Chapter 6 Setting Up and Managing User Groups
Configuration-specific User Group Settings
6-34
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Before You Begin
•
Ensure that a AAA client has been configured to use as the
security control protocol.
•
On the (Cisco) page of Interface Configuration section, ensure
that the PIX Shell (pixShell) option is selected in the Group column.
•
Ensure that you have already configured one or more PIX command
authorization sets. For detailed steps, see
Command Authorization Sets
Configuration, page 5-16
.
To specify PIX command authorization set parameters for a user group,
Step 1
In the navigation bar, click Group Setup.
Result: The Group Setup Select page opens.
Step 2
From the Group list, select a group, and then click Edit Settings.
Result: The Group Settings page displays the name of the group at its top.
Step 3
From the Jump To list at the top of the page, choose .
Result: The system displays the Settings table section.
Step 4
Scroll down to the PIX Command Authorization Set feature area within the
Settings table.
Step 5
To prevent the application of any PIX command authorization set, select (or
accept the default of) the None option.
Step 6
To assign a particular PIX command authorization set to be effective on any
configured network device, follow these steps:
a.
Select the Assign a PIX Command Authorization Set for any network
device option.
b.
From the list directly below that option, select the PIX command
authorization set you want applied to this user group.
Step 7
To create associations that assign a particular PIX command authorization set to
be effective on a particular NDG, for each association, follow these steps:
a.
Select the Assign a PIX Command Authorization Set on a per Network
Device Group Basis option.
b.
Select a Device Group and an associated Command Set.