Problem of access 5.2 ACS policies

Looking for help as I am new on this version of the ACS.

Here's the scenario:

We have two groups of devices

  1. ASAs for VPN access
  2. Wireless controllers

There are 2 AAA devices in each group.

We have 4 identity stores

  1. The internal user ACS Bank - this is used for external suppliers making SSL VPN on ASAs
  2. External Radius Server - this is an authentication server two factor in turn look up our ad and its own internal database that are symbolic. This is used to access IPSEC VPN for internal employees.
  3. We have mapped the ad groups - this is used to allow access for wireless users.
  4. Group LDAP mapped from another AD domain - used to allow wireless access to an associated organization.

Our requirements

  1. We need to create a rule for the VPN to access the first of all by the store's internal ACS - if a user is not found, then it checks the external Radius server. If no user is found where access is denied.
  2. We need create a rule similar to wireless users so that it verifies AD - if a user is not there then it checks LDAP. If no user is found access is denied.

Any help you could give me it would be much appreciated. If more information is required then please let me know.

Kind regards

TC

Hi Thomas,

for point 1. set up a 'store of the identity sequence' which consists of:

ACS - db internal

-External radius server

Let's call it "VPNSequence".

For point 2, set up a sequence of identity store of:

-AD

-LDAP

Let's call it "Sequence wireless."

Then configure the section of your service 'access to the network by default' identity.

Put a condition that will percolate vpn access (for example "If peripheral network belongs to the peripheral group network called"VPN concentrators".") You will of course be ASAs all there). Storage of identity used will be the sequence you created above ("VPNSequence").

Create a second rule (point 2) which will correspond to wireless access (if the network device belongs to the WLC group for example) and which uses the "WirelessSequence" sequence as identity store.

It must authenticate all accordingly. However that "allow access" will be returned. If you want to return different attributes, in the permission tab, and it's something else :-)

Tags: Cisco Security

Similar Questions

  • Problem with access policies (create several resources)

    I'm having a problem with access policies:

    The first policy must create a resource.
    And the following policies should create childs on the resource.

    The problem here is that when the policies will add the childs, the resource is not configured yet.
    And then each will create a resource but I want just a single resource of the childs.


    When the resource is already deployed, policies to update this resource correctly.

    How can I fix?

    TKS

    Ricardo,

    I had a similar problem. In a post processing Manager, I managed the membership of the user to specific through the removeMemberUser roles and the addMemberUser of the tcGroupOperationsIntf class.
    The last parameter of this method is a Boolean value that, if true, would automatically trigger access by programming strategies in post processing.
    The problem is that there also is an OOTB handler for triggering access rules, so I was basically triggering twice access policies and duplicate resources appear.

    I hope this helps.

    See you soon

  • I downloaded Safari 10 and now every page that uses Java asks me to activate or not. How to avoid this new feature? I have problems to access my bank account.

    I downloaded Safari 10 and now every page that uses Java asks me to activate or not. How to avoid this new feature? I have problems to access my bank account.

    I think they mean JavaScript.

    In your Safari menu bar, click Safari > Preferences and then select the Security tab, and then select: Enable JavaScript

  • I had problems with access to most of the Web sites and I noticed that HTTPS is no longer, how do I make permanent HTTPS so I can access any Web site?

    I had problems with access to most of the Web sites and noticed that HTTPS no longer appears whenever I try to access a Web site. I can easily connect to my gmail and facebook account, but the problem is that when I click on a link on FB and gmail, I get the annoying message "refused to connect.

    How to address this issue, rather how to make HTTPS permanent so I can easily access any Web site. The date and time on my laptop are both correct. I am currently using OS x 10.9.5.Please!

    How to address this issue, rather how to make HTTPS permanent so I can easily access any Web site.

    My guess is that you have a damaged or invalid certificate entry OS X KeyChain, but to directly answer this question, I would say that consider you something like HTTPS Everywhere. Note, it is not available for Safari. It is available directly through the Google Chrome browser extensions.

  • Problem with access point or wireless adapter

    Hello world

    tried to connect to my WiFi, but the convenience store detects that the problem with access point or wireless adapter.
    The drivers are up-to-date and functioning normally. There were discussions on BIOS but I don't know if I would be able to complete the task without bricking your laptop.

    Is there any online support?

    Hi smert

    Your message is not really useful.
    Why? Because no one knows all the details of the laptop, wireless network card system...
    So please would you be kind enough to provide more details.

    But despite the missing information, I recommend:
    (1) reset your router WLan
    (2) check the connection to the WiFi unsecured. (of course for testing purposes)
    (3) check the different (WPA/WPA2 AES, TKIP) encryption

  • Increasing problems to access web pages in Safari or Chrome

    Hello. I have a Mac Mini 2.5 GHz, 4 GB RAM, 500 GB HD; running Mac OS x 10.11.2; Safari 9.0.2; Sophos AntiVirus Home Edition 9.4.1; Chrome 49.0.2593.0 dev (64-bit).

    Several months ago, I started to have problems of access to some web sites, namely OpinionWorld and your voice. I would get an email from them with a link, like http://dkr1.ssisurveys.com/projects/start?psid=s_LXqAJmxx3JVOk_yTSTvgBEHjCAUQLr>, and when I went to access I got error:

    400 bad request

    Your browser has sent an invalid request.

    so that I could access these sites from my mother did investigations using his computer and Windows 10 machine. I had the same problems in Safari or if I pasted the links in Chrome. After some time I also started having problems with other websites such as Amnesty International. I would like to click on a link such as al http://www.amnesty.org.au/action/action/41035/?utm_source=FBPAGE&utm_medium=soci & utm_content = 20151220043000 & utm_campai... > and he'd make the same error 400 Bad request. I took it to the Genius Bar for an appointment and after a long period it check and tries to connect to some of these sites from another Mac and my mom on my Mac Mini account, that the Apple employee said it was a problem with sites and not with my computer, but problems encounter on the other computer and even on my mother's account were different. On the other machine, it seemed that someone else had bought the areas OpinionWorld and your voice and I forgot what happened account of my mom, but it wasn't a 400 error. Also, it didn't explain why I was able to access it on a Windows 10 using Chrome for Windows machine. Also, it was just the links OpinionWorld and your voice, not links to Amnesty International etc.

    Sometimes, I would have similar problems with other sites. Sometimes I could open in Chrome but not Safari, or if I clicked on the link it won't work but if I pasted the link and press return it would work. More recently, I was not able to access the site with Safari iTunes feedback feedback/itunesapp.html >, he just said:

    Bad request

    Your browser has requested that this server could not understand.

    Reference #7.ebb7d117.1450593610.0

    I receive for several sites these last time. Also although when I accessed this site through Chrome, it worked, when I had finished my comments he tried to go to http://www.apple.com/feedback/itunesapp_thankyou.html> where he got another 400 error but when I went there now it worked.

    Also when I tried to access the first link in this post just recently I received:

    403 Forbidden

    Request prohibited by law.

    in Safari. Previously I would have uninstalled and re-installed Safari and Chrome, but apparently it is like an option with Safari.

    Can anyone suggest what should I do then? Thank you for your consideration.

    Can anyone suggest what should I do then?

    He doesn't know what is the problem but "Sophos" is capable of anything beneficial and his presence will only complicate troubleshooting. Remove it. Back up your Mac before making changes to its file system.

    Use the Remove Sophos Anti-virus program. It will be installed in the Applications folder on your Mac, unless you have moved or deleted. In this case, follow the instructions in uninstalling here: https://www.sophos.com/support/knowledgebase/122710.aspx. Ensure that its eradication is complete and irrevocable from your system. Do not reinstall, or something like that. Only then will you be able to solve the problems you are having.

  • I have a problem of access to the Outlook account and other pages because appears "certificate error" what's happened with these certificates?

    I have a problem of access to the Outlook account and other pages because appears "certificate error" what's happened with these certificates? Help please.

    There are two main reasons for the mistakes of certificate:

    1. Your computer's time is not set correctly.  Check your time year/month/day/hour/minute/timezone/light of day.  Right-click on the clock in your taskbar and select "set Date/time" and make sure you are ready approximately 5 minutes of real time (don't forget time zone and DST).
    2. The second reason is that Windows XP is not very good for updating root certificates.  Go to the following site:
         <>http://support.Microsoft.com/kb/931125 >
      and go down to the section:
      'Update Package root (designed for Windows XP only)'
      There is a link, you can use to download a update for your root certificates package.  Download this package and double-click it to update.

    HTH,

    JW

  • Since an update to Adobe Flash Player (10.3?), I had many problems to access web sites and play 'videos' on them.

    Since an update to Adobe Flash Player (10.3?), who apparently is not 64-bit capable, I had many problems to access the websites and "videos" by playing on their. There is also a special site that charge but the screen displays a full blank page. What can or should I do? The adobe site indicates that the new application does not support 64-bit, but it doesn't seem to be a solution for it or the option of returning to the previous flash drive that was no problem.

    Hello

    Read this interesting information and use the 32-bit IE browser:

    'http://kb2.adobe.com/cps/191/tn_19166.html '.

    Troubleshoot installation of Flash Player for Windows

    http://kb2.Adobe.com/CPS/141/tn_14157.html

    Uninstall Flash by using the uninstall program Flash Adobe link above.

    Flash is sometimes corrupted.

    http://get.Adobe.com/flashplayer/?promoid=BUIGP

    Reinstall Flash, after 1st unchecking / unchecking the Google Toolbar download option there.

    http://pietschsoft.com/post/2006/12/Vista-experience-update-Windows-Vista-x64-runs-32-bit-Internet-Explorer-by-default.aspx

    The Internet Explorer shortcut in the Quick Launch toolbar, and in the x 64 Vista Start menu will run the 32-bit version of Internet Explorer by default. Why run the 32-bit version if IE on the 64-bit version of Vista?

    There are actually two shortcuts for Internet Explorer in the "Programs" menu Why two and what is the difference?

    This is the title of each and they run exe:

    Internet Explorer
    "C:\Program Files (x 86) \Internet.

    Internet Explorer (64-bit)
    "C:\Program may Explorer\iexplore.exe.

    One runs IE in the "Program Files (x 86)" folder, this is the 32-bit version. The second is the 64-bit version.

    http://kb2.Adobe.com/CPS/000/6b3af6c9.html

    Trial of Adobe flash 64-bit

    http://www.ehow.com/how_4670030_adobe-Flash-bit-browsers.html

    Read the above article on the 64-bit browsers

    http://social.answers.Microsoft.com/forums/en-us/InternetExplorer/thread/babaa5f8-FF06-4EA2-aef6-a9416d65f981

    Read the above information about Flash and 64-bit browser by PA bear MVP"

  • Problems with access to the web pages, email, video, etc. even when I have 4-5 bars.

    I installed a Dell Wireless 1505 low-profile carrier 1.2 antenna dim/insp in desktop. Its a PCIe wireless lan card. But since last Tuesday patches have been installed I had problems with access to the web pages, email, video, etc., even when I have 4-5 bars.  Someone at - it an idea of what's going on.

    Hi William e. Swann

    1. what web browser do you use?

    Method 1:

    You can read the following article and check.

    You may experience connectivity problems or performance issues when you connect a portable computer that is running Windows Vista or Windows 7 to a wireless access point

    Method 2:

    You can also read the following article.

    How to troubleshoot network connectivity problems in Internet Explorer

    Hope this information is useful.

  • Problems with access to Web sites in the laptop of my mother, both wireless and ethernet connections

    Original title: Internet issues

    My mother's laptop has suddenly stopped to access Web sites. I tried to explore, Firefox and Chrome using both wireless and ethernet... connections we both century link and I tried the two houses... my works laptop on both networks. All three browsers connect to the internet, but not all pages opens. I ran the store and he told me that I should look online for more help... which is not the case, but it cannot determine the problem. Any ideas?

    Hello

    Welcome to the Microsoft community.

    I understand that you have a problem with access to Web sites. We apologize for the inconvenience caused to you and appreciates your efforts to try to resolve the problem.

    I would like to know the details below to help you better

    1. Do you receive an error message/code when you access Web sites?
    2. Do you think that any symbol with exclamation on the icon of this internet access on the taskbar (right)?

    I ask you to try the steps in the Microsoft Help article below and check if it helps.

    Why can't I connect to the Internet?

    http://Windows.Microsoft.com/en-us/Windows/cant-connect-Internet#1TC=Windows-7

    Also I ask you to reset TCP/IP and check if it helps.

    How to reset TCP/IP using the NetShell utility
    http://support.Microsoft.com/kb/299357/en-us

    Keep us updated on the issue to help you better.

  • How do .1x port based authentication access network through ACS

    How .1x port based authentication access network through ACS.

    Hello

    802. 1 x can authenticate the host or by the name of username/password, or either through the MAC address of the clients (PC, printers etc.). This process is called agentless network access that can be done via Mac Auth Bypass.

    In this process, the switchport 802.1 x would send the address MAC PC's connected to the server radius for authentication. If the radius server has the MAC address in its database, authentication will be successful and the PC would be granted network access.

    To check the configuration on GBA 4.x, you can go to http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_ser...

    To check the configuration on a CBS 5.x, you can go to http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_contro...

    Kind regards

    Kush

  • critical problem of access to a file

    I get an error message saying "we encountered the following problems: there seems to be a problem of access to a critical file for download.» For troubleshooting tips, please visit our customer support page. (Error code: 204).

    I tried the cleaning of adobe tool, but I always get an error when I run the file CreaticeCloudSet-up...

    Tried to delete the temporary adobe in the folder C:\Users\Lars\AppData\Local\Temp...

    Other applications like visual studio, etc. of unity downloaded and installed successfully just before I tried to install the creative application of cloud to adobe.

    OS = new install of Windows 10 12.08.2016 pro, updated today

    uninstall all cc including the application of cc office.

    clean your computer of files cc by http://www.adobe.com/support/contact/cscleanertool.html

    Restart your computer (do not skip this)

    Reinstall the cc desktop application, https://creative.adobe.com/products/creative-cloud

    Use the desktop application to install your programs and the cc events

    If this fails, search your computer oobe folder and rename it to oobe_old and look for the aamupdater folders and rename to aamupdater_old.  Repeat first paragraph.

  • just joined the cloud having problems to access the pro Prime Minister... help me please

    just joined the cloud having problems to access the pro Prime Minister... help me please

    Hi again Jeff... Thank you for the time you took on this

    question... my daughter figured it out and all is well

    Duarte

  • Problem of access to an object in a VBox

    Hello!

    I have a problem with access to an object that is in a VBox.
    I made an example so you can see my problem. I'm trying to access pnlChat.
    If you load the swf file you will not see the alert because there is something wrong (and I don't know what)
    If you try to delete the < mx:VBox > tags that surround the pnlChat Panel, it will not work.

    Why can't I access the object when it's in a VBox?

    Thank you

    'Jimmy Jeeves' wrote in message
    News:g8jv84$5ib$1@forums. Macromedia.com...
    > Hi!
    >
    > I have a problem with access to an object that is in a VBox.
    > I made an example so you can see my problem. I am trying to access
    > pnlChat.
    > If you load the swf file you will not see the alert because there is something
    > evil
    > (and I don't know what)
    > If you try to remove the tags that surround the pnlChat Panel, it
    > will be
    > work.
    >
    > Why can't access this object when it's in a VBox?

    In the FAQ I am compiling:

    Q: I need to set a property or add a listener for events on a component
    It's in a ViewStack/TabNavigator/accordion. When the component is not
    the first child of the browser container, I get null object error
    (#1009). What causes this and how can I solve this problem?
    R: by default, the Navigator container create only the children of
    each component this component is seen. The easy way to fix this is to set the
    creationPolicy for the browser to 'all '. However, this will cause your
    request to take more time to load. A better way to solve this problem is to wait
    a future event, like creationComplete on the component that you want to access,
    or use the link to 'pull' data in the component.
    The way I handle it is to call invalidateProperties() on the evolution of the
    ViewStack. I then override commitProperties() and claim an initializer of «»
    each pane. In the body of each initializer function, I check to see if the
    selectedItem to the viewStack is one that cares about my initalizer. If
    No, I just got back from the function immediately. This initializer inside
    function, I set properties and add listeners as appropriate.

  • Only read access to the ACS for a specific group

    All the

    I use an ACS with version (5.5.0.46.8). There is a group within the company requesting access RO to GBA.

    This group is already created in the user and groups of banks of identities/EXTERNAL/AD/directory

    In all of the elements/device/order Admin policy, I already have a set of SHOW command created

    I have looked in policies/Acess Network Services access authorization / Default / access but am a little lost after that.

    Please inform promptly.

    Looks like 'show' and 'sh' problem in the command set.

    If you pass for full access with it. It work?

    Remove 'sh' him then use some commands specific complete show.

    Let me know the results!

Maybe you are looking for

  • 10 IOS resets randomly

    I use an iPhone 6 + and I recently updated to iOS 10. Since the update, restart my iPhone randomly 'fast '. I use an app, the screen will turn black with a white spinning circle in the middle of the screen for about 3-4 seconds and then the phone wil

  • P10 - 792 already built-in WiFi antenna?

    I have Toshiba satellite P10 792 and I try to installIntel 2100 WiFi but I can't find the built-in antenna http://nl.computers.Toshiba-Europe.com/contents/Toshiba_nl/NL/others/Pricelist/Prijslijst_Nederland_3jan2005.PDFas they say here on page 15. Th

  • AAC to MP3 conversion... where the MP3 files will once you seem to complete the conversion

    Followed by conversation jury instructions received but never a popup to designate the location where to save the files.  Should what setting I set?

  • NIC on xbox 1

    OK so I bought my first day of 1The xbox as it left, it was great until about 2 months ago then he decided to stop well enough to connect to my internet, it would not disconnect but my download speed went from 25-30mbps less than 1, so I called my IS

  • Download Windows xp professional

    Is there a place where I can download windows xp professional? I already have the license key but you do not have the software.