cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
332
Views
0
Helpful
1
Replies

LMS & ACS Permissions by VLAN

382pch101
Level 1
Level 1

Using ACS version 4.2 & LMS version 3.1

Multiple catalyst4506 network. One of the vlans in the environment is dedicated to a subsidiary company. The operators in this vlan want to be able to enable/disable and add descriptions to the ports in their vlan. They have one switch which I was able to lock down, however they also have a blade in one of the parent company's switches. Can I limit their access to that specific blade or to their vlan on the switch? Thanks for the help

1 Reply 1

Joe Clarke
Cisco Employee
Cisco Employee

The only restricting you can do is with ACS. With ACS, you can restrict certain LMS users to only being able to access certain devices. This is done by creating NDGs within ACS, then attaching the ACS users to those NDGs for LMS roles.

However, you cannot limit access to a specific VLAN or interface on a switch (without using something like VRFs on the device). LMS + ACS will only give you device-level access.