Setting up authentication by using ad group mappings
Hello
I recently installed ACS 5.3 and I try to configure as follows:
(1) devices are separated in places and device types.
(2) ACS performs authentication by using AD.
(3) the user must be in the specific ad group in order to access a device specific type/location.
I'm testing my setup with WCS. The server has been added to the list of network devices and placed in the appropriate place/device type.
Under the rules of access, I have set up a named (NAAS-WCS) Access Service that has an identity and mapping group structure.defined as follows:
* Identity: Condition (NDG:Device Type-> in all Types of devices: WC), results (identity store: AD1).
* Mapping group: (Condition: AD1:ExternalGroups), results (identity group: all groups: SBD-SEC-ENG).
What I'm trying to implement is the following rule:
If (device in device type WC) and (the user in the Group G-CRP-SEC-ENG) then allow access otherwise block.
I added the groups in the AD of the server configuration and used this group in the definition of the rules. The error I get from Ganymede when I try to open a session is attached in jpeg format.
Anyone know where I am going wrong? It's the first time I used the new ACS system.
Thank you
Sami Abunasser
I had a similar problem, since any request came as CHAP/MD5, which is not the same as MS-CHAP v1 and v2 that we chose the GBA.
How do you try to authenticate users? Web page or dot1x? If it's a web page, choose PAP as authentication and you should be fine.
Tags: Cisco Security
Similar Questions
-
How to use the Group condition in the ODI mappings
Hi Experts,
I have a requirement in the customization of BI applications. Can you please someone explain how to use the LISTAGG function in odi mapping.
I applied the LISTAGGR function at the level of mapping odi, but I get error below.
Mapping of ODI: ColumnName: ENAME Expression: LISTAGG (EMP. ENAME, ",") THE GROUP (RANKING BY EMP. ENAME)
Error:
ODI-1240: Flow LIST_AGG_FUN_USAGE fails during an operation of integration. This flow of charge table target EMP_BI.
ODI-1228: task failed LIST_AGG_FUN_USAGE (integration) on the scott_db of ORACLE target connection.
Caused by: java.sql.SQLSyntaxErrorException: ORA-00937: not a function of simple-group
Oracle query:
If I used this sql query in the database the correct result is.
SELECT DEPTNO, LISTAGG (ENAME, ',') WITHIN THE EMP EMP (ENAME CONTROL) GROUP. DEPTNO;
Output:
10 CLARK, KING, MILLER 20 ADAMS, FORD, JONES, SCOTT, SMITH 30 ALLEN, JAMES, MARTIN, BLAKE, TURNER, WARD Please give your valid solutions, thanks in advance.
Kind regards
REDA
If you try in #ODI12C then in the set of properties, you can select the column which should be used to group by.
If it's 11g so its bit complicated. Simply replace the mapping with below codes.
LISTAGG (EMP. ENAME, ",") WITHIN GROUP (ORDER BY ENAME) / * sum() * /.
Magic!
Thank you
Chantal
-
XMLAgg using in group by in OWB 11 GR 2
Hello
I want to use the sql xml operators to build the XML from relational data.
I use 11 GR 2 (11.2.0.1)
I followed this: http://blogs.oracle.com/warehousebuilder/entry/leveraging_xdb, but mapping wearing it is not included in the downloadable zip file.
My problem is the following:
I don't know how to use the group by part of the XMLAgg function in expression of OWB operator.
I will explain:
You have Tables DEPARTMENT and PERSON (examples of oracle data).
The XML must be:
< = 'SALES' service name >
PU_CLERK Baida < employee > < / employee >
Colmenares PU_CLERK < employee > < / employee >
< / Department >
Owb, you can join two tables and even use XMLAgg for combined, the employee fields.
Something like:
XMLAgg)
XMLElement ("EMPLOYEE", employee.lastname)
)
And that put in an xmlnode becomes:
XMLElement ("Department",
XMLAgg)
XMLElement ("EMPLOYEE", employee.lastname)
)
)
However if I want to use the departname of the person, who is just a field in the Recordset adheres and putting that in an attribute of the node Department Oracle complains.
XMLElement ("Department",
XMLAttributes (department.name like "name"),
XMLAgg)
XMLElement ("EMPLOYEE", employee.lastname)
)
)
This is because Oracle aggregates all records used for sourcing the constructed XML, not just things of the person.
Normally, you must include a Select Group by some of the training to allow the use of the Department name in the attribute such as:
Select
XMLElement ("Department",
XMLAttributes (department.name like "name"),
XMLAgg)
XMLElement ("EMPLOYEE", employee.lastname)
)
) of the employee to join the Department on (department.xx = employee.xx)
Department.name group
That is the catch! By using the group by in an expression of the faulty operator in sql results since OWB generates incorrect sql when you use generate intermediary and apparently in the wrong place!
Rather than appear after the xxx FROM it appears between the hook closing of xmlelement and FROM.
(Of course that this is due to owb just paste the contents of entire expression operators between the parties)
Someone knows how to fix this?
I need some kind of workaround without resorting to the pl/sql, etc.
As I said the blog display is not clear enough for me so if someone can help, please do :-)
This problem should not be first on the surface because it seems commonplace, it's just that I'm perplexed and owb guide is incomplete at best on this point.
I'm sorry for the loss of formatting, but the editor post on this forum is really...
Published by: MichaelR64 on June 30, 2011 14:21Hi Michael
You must use the aggregator to make group as in the example below, you can set other expressions to project the XML, as I did below...
http://blogs.Oracle.com/warehousebuilder/resource/OWB/owb_xdb_example20110701.jpgIs that what you're after?
See you soon
David -
Using cfquery GROUP of output within the intrusion via CFMAIL
Having a problem with the display of the CFQUERY results grouped in an intrusion via CFMAIL. After studying this question on these forums and the internet, I found some useful information, but have been unable to find the answer to my question...
Here's what I'm trying to do. I want to send an intrusion via CFMAIL to a single user. So far so good. I do not use CFOUTPUT in the intrusion via CFMAIL and it displays correctly the variables CF.
The problem is this: I have a CFQUERY that uses the GROUP setting and I want to display these results in AN e-mail. The display works if outside intrusion via CFMAIL:
< cfoutput query = "GetHoliday" group = "year" >
< b > #year # < /b > < br >
< cfoutput > #DateFormat(holiday,"mm/dd/yyyy") #-< / cfoutput > < br > < br >
< / cfoutput >The output looks like this:
2010
05/02/2010 - 05/03/2010 - 23/05/2010
2009
07/06/2009 - 05/07/2009 - 23/08/2009
However, inside the intrusion via CFMAIL it does not work. First of all, I took the CFOUTPUTs and used CFLOOP, but then I can't use the GROUP attribute.
I tried the attribute of the GROUP on the intrusion via CFMAIL, but who sends an e-mail by group. I want only an email sent and the results grouped into this one email as described above.
Any ideas on what I am doing wrong?
Or is there a way to run the group outside the intrusion via CFMAIL, store in a variable and display it somehow? I guess not since the query is a type of complex data...
loamguy wrote:
Any ideas on what I am doing wrong?
Or is there a way to run the group outside the intrusion via CFMAIL, store in a variable and display it somehow? I guess not since the query is a type of complex data...
I don't think you're doing something wrong. As far as I KNOW, there is no method integrated to group the content of the mail exactly in this way that you have described.
Yes, you could use cfsavecontent to capture grouped. Then include it in your e-mail message.
#year #.
#DateFormat(holiday,"mm/dd/yyyy") # -.
[email protected]"from ="[email protected]"subject ="Holidays">"
#mailContent #.
-
Delivery set of users in a particular group in AD - custom or STANDARD?
I can supply a specific set of users in a particular group within an LDAP (for example AD) using IOM OOTB?
The customer wants a set in bulk users are created directly in a specific in the ad group so that users have access to this resource group. Hints/tips/ideas?
If customization is required, then can which API/method be used?
Thank you
-oidm.You can create a field defined by the user and the recon on the IOM user profile to fill in this field. Based on this attribute, you can create a rule group membership and access policy related to that group and the disposal of these ad groups.
-Kevin
-
How to use the Group feature in insert or update
Hai All
How to use the Group feature in insert or update statement
I'm generating attendance so I have a different set of timing example
0800,1200,1230, 1700 and I need to insert data into the table that contains the intimate value min and max value for
outtime and othere to inertval time in or out
Pls tell me with some examples
For example
For INSERT
Insert into T2 (barcode, empcode, respondent, attend_date)
values (R2.cardn, R2.enpno, min(R2.) PtIMe), R2.pdate);
Update
Update dail_att set outtime = MAX (r2.ptime) where empcode = r2.enpno and barcode = r2.cardn and
attend_date = r2.pdate;
Here, in the place where I used to have so pls tell how to use
Thanks and greetings
Srikkanth.MHi Srikkanth.M
to insert:
insert into test (dummy) values ((select max (dummy) to double));
Update:
Update test dummy value = (select max (dummy) to double where to test them. XXXXField = double. XXXXField);
-
The use of group with into clause
Oracle forms 6i
Hai
While using a group function if is it possible to use would be to would adopt the how many times a record created one employee and to fill the number not in a variable
I tried like this, an error has occurred
SELECT count (*), barcode, bardate in temp_attendance cnt
where AT_DATE = bardate of bardate group, barcode;
Some allow you to set a good example
Thanks and greetings
Srikkanth.MSELECT count (*), barcode, bardate in temp_attendance cnt
where AT_DATE = bardate of bardate group, barcode;You choose 3 columns, but have only a returnitem, then how would that work?
select count(*),barcode,bardate into var1, var2, var3 from temp_attendance where AT_DATE = bardate group by bardate,barcode;
But I guess you have more than one bardate for each barcode for a SELECT INTO will cause an exception-TOO_MANY_ROWS, so you could go with a slider-loop, as
FOR rec in (select count(*),barcode,bardate into var1, var2, var3 from temp_attendance where AT_DATE = bardate group by bardate,barcode) LOOP --do something with each record END LOOP;
-
Error when you use the Group feature
Oracle forms6i
Hai
While I compile my coding it will compile correctly, but when I tried to run I revealed an error in the function of group
my code is
If (NTC <>0) then
Select the BAR code, RESPONDENT, OUTTIME today_bar, today_in, today_out from dail_att where BARCODE =: bar code
and ATTEND_DATE =: bardate;
Update dail_att set outtime = max(:bartime) where barcode =: bar code
and ATTEND_DATE =: bardate;
on the other
If (cnt2 <>0) then
Select RESPONDENT, OUTTIME in yest_in, yest_out from dail_att where BARCODE =: bar code
and ATTEND_DATE =: bardate-1;
If (yest_in is not null and yest_out is null) then
Update dail_att set outtime = max(:bartime) where barcode =: bar code
and ATTEND_DATE =: bardate-1;
on the other
insert into dail_att(barcode,intime,attend_date)
values (: Barcode, min(:Bartime),: bardate);
end if;
on the other
If: bartime between 0100 and 0630
insert into dail_att(barcode,intime,attend_date)
values (: Barcode, min(:Bartime),: bardate-1);
Update dail_att set outtime = max(:bartime) where barcode =: bar code
and ATTEND_DATE =: bardate-1;
on the other
insert into dail_att(barcode,intime,attend_date)
values (: Barcode,: min (Bartime),: bardate);
end if;
end if;
end if;
while I'm trying this groupfunction it throws error while I use seen tell me how to use the Group feature and where
to use
Regadrs
Srikkanth.MSrikkanth,
For this you need to calculate the max outside of the update statement and then use this value in the update statement.
The bartime is a control in the block?
If Yes, then you need to find the max manually, and if it isn't, then you can write a sub query to find the maximum value.
Kind regards
Manu.
If my response or response from another person was helpful, please mark accordingly
-
If I go buy Apple Watch nike, that I can use other groups like leather band?
If I go buy Apple Watch nike, that I can use other groups like leather band?
At this point, all we know is here:
-
How can I turn OFF any possibility of use of private browsing OR - how to set a password to use the private browsing?
My children are free to use the internet - but I don't want them to be able to hide their internet activity to me.
Thank you.Try this new extension - turn off private browsing:
https://addons.Mozilla.org/en-us/Firefox/addon/disable-private-browsing/Ignore the review I did there on the 22nd, as both versions again, improving have been released during the 6 days and most of the articles I've written about have been fixed.
Richie just needs to get to the function disable compensation no browsing history, who works at.
-
using the group name and password group in client anyconnect
Hello. Is it possible to use the group name/password of the legacy in customer cisco anyconnect vpn client? I checked the AnyConnect Administrator's Guide ' VPN XML Reference"and found nothing on this subject.
It's true.
AnyConnect Secure Mobility Client (VPN Module) can be used to connect to both types of VPN remote access:
1. full SSL VPN tunnel
2 IKEv2 VPN IPsec.
The legacy VPN client is used only with the old IKEv1 IPsec VPN and you cannot use this type of VPN client AnyConnect.
-
How to set up a connection using a Toshiba Satellite C655D-S5508 mobile access point?
How to set up a connection using a Toshiba Satellite C655D-S5508 mobile access point? I am trying to connect a Samsung Galaxy stellar and receive an error page indicating that the DNS search failed. I do not know how to set up my computer, I have the wireless power and know how to connect to the hotspot from the phone. The phone is able to recognize the computer and its IP address, and the computer recognizes the phone and tries to connect but then displays the error message "DNS search failed.
Any help would be great!RaquelHi Raquel,.
Do you have any security program installed on the computer?
I suggest to go through the steps from the link provided and check if it helps.
Add a Bluetooth device or other wireless or network device: frequently asked questions
You can also consult the manual of the computer for the same and check.
If the problem persists, you can also contact manufacturing for known problems:
Support.Toshiba.com
http://www.CSD.Toshiba.com/cgi-bin/TAIS/support/JSP/home.jsp
Hope this helps and let us know if you need more assistance.
-
Im trying to set up a printer used... lexmark z611 but he changed amyuni document converter 300.but have always a mistake-41... what should I do?
Contact Lexmark support.
-
Block traffic using security groups.
I want to block all traffic between two virtual machines, for which I created the security in Service named composer SG-WEB group.
In the DFW, I have two simple rules:
One rule that block traffic between the SG-WEB security group and another which helps everything. But I can still ping WEB1, WEB2 and vice versa. Of the ESXi if I look in the log of the FW I see traffic is allowed for the L2.
If instead of security groups, I use subnets, everything works fine. I know I have used security groups to identify the DFW traffic, but here does not at all, is this a bug or I'm missing some configuration required to achieve this?
Thank you.
What is the status of the VMware Tools in these virtual machines?
-
Photoshop crashes for almost 15 seconds, when using layer > Group layers or Layers Palette > layers command group. NOT on creating new group and creation of layers and n-drag-drop group manually in the Palette layers. Got a file of user interface design with close to 800 layers and lots of groups. This doesn't happen in smaller files. Using OS X Mavericks, Photoshop, CC 2014.2.2, mi 2014 15-inch Macbook Pro Retina.
I understand that the solution would be just to cut the file into smaller files and design each display of the user interface in a separate but file which would be painful. And it doesn't seem to be a very difficult task to just the layers in group.
OK, the first thing to try: disable the generator in the preferences of hiking (under Plug-Ins, at the top).
On my system, generator never took and a week to read information on all layers and is particularly slow on text layers.
Maybe you are looking for
-
Off__ active Windows Firewall
Every time when I start or restart my PC the Windows Firewall GET is disabled.
-
(Redirected) Dell XPS 15 9550 - battery problems
Have been a customer for a long time of the Dell laptops. Bought various laptops such as Vostro 1720, XPS Duo 12 etc. I bought the XPS 15 9550 on 27 June 2016 after costing a fortune. Immediately noticed a problem with the battery life that is loadi
-
3 weeks hp-500 214 never no sound
PC brand new never had any sound Re loudspeaker activated, they work Re pluged to the orange plug through tests to see if I had a map its 'yes '. test is not pluged in What now?
-
Guys I have a small and stupid question. Is there a problem with TCP using pairs of VLAN. The IPS resets the connections? Problem is that I do for example a PAIR of vlan 50 do VLAN 51 when traffic is a native of vlan 50 he will inspect traffic and se
-
I used the script of HTML5 geolocation API: location in Google Maps ads(German)I use the built-in in folio Builder web form to add an html file that contains the script.the goal is to have google maps shown with the current position of the users.This