPN.

Now the same user comes to work with his/her private laptop and wants to access the guest wlan which our policy allows. We have a WLC4402 providing the guest wlan. User opens browser and logs in to the guest wlan, gets authenticated on the Cisco ACS/RADIUS and ends up in the same SSL VPN group.

My question is can we configure our ACS 4.1 in such way that it is context sensitive? Knows where the user is coming from and places the user in the right group accordingly?

We use LDAP group mappings and they are very static.

Any ideas?

Kind regards,

Rutger

2 REPLIES
Silver

Re: Same user in different ACS groups?

With ACS v4.1 and NAP, externally authenticated users get a user record for each NAP they authenticate against.

As each NAP may have its own external authenticator config, db mappings and authorisation - it should be totally possible.

The trick is setting up the NAPs to trigger on RADIUS requests of the appropriate type.

New Member

Re: Same user in different ACS groups?

Hi

I didn't know this was possible using NAPs. Triggering the NAPs could in our case be done by specifying the NAS IP users come from.

I will test with NAPs and come back to you.

Kind regards,

Rutger

132
Views
3
Helpful
2
Replies