
7-13
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 7 Setting Up and Managing User Accounts
Basic User Setup Options
Typically, you define (shared) NARs from within the Shared Components section
so that these restrictions can be applied to more than one group or user. For more
information, see
Shared Network Access Restrictions Configuration, page 5-8
.
You must have selected the User-Level Shared Network Access Restriction check
box on the Advanced Options page of the Interface Configuration section for this
set of options to appear in the Cisco Secure ACS HTML interface.
However, Cisco Secure ACS also enables you to define and apply a NAR for a
single user from within the User Setup section. You must have enabled the
User-Level Network Access Restriction setting under the Advanced Options page
of the Interface Configuration section for single user IP-based filter options and
single user CLI/DNIS-based filter options to appear in the Cisco Secure ACS
HTML interface.
Note
When an authentication request is forwarded by proxy to a Cisco Secure ACS,
any NARs for requests are applied to the IP address of the forwarding
AAA server, not to the IP address of the originating AAA client.
To set NARs for a user, follow these steps:
Step 1
Perform Step 1 through Step 3 of
Adding a Basic User Account, page 7-5
.
Result: The User Setup Edit page opens. The username being added or edited is
at the top of the page.
Step 2
To apply a previously configured shared NAR to this user, follow these steps:
Note
To apply a shared NAR, you must have configured it under Network
Access Restrictions in the Shared Profile Components section. For more
information, see
Shared Network Access Restrictions Configuration,
page 5-8
.
a.
Select the Only Allow network access when check box.
b.
To specify whether one or all shared NARs must apply for the user to be
permitted access, select one of the following two options, as applicable:
•
All selected NARS result in permit
•
Any one selected NAR results in permit