10-5
User Guide for Cisco Secure Access Control System 5.4
OL-26225-01
Chapter10 Managing Access Poli cies
Configuring the Service Selection Policy
If you have implemented Security Group Access functionality, you can also customize results for
authorization policies.
Caution If you have already defined rules, be certain that a rule is not using any condition that you remove when
customizing conditions. Removing a condition column removes all configured conditions that exist fo r
that column.
To customize a policy:
Step1 Open the Policy page that you want to customize. For:
The service selection policy, choose Access Policies > Service Selection Policy.
An access service policy, choose Access Policies > Access Services > service > policy, where
service is the name of the access service, and policy is the name of the policy that you want to
customize.
Step2 In the Policy page, click Customize.
A list of conditions appears. This list includes identity attributes, system conditions, and custom
conditions.
Note Identity-related attributes are not available as conditions in a service selection policy.
Step3 Move conditions between the Available and Selected list boxes.
Step4 Click OK
The selected conditions now appear under the Conditions column.
Step5 Click Save Changes.
Configuring a Policy—Next Steps
Configuring the Service Selection Policy, page10-5
Configuring Access Service Policies, page10-22
Configuring the Service Selection Policy
The service selection policy determines which access service processes incoming requests. You can
configure a simple policy, which applies the same access service to all requests; or, you can configure a
rule-based service selection policy.
In the rule-based policy, each service selection rule contains one or more conditions and a result, which
is the access service to apply to an incoming request. You can create, duplicate, edit, and delete rules
within the service selection policy, and you can enable and disable them.
This section contains the following topics:
Configuring a Simple Service Selection Policy, page10-6
Creating, Duplicating, and Editing Service Selection Rules, page10-8