Re: Cisco ACS Help

What version of ACS are you running? You may want to see if you can set up 2 separate groups of network devices, and see if you can authenticate one network group against one domain, and the second group against the other domain

----------------------------------------------------------------------------------------- I don't think this can be done. You authenticate the users against a database Windows/Ciscosecure to give access to devices. The devices don't care where the user autheticates. You can create two groups of users (one for each domaiin) and configure the devices to authenticathe against those groups.

Rgds,

Robert B. Phillips, II wrote:

I am new to ACS so my apologies if this is a n00b question or in the > documentation, I have viewed the documented but I am not finding how > to accomplish what I am trying to accomplish. > > I have setup Cisco ACS to authenticate to the external Windows > database (Active Directory). I have two domains, Domain A and Domain > B. I have domain mappings setup to point ACS to each of the domains > and the NT group within each domain with the user accounts I want to > authenticate. I want to have some of our network devices to > authenticate ONLY against Domain A and some of our network devices to > authenticate ONLY against Domain B. I am not certain how to "segment" > the network devices in ACS so that they only authenticate against the > chosen domain. Right now all devices authenticate against either > domain mapping. What is the best way of going about implementing this > "segmentation"? > > We are on ACS version 4.0. The network devices right now are only > Lantronix SCS100 console servers attached to Cisco 1751-V routers. In > the future we will have other network devices authenticate here and > will have VPN connections terminated on our ASAs authenticate here as > well. > > Thanks. > Robert Phillips, CCNA

--------------= Posted using GrabIt =----------------

------= Binary Usenet downloading made easy =---------

-= Get GrabIt for free from

formatting link
=-

Reply to
webnetwiz
Loading thread data ...

separate groups of network devices, and see if you can authenticate one network group against one domain, and the second group against the other domain

Reply to
Robert B. Phillips, II

If the userids are different, than a group-mapping will be sufficient. If you have a single userid that exists in domain A and domain B, and want device A to only authenticate to Domain A, and Device B to authenticate only Domain B, then you need to setup two different ACS servers. One for device A, configured only to talk to domain a, one for device b to authenticate only to domain B.

Scott

Reply to
thrill5

What I was hoping was that there was a way to force certain devices to authenticate against ACS Group 0 and others against ACS Group 1. It's those ACS groups that link to the domain-mappings. There is no way to force a device to use one ACS group over another for authentication? Also, can this be accomplished via a NAR (i.e. by creating two groups of devices and filtering one group or the other via NAR)?

Yes userids are >If the userids are different, than a group-mapping will be sufficient. If

Reply to
Robert B. Phillips, II

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.