ACS 5.5: isolate a user to open a specific IP session (or MAC)

Hello

We use the ACS 5.5.

And what we would do to achieve is:

A specific user (internal identity store) than logons to a Cisco router (could be more then one).

Is only allowed to access this Cisco router when the user enters a IP address specific (or MAC address).

This filter should prevent this specific user to log on anywhere else.

If you login with this specific user account from an IP address defined in the filter then another must fail.

And would benefit from a logon with account specific user of the IP address in the defined filter.

Thank you very much.

Hi there,

You must create an END STATION FILTER and use it when creating the access policy. Which should limit the access of this station/terminal only.

Let me know if you have any other questions.

Kind regards

Kanwal

Note: Please check if they are useful.

Tags: Cisco Security

Similar Questions

  • Prevent users from opening a PDF form in preview Mac

    When I create an AcroForm, it does not have the same thing when someone doesn't fill it out in preview, and when I get the form back from them, some of the information in the fields of the form is missing.

    Is there a way to prevent Mac users from opening the form in the preview? Or give them a message that the form must be completed using Reader?

    You can't stop them to do (except while standing next to their computer with a big stick).

    You might consider having a large field on the warning page that the file should be used (or other), what is hidden using Acrobat JavaScript.

    Be aware that we are now dealing with a very large number of PDF readers.

    Included with computers: overview of Mac OS, Windows player.

    Included with the browsers: Chrome, Firefox.

    Included with portable devices.

    Anyone who gets a computer these days actually gets a PDF Viewer that's bad with shapes. You must give them a good reason to download additional software. (Or even, frankly, to renounce forms PDF. "I think that their day has passed to a general public who could fill out a form of browser).

  • Allow users to open a file on the network but not copy it for their machine. Possible?

    People! I have a scenario. Please let know us if its possible. I put a PDF on a folder and share it. I want to give users a direct link (network path) to this file so that users can open the pdf file. But I don't want them that copy on their local machine. Is this possible? If Yes please let me know for XP SP3 and Server 2003. Thank you!

    Hi rkka.

    Thanks for visiting the site of the community of Microsoft Windows XP. The question you have posted is related to the Server 2003 and would be better suited to the Technet community. Please visit the link below to find a community that will provide the support you want.

    http://social.technet.Microsoft.com/forums/en-us/categories/
    Shawn - Support Engineer - MCP, MCDST
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

  • Secondary ACS authenticates not to dynamic users

    Hi all

    I have two ACS server for windows with version 4.2. My problem is that, if the primary ACS server is down, dynamic users from the database windows in unable to authenticate with the ACS secondary. Please note that if a user is added to the ACS, this user can authenticate with the windows database. Only the dynamic mapping is not the case with the second ACS server.

    A quick response will be appreciated.

    What is in the database of Windows in both the points of the unknown user policy? Dynamic users are active under the unknown user policy?

    Are these servers ACS for Windows or the ACS SE with a Remote Agent installed on a member of the AD Server?

    If they are remote Agents, see the external database > Windows Configuration > selection of the Remote Agent. The same remote Agent is selected on both ACS servers?

    Please be aware that if you change the order of the RA he would remove all your group mappings.

  • Search ACS 4.2 order unknown user from database

    Hello

    I have several user databases in the search order for the unknown user policy. Ignoring the manual (http://www.cisco.com/en/US/partner/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UnknUsr.html#wp277530), which States that, after the failure of authentication from the first database (Windows) the ACS does not continue to look for the second database, a RADIUS server. I see that, with the failure in the first user, database stops the ACS research and fails to the user authentication with an authentication failure code "external DB password invalid.

    Documentation not going or is this a bug in the ACS v4.2.1? How can I make the ACS to continue to seek the second database user?

    Hello Roberto,.

    If the external database returns an invalid username/password, then it is intended for ACS is not to check the following data in the sequence and the failure of authentication:

    http://www.Cisco.com/en/us/partner/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UnknUsr.html#wp277502

    "For authentication requests, ACS applies the unknown unknown user policy to users. ACS does not backup to the known or discovered users authentication failure unknown when user authentication support. »

    If you want that ACS to verify the following database, even if a response from the invalid username/password has been received, you will need to explicitly set this on the external Windows database configuration page, in the section entitled 'Strategy for the unknown user' (but on the database configuration page specific Windows, not covered by the unknown user policy) :

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2.1/User_Guide/UsrDb.html#wp354338

    In addition, on the previous screenshots, I could see that you have configured both as a result of database:

    Windows database

    RADIUS Server token

    So we may be running into a situation where the authentication method used is not supported by the tokens, Radius servers, and therefore impossible to check the second database in the list:

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2.1/User_Guide/UsrDb.html#wpxref36799

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2.1/User_Guide/Overvw.html#wpxref846

    Kind regards

    Fede

    --

    If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

  • Cannot open the file PDF as computer Mac tells me to accept the end user license agreement and to relaunch the browser... How can I do this? URGENT!

    Cannot open the file PDF as computer Mac tells me to accept the end user license agreement and to relaunch the browser... How can I do this? URGENT!

    With closed drive, open your Applications folder and double click (left) on the drive icon.

  • User has opened all the 1000 + projects and cannot open a session now

    Does anyone know how to prevent the opening of the launch projects that were open the last time you were in the P6 app?  I have a user who has opened up to 1200 projects by mistake and now the system crashes before we can discover close all projects or change the preferences of the user.  I was hoping there was a switch that I could use to launch P6 in safe mode or maybe someone knows where the last session information is stored in the DB or where p6 is picking up projects open in the last session.  It is no doubt Central...

    Thanks in advance for any help you can provide.

    Wendy

    Yes, you must delete the user's preferences

    Run the following query as a privileged user (ex: privuser)

    Update userdata set user_data = null where Field_Name = "pm_settings" and user_id in (select user_id from user where user_name = "");

    where is the id of the user for project management

    If Oracle, run validation;

  • How to prevent a user from opening multiple instances on the same computer?

    On site oldnavyweekly.com , there is a .swf which prevents users to open multiple instances of the site at the same time on the same computer. If you open the site and try to open it again in another window, it will not load. Cannot open the site again until the first window is closed. How did they implement this?

    My analysis, that is NOT:
    1. cookies - the block always takes place if you try to open it in Internet Explorer and also try to open it in Firefox at the same time.
    2 flash Cookies - the block always takes place if I disable flash cookies.
    3 IP Based Block - you are not blocked if you open the site on two separate computers with the same outgoing IP address. From my analysis, their server does not help in the block at all.

    It seems as if their .swf creates a sort of object throughout the global system which can be detected in other instances of the application on the same computer. How did they implement this?

    Thank you!

    use localconnection.  everyone has a localconnection to send and a receiving localconnection.  the lc reception closes the current application.

  • How to manage what programs open when I turn on my Mac

    How to manage what programs open when I turn on my Mac

    System Preferences > users and groups > Login. Unlock the padlock (bottom left), select the item you want to remove, and then click the sign less.

  • Why Firefox always opens with the last session tabs?

    When I open firefox always opens with the last session tabs? How can I solve this problem?

    You can check if you have a user.js file in the Firefox profile folder that affects the pref browser.sessionstore.resume_session_once true value.

    The user.js file is present than if you or another software has created this file and normally it wouldn't be here.
    You can check its contents with a text editor (right click: 'Open with'; do not double-click).
    The user.js file is read whenever Firefox is started and initializes the preferences to the specified value in this file, so the preferences set via user.js can be changed temporarily for the current session.

    You can remove the user.js file if you do not create this file yourself.

    You can use this button to go to the Firefox profile folder currently in use:

    Windows hides certain default file extensions.
    Among them are .html, .ini and .js, .txt, so you can see only file name without the file extension.
    You can see the type of actual file (file extension) in the properties of the file via the context menu in Windows Explorer.

  • I lost all open tabs in Firefox 4 for MAC when my computer restarts or restarts Firefox

    I lost all open tabs in Firefox 4 for MAC when my computer restart or at any time to restart Firefox. Help, please

    You are welcome!

    Please mark this issue as resolved for the benefit of other users. Thank you.

  • Since the launch of Teststand I want to open a specific movie file

    Hello

    When I run Testand his way by default, it starts with the default behavior: opens "Movie file 1" (see attached .jpg)

    I want to change this behavior. I want to open a specific movie file.

    The pointers will be appreciated.

    Thank you.

    Hello chimbombo,.

    A simple way to do this is to create a single batch file that launches TestStand with 'sequencefile' argument, as described in this help document:

    TestStand Help: Configuration sequence editor and the Boot Options for the User Interface

    http://zone.NI.com/reference/en-XX/help/370052K-01/tsfundamentals/infotopics/startup_opt/

    That should cause the sequence editor open and load one or more files in sequence you specify.

    Hope that helps!

  • InDesign crashes when opening a specific .indd file

    Hello

    This morning, I added some finishing touches to a little book. Then I split the file into the cover and the inside of the book. Suddenly, InDesign crashed and maintains the plant after that I open the file with the content inside. Also, it crashes in InCopy. I tried several suggested solutions on the internet as the deletion of fonts the user, start in safe mode, but none of them worked.

    I pasted the file of report here:
    Process: Adobe InDesign CC 2014 [1451] path: / AP - Pastebin.com

    Thank you

    The script here can help: community Adobe: InDesign 6 crashes when you try to open a specific document. All others are open OK.

  • How can I open a portfolio Adobe on my Mac?

    I've created a portfolio file on my windows laptop, but I can't see / open on my Mac.  I'd appreciate any help.

    Caesar

    Hi codacrem1,

    Please check the recommended steps in the items listed below and you must have Adobe Reader installed on your machine.

    Why MAC users cannot open the Briefcase (merge and combine files) PDF

    https://forums.Adobe.com/thread/1246379

    Kind regards

    Ajlan Huda.

  • Open a specific browser, i.e. Firefox

    I don't know if it's possible, but I would like to be able to open a specific browser and then access a URL. What I mean is if the user has a Flash site open in Internet Explorer, I need for them to click on a button and this will open the link in Firefox. Is this possible?

    Background...

    Our company uses Internet Explorer 6 as your primary browser on all employees of the PC and for technical reasons, what IE cannot be updated. The problem is that the Web App site that I want to open must be opened in a modern browser, the application does not work on an old browser such as this. Firefox is installed on every PC, for this reason, but I cannot be sure that the user opened my site in Firefox so I need to check that they use Firefox, otherwise it must be opened first. Any ideas around this issue would be most appreciated.

    Thanks for your help. That's what I did incase ultimately this issue arises again.

    {if(Flash.System.Capabilities.playerType=="plugin")}

    trace ("using FireFox");

    }

    else {if(flash.system.Capabilities.playerType=="ActiveX")

    trace ("Internet Explorer");

    }

    else {}

    trace ("No. Browser");

Maybe you are looking for