12-17
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 12 Administering External User Databases
Database Group Mappings
Tip
To clear your domain selection, click Clear Selection.
c.
If the Windows domain for which you want to create a group set mapping
does not appear in the Detected domains list, type the name of a trusted
Windows NT/2000 domain in the Domain box.
d.
Click Submit.
Result: The new Windows NT/2000 domain appears in the list of domains in
the Domain Configurations page.
Step 5
If you are mapping a Windows NT/2000 group set, click the domain name for
which you want to configure a group set mapping.
Result: The Group Mappings for Domain: domainname table appears.
Step 6
If you are mapping a Novell NDS group set, click the name of the Novell NDS
tree for which you want to configure group set mappings.
Result: The Group Mappings for NDS Users table appears.
Step 7
Click Add Mapping.
Result: The Create new group mapping for database page opens. The group list
displays group names derived from the external user database.
Step 8
For each group to be added to the group set mapping, select the name of the
applicable external user database group in the group list, and then click Add to
selected.
Note
A user must match all the groups in the Selected list so that
Cisco Secure ACS can use this group set mapping to map the user to a
Cisco Secure ACS group; however, a user can also belong to other groups
(in addition to the groups listed) and still be mapped to a
Cisco Secure ACS group.
Tip
To remove a group from the mapping, select the name of the group in the Selected
list, and then click Remove from selected.
Result: The Selected list shows all the groups that a user must belong to in order
to be mapped to a Cisco Secure ACS group.