beautypg.com

Cisco 3.3 User Manual

Page 199

background image

6-9

User Guide for Cisco Secure ACS for Windows Server

78-16592-01

Chapter 6 User Group Management

Basic User Group Settings

Note

When an authentication request is forwarded by proxy to a Cisco Secure ACS
server, any NARs for TACACS+ requests are applied to the IP address of the
forwarding AAA server, not to the IP address of the originating AAA client.

To set NARs for a user group, follow these steps:

Step 1

In the navigation bar, click Group Setup.

The Group Setup Select page opens.

Step 2

From the Group list, select a group, and then click Edit Settings.

The Group Settings page displays the name of the group at its top.

Step 3

To apply a previously configured shared NAR to this group, follow these steps:

Note

To apply a shared NAR, you must have configured it under Network
Access Restrictions in the Shared Profile Components section. For more
information, see

Adding a Shared Network Access Restriction,

page 5-19

.

a.

Select the Only Allow network access when check box.

b.

To specify whether one or all shared NARs must apply for a member of the
group to be permitted access, select one of the following options:

All selected shared NARS result in permit

Any one selected shared NAR results in permit

c.

Select a shared NAR name in the Shared NAR list, and then click --> (right
arrow button) to move the name into the Selected Shared NARs list.

Tip

To view the server details of the shared NARs you have selected to apply,
you can click either View IP NAR or View CLID/DNIS NAR, as
applicable.