6-35
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 6 Setting Up and Managing User Groups
Configuration-specific User Group Settings
c.
Click Add Association.
Result: The associated NDG and PIX command authorization set appear in
the table.
Note
To remove or edit an existing PIX command authorization set
association, you can select the association from the list, and then click
Remove Association.
Configuring Device-Management Command Authorization for a
User Group
Use this procedure to specify the device-management command authorization set
parameters for a group. Device-management command authorization sets support
the authorization of tasks in Cisco device-management applications that are
configured to use Cisco Secure ACS for authorization. There are three options:
•
None—No authorization is performed for commands issued in the applicable
Cisco device-management application.
•
Assign a device-management application for any network device—For the
applicable device-management application, one command authorization set is
assigned, and it applies to management tasks on all network devices.
•
Assign a device-management application on a per Network Device Group
Basis—For the applicable device-management application, this option
enables you to apply command authorization sets to specific NDGs, so that it
affects all management tasks on the network devices belonging to the NDG.
Note
This feature requires that you have configured a command authorization set for
the applicable Cisco device-management application. For detailed steps, see
Command Authorization Sets Configuration, page 5-16
.