Definition of access a single device, from the Group of GANYMEDE

Hello

Here's my situation: I have a Lantronix device and two groups of users who need access using Ganymede (ACS 5.6).  I don't want to put all the users in a group because many of the users would then receive access to other restricted devices.

Basically, I need to combine peripheral access 1 - 10 but Group B only able to access devices 1.

I've been reviewing the authorization policies, but I'm not clear exactly where to go.  Any help would be grateful.

Thank you.

Daniel

daniel.m.williams1,

I don't know how the ACS 5.6 Menus have changed compared to 5.4 ACS (us still have but began to abandon to ISE 2.0 for GANYMEDE). But I'll throw my idea anyway and hopefully give you some progress. I'm not familiar with the Lantronix devices but they are configurable with GANYMEDE?

Here's how I'm going to try to solve this problem in ACS 5.4. Make sure that you also have approriate profile of Shell and the sets of commands in the authorization below rules.

1. users and identity stores > identity groups > create Group A and B > save.

2. users and identity stores > internal identity stores > users > create users > when creating users, assign them to their respective membership in step 1 group (Group A and B) > save.

3. users and identity stores > identity store sequences > create identity store = Local for example > in additional recovery search attribute list, select users > save.

4 policy elements > Session Conditions > network Conditions > device filters > filter device create Group A = > tab select an IP address then check mark peripheral IP > add the ip address of the devices > filter device create Group B = > tab select an IP address then check device IP > add the ip address of the devices > Submit.

5. political access > Access Services > create Access Service > identity = Local to step 3 > authorization > customize > add filter device and group identity > click OK > create an authorization rule 1 > select device filter = Group A > select a group identity identity of Group A in step 1 > click OK > create an authorization rule 2 > select device filter = Group B > select a group identity identity of Group B in step 1 > click OK

HTH

Please note and mark the correct comment if you find it useful. Thank you *.

Tags: Cisco Security

Similar Questions

  • Removable storage to access folder is missing from the group policy under Administrative Templates\Systems

    Hello

    I intend to control the reading and writing of removable storage devices using Windows Server 2008 GPO.

    However, after reading the online group policy settings, when I tried to apply the GPO settings, I found that 'Access to removable storage' folder is missing from the group policy under administrative Templates\Systems.

    Please suggest others.

    Thank you

    Amit Jogi

    Hi Amit,

    Thanks for posting your query in Microsoft Community. However, your question is beyond the scope of what is generally answered in this forum of consumer and would be better suited for the IT Pro TechNet public.

    Please post your question in the TechNet Forums.

    Thank you.

  • How to Access Manager for devices in the Windows 7 Ultimate Computer of the Microsoft Management Console (mmc) or Windows XP Professional computer using the computer (compmgmt.msc) management?

    I want to access Device Manager on a Windows 7 Ultimate remote computer from a computer running Windows XP Professional.  Whenever I have use (compmgmt.msc) computer management and access the remote computer, I connect successfully to it.  But when I select the Device Manager it says: 'access denied '.  I checked the security policy (secpol.msc) and I chose the deny access to this computer from the network and there no users and groups listed but it says that its default value is invited.  Can you tell me the step by step procedure?

    Thank you.

    In addition to changes to the GP, you must also do the following.

    Open services.msc, locate the "Remote registry" service, start the service and set to start automatically.

  • With a binding high-speed small (1.3 MB) and living in a multi storage House, is it a lot to win add a device from the airport to the BT router?

    We have a high link flow modest (1 to 3 Mbit/s) and a several-storey house.

    My iMac will work faster Safari if I add a device from the airport to the BT router?

    My iMac will work faster Safari if I add a device from the airport to the BT router?

    No, because the speed of your Internet connection is controlled by your provider, BT, if you need a faster Internet connection, you will need to talk to BT one faster... and more expensive... plan connection.

  • Cannot access folders after recovering from the virus.

    My system was infected by the virus from Windows recovery. It seems to me have removed, but now I can't access certain folders, such as Documents and settings, Cookies, ect. Change permissions don't seem to work. I'm getting an access denied.

    Hello

    Make sure that you have tried the steps listed in the article provided in the method 1 to change permissions.

    Method 1:

    I suggest you try the steps from the link below and check if it helps.

    http://Windows.Microsoft.com/en-us/Windows7/how-do-I-open-a-file-if-I-get-an-access-denied-message

    Method 2:

    Alternatively, you can scan your computer for the Microsoft Security Scanner, which would help us to get rid of viruses, spyware and other malicious software.

    The Microsoft Security Scanner is a downloadable security tool for free which allows analysis at the application and helps remove viruses, spyware and other malware. It works with your current antivirus software.

    http://www.Microsoft.com/security/scanner/en-us/default.aspx

    Note: The Microsoft Safety Scanner ends 10 days after being downloaded. To restart a scan with the latest definitions of anti-malware, download and run the Microsoft Safety Scanner again.

    Hope this information is useful.

  • In Windows 7, after the application of SP1, I can no longer access my phone book from the start menu or use the search function.

    I just applied SP1.  Until I applied this update that everything worked as I expected.

    Since then, whenever I type anything in the search on the start menu, there is no result.  The only exception to this is that if I type in a full path, for example "C:\Program Files\", how I get a list of files in that directory.  If I type in everything that is not a path, as for example the letter p or the word 'paint', told me that "no element not corresponding to your research."

    If I click 'more results', I get an error with a big red x box.  The legend is "search query: = paint", for example if I searched for painting.  The text is "Windows cannot find ': search query = painting '.»  Make sure you typed the name correctly and then try again. "I wasn't expecting this error box, but rather a window with a list of search results.
    I have downloaded and run the troubleshooter of research - Mats_Run.search.exe.  It tells me that no errors have been detected and gave me the option to reset the search.  I did this, then waited a whole day to search for re - index, but the results are the same.
    In addition, after reading a few other questions on the microsoft Web site, I've done different things which seem to as they should not work - I have turned me folder, active random registry settings options, etc..  Indeed, none of these things had an impact or shows something unusual.
    Also, I can access is no longer my home directory from the start menu.  If I click on my user name that appears in the upper right corner of the menu start, the start menu closes and nothing happens.
    There are a few other circumstances where I can't reach my directory.  For example, if I have an Explorer pointed toward a library, say "Downloads", if I click on my user name in the breadcrumb path, he will remain in the directory downloads instead of going to my home folder, as I expect.  Also, if I click on my user name in the Favorites list in the left pane of the Explorer, I would expect the Explorer window to access my home folder.  Instead, he remains in the folder where he currently resides.
    As I said earlier, before applying the update it worked as expected.
    Thanks a lot for your time!

    Hello

    Turn off or uncheck search in Windows Control Panel and restart the computer.
    After the computer restarts, place a check for Windows Search and restart the computer. Then find the issue.
    Reference: http://windows.microsoft.com/en-US/windows7/Turn-Windows-features-on-or-off

    Also please take a look at the article that could help you.
    The box "search programs and files" does not correctly display the search results in Windows 7 and Windows 2008 R2
    http://support.Microsoft.com/kb/977380

  • Windows Live Movie Maker: What happened to the function "Capture Video Device" from the good old Windows Movie Maker?

    I am running Windows 7 (64 bit) and Windows Live Movie Maker 14.0.8091.0730. Good old Windows Movie Maker that came on Windows XP, I could add video capturing directly from the video device (my webcam). In this new version of Movie Maker extra in Windows 7, I can't.

    How can I add this feature in this new version? Why it was deleted?

    Hi romzap,

    The feature you found in Windows XP Movie maker to add video to your video device, such as webcam, who called such as Capture video device has been replaced by the name Windows Live Video acquire Wizard. For more information on how to import videos and work with Windows 7 Live Movie Maker things, please visit the link below.

    ·         http://windowslive.com/desktop/MovieMaker

    Hope this information helps you.

    Concerning

    Arona - Microsoft technical support engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

  • Pinout of the device from the PCI-6225 in differential Mode of I

    Simple question: where is the pinout of the device for the card PCI-6225 for differential of analog input mode? I looked in the device list of the pins in MAX, in the NI 622 x specifications document and several other places, but I was not able to find it. I found the pinout for referenced asymmetrical measures, but no differential.

    Related issue: most people use devices like the 6225 for no entries analog differential? So why in tarnation do many brand of material OR that upper and lower manuals, looking for the differential input version?

    Thank you!

    «Referring the number of pins would make it impossible to use the same code when you change maps DAQ.»

    I'm not sure I followed here. Can you please explain a little further? Are you referring to the 1-68 0 connector pins and 1-68 pin connector 1? If so, I'm not sure, I followed. A different pinout may not change the code. If I had to replace a 6225 with another equivalent at least DAQmx device as many channels and the device number was the same, then I'd not change all the names of channel in the code, I? It would certainly change the wiring, which is precisely what I'm doing right now.

    I know that the analog input channels look like ai0, ai1, etc.. My concern is later: where the jumps occur when you're in differential mode?

    I have attached exactly what I would like to see in the documentation of ALL analog input device which allows the differential mode, only with the + and - channel names only and not the labels AI0-AI79. I couldn't find this photo any place, but rather had to laboriously calculate this pinout. If you know where to find this photo, I would be very grateful.

    Thanks for the reply.

  • Computer hangs after having gained access to workstation, network from the beginning places and at other times.

    Hi, I use Windows XP Professional SP/3 on a 32-bit computer. We have three computers on a home network wireless, everything works well for several years. Now several weird things happened more or less at the same time. I can't identify anything what I did precisely that lead to these problems that are:

    a. when I try to open 'My computer', ' Start ' or after opening 'Explorer', all I see is a small icon yellow flashlight, but not records.

    b. when I go 'Start' to 'My Documents' or 'My images', 'My Network Places' and the respective window opens but then crashes if I try to select an option in the left column.

    c. when I open a Word, PowerPoint or other document and try to "save under", a small window pops up that says "initialization root to display folders» Finally after about 2 minutes, show records roots but once again the process crashes as I try to use it.

    d. my computer recognize my HP ScanJet 5590 or my Canon digital camera when I attach one of them through a USB port, but the scanner Wizard and camera does not open to receive the downloaded or scanned images... nothing happens.

    e. when I open a file in "My pictures", I get a picture icon, not the image and then have to go to 'open with' to see the photo in the image viewer. If I try the film option, I see "generating Preview ' but nothing happens.

    f. and finally, when I get to the "my network places" and then click on "computers from the network view", the window hangs. Other computers on the network will appear in "My Network Places" but now only show as an icon is empty, is not an active link.

    So, maybe all these oddities relate? I have reloaded the scanner software, checked the camera drivers and a scanner, all OK. I don't know where to go from here after reading several threads of discussion about some of these issues. Can someone help me? Thank you very much.

    John

    To answer #1, that looks like a setting in the "boot.ini".  The following articles answer this:

    "How to edit the Boot.ini file in Windows XP"
      <>http://support.Microsoft.com/kb/289022 >
    "Switches to boot mode safe mode to the Windows Boot.ini file"
      <>http://support.Microsoft.com/kb/Q239780/ >

    This could have also been established by setting a check mark in the tab "Boot.ini" in msconfig.  Try to clear all the check marks in this tab.

    Good job tracing it down to WIA.  He would explain or influence the camera, scanner and long delays to explore.  Check out some of the following items:

    "Long delay before appear it files in my computer in Windows XP"
      <>http://support.Microsoft.com/kb/819017 >
    "Windows XP does not recognize a Canon PowerShot S100 Digital camera"
      <>http://support.Microsoft.com/kb/810609 >
    "Windows XP takes a long time to start"
      <>http://support.Microsoft.com/kb/823612 >

    I believe that the general consensus is to remove all the seller WIA drivers, reboot, then reinstall them using the manufacturer.  It could be that you ended up with an incompatible mix of drivers, perhaps due to an update.

    HTH,
    JW

  • Device from the Application context context

    I am a beginner to programming of Blackberry and I'm trying to understand the different between developing countries in the device against the Application context.

    My development so far has just been messing around with the listeners and figureing on their functioning on the eclipse Simulator

    My current test project consists of a phonelistener that simply writes to console when a phonelistener event is fired. I think that my project as a module system, where this is not really an app its just something that I want, running in the background. But perhapse I think about evil.

    I have my project to "autorun". Now, what are the benefits to my project to extend the Application?

    at the moment I just:

     CustomPhoneListener extends AbstractPhoneListener
    

    It works fine and I can see the console outputs when I simulate phone calls. I know that my sample program is very simple, but can someone shed some light on what problems might come with not extending "application"?

    Thank you

    Stephanie

    Device vs. request context has no meaning for me.

    Each Application has its own context, says Simon if you use a listener usually perform you in the streamed Application context too.

    Re the difference between

    CustomPhoneListeners extends the Application Implements PhoneListener
    and

    CustomPhoneListeners implements PhoneListener
    I would ask you to think about this:

    CustomPhoneListeners extends String Implements PhoneListener

    What is the advantage of the extension of string?  Not really, except in certain circumstances, you need to treat your CustomPhoneListeners as a string!  Same thing with Application, if you want to treat like your own Application, then you might want to code

    CustomPhoneListeners extends the Application Implements PhoneListener
    Personally, I think that you don't want to have an Application also act as a PhoneListener, this does not seem a useful merger.

    About the benefits of creating an Application, it has no value extending the Application If you can work in the listener.  But you can do a treatment long, or perhaps a network call.  Or maybe you are not sure of the reliability of your code.  If you run this in the context of the phone, then if he dies or hangs, it is the phone that is killed.  Not good.  Then you can consider extending the Application, it is started (enterEvent Dispatcher), and then you can pass things for her to run.

    Personally, I do as little as possible in the headphones.

  • Import my own device from the host data store

    This is my first post so Hello all who read this.

    I am currently runing ESX 3.5i directly on the hardware of a test done home server (tests, the fonstionality before rolling it into production) here is my problem

    I could create and install an a virtual machine (windows 2K 3 R2 server) and once all the basic configuration were made I exported the virtual machine as a unit. now, the comand export will only export file on the computer of gest. I was able to download the 2 files (hard and .ovf) on the host's data center. Now, I would like to deploy a new instance of the VM on the server. But when I drop & gt; virtual appliance & gt; I have only the option import from the hard drive of gest. I want to do it directly from the data store, so I did not download the file whenever I ride on a new virtual machine.

    Just a note I will administer the trought host VPN exclusively in production so it'll take fo never download the entire server every time.

    I hope that I was clear enough, if not feel free to ask questions.

    Thank you!

    Edit: spelling mistake little

    Hello

    So if I get this right I would create a virtual (windows XP for example) machine i would be VPN on this machine open a remote destop window there and then open the VMware console in this environment and then use it to make my new server deployment. Did I get it all?

    That is right. The reason is mainly the latency. You will not have much and if the VPN interrupts the action you take also WITHOUT giving up and continue until you reconnect.

    Can you tell me if there is a more easier way to do it?

    It's the simplest way.

    Best regards

    Edward L. Haletky

    VMware communities user moderator

    ====

    Author of the book "VMWare ESX Server in the enterprise: planning and securing virtualization servers, Copyright 2008 Pearson Education.»

    Blue gears and SearchVMware Pro Articles: http://www.astroarch.com/wiki/index.php/Blog_Roll

    Security Virtualization top of page links: http://www.astroarch.com/wiki/index.php/Top_Virtualization_Security_Links

  • After you have selected a contact group for sending electronic mail to:, how to remove 1 or more addresses from the group list once it is added to the new email? THX

    The best flexibility might always have the ability to add individual addresses from a group list to any email, so the list can then be cut. Or only the address list in the list group selected as a list of checkboxes (all checked by default) if the user can deselect those who should not be included in the list of email recipients. THX

    _ http://KB.mozillazine.org/Thunderbird: _FAQs_:_Create_Mailing_List #Avoid_sending_to_an_address_in_a_mailing_list

  • Bug in the transition from the groups of tabs when the mouse is over a tab

    I use two groups of tabs, each around 3-10 tabs open. I press Ctrl +' to switch between groups of two tabs. Everything works fine except when I have the chance to have the mouse cursor positioned on a tab when I press Ctrl +'. In this case, Firefox seems to get confused and I get an unpredictable mixture of the two groups of tabs tabs. I have to then move mouse tab and then press Ctrl +' twice to the tab group good I tried to move on. It's boring.

    I think it started in FF29, but I'm not sure.

    First of all, I would like to confirm that it is a bug. Secondly, I would like to see it attaches. I tried to find info on this several times without success. Anyone know anything about this?

    Thank you.

    OK nevermind, I did some more research and found a bug in Bugzilla for it. The bug has been fixed and I've confirmed with a night generation. Looking forward from the set in a regular release.

  • Delete the single pool of the Group

    Hello

    Is it possible to remove a member from a group that is the sole member of a swimming pool without losing data in this pool?
    I want to add that members of a new group and keep the pool.

    Kind regards

    Arnaud

    No, remove a member needs to evacuate all the data to the rest of the members first. If there is no member or free space left you can not remove the Member.

    Also delete removes the configuration of a member.

    Kind regards

    Joerg

  • Cannot able to remove a member from the Group:

    Hello

    I've had a named group compensation with currently 3 members say X, Y, Z. I'm removing 2 of them by the user to find x, then goes to his groups, selected one of its Compensation group, then

    by clicking on the button Delete.

    I see an error message to say: E-mail alias contains an invalid address.

    All of our users are synchronized with LDAP.

    Help, please. I searched all forums on this error. But I found nothing.

    Please see the screenshot below:

    screenshot.jpg

    Thank you

    Krishna

    I found the answer.

    It's the slightest mistake on because I'm trying to edit a group that was created in LDAP. The networking team removed the members of the group & now it works fine.

    ---

    Krishna

Maybe you are looking for

  • How can I set up Gmail access with parental controls?

    I want my son to be able to access his account Gmail school and Google allow to complete the tasks for the school, but I can't seem to make it work with Parental controls.  Help, please!  (Preferably using Firefox.)

  • When I make a change in about: config it does not record

    I'm changing the keyword search, but when I change about: config and then restart it does not save my change

  • determine the usb port

    Hello I have a problem with this configuration: How can I determine what 6210 peripheral USB is USB 1 with the USB converter to RS485? I communicate with the converter via CreateFile(). Thank you!!

  • Xbox 360 and Windows XP Media Center Edition 2005

    Hello Hoping to get help with this, because I searched everywhere and had not found an answer.  All the work around the items, reference Windows 7 and 8 not XP my Dell Dimension C521 shipped with Windows XP Media Center Edition 2005 pre installed.  I

  • M775 MFP LaserJet 700: error Fuser LaserJet 700

    My fuser unit started failing last week.  I recycled power several times, but error persists. I purhased and installed a new fuser kit. However, I always get the same fuser error. My guess is that the power supply of the fuser unit is toast. Anyone k