1-19
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 1 Overview of Cisco Secure ACS
AAA Server Functions and Concepts
application and apply those sets to user groups that contain network
administrators or to individual users who are network administrators. For
information about configuring a command-authorization set, see
Command
Authorization Sets Configuration, page 5-16
. For information about applying a
shared device command-authorization set to a user group, see
Configuring
Device-Management Command Authorization for a User Group, page 6-35
. For
information about applying a shared device command-authorization set to a user,
see
Configuring Device Management Command Authorization for a User,
page 7-30
.
Other Authorization-Related Features
In addition to the authorization-related features discussed in this section, the
following features are provided by Cisco Secure ACS:
•
Group administration of users, with support for up to 500 groups (see
Chapter 6, “Setting Up and Managing User Groups”
).
•
Ability to map a user from an external user database to a specific
Cisco Secure ACS group (see
Database Group Mappings, page 12-11
).
•
Ability to disable an account after a number of failed attempts, specified by
the administrator (see
Setting Options for User Account Disablement,
page 7-20
).
•
Ability to disable an account on a specific date (see
Setting Options for User
Account Disablement, page 7-20
).
•
Ability to restrict time-of-day and day-of-week access (see
Setting Default
Time-of-Day Access for a User Group, page 6-5
).
•
Ability to restrict network access based on remote address caller line
identification (CLID) and dialed number identification service (DNIS) (see
Setting Network Access Restrictions for a User Group, page 6-7
).
•
IP Pools for IP address assignment of end-user client hosts (see
Setting IP
Address Assignment Method for a User Group, page 6-27
).
•
Per-user and per-group or RADIUS attributes (see
Advanced
Options, page 3-4
).
•
Support for Voice over IP (VoIP), including configurable logging of
accounting data (see
Enabling VoIP Support for a User Group, page 6-4
).