Chapter 10 Managing Access Policies

Configuring Access Service Policies

Configuring Device Administration Authorization Rule Properties

Use this page to create, duplicate, and edit the rules to determine authorizations and permissions in a device administration access service.

Select Access Policies > Access Services > service > Authorization, and click Create, Edit, or Duplicate.

The Device Administration Authorization Rule Properties page appears as described in Table 10-18.

Table 10-18 Device Administration Authorization Rule Properties Page

Option

Description

General

Name

Name of the rule. If you are duplicating a rule, you must enter a unique name as a minimum configuration;

 

all other fields are optional.

 

 

Status

Rule statuses are:

Enabled—The rule is active.

Disabled—ACS does not apply the results of the rule.

Monitor—The rule is active, but ACS does not apply the results of the rule. Results such as hit count are written to the log, and the log entry includes an identification that the rule is monitor only. The monitor option is especially useful for watching the results of a new rule.

Conditions

conditions

Conditions that you can configure for the rule. By default the compound condition appears. You can change the conditions that appear by using the Customize button in the Policy page.

The default value for each condition is ANY. To change the value for a condition, check the condition check box, then specify the value.

If you check Compound Condition, an expression builder appears in the conditions frame. For more information, see Configuring Compound Conditions, page 10-40.

Results

Shell Profiles

Shell profile to apply for the rule.

 

 

Command Sets

List of available and selected command sets. You can choose multiple command sets to apply.

 

 

Configuring Device Administration Authorization Exception Policies

You can create a device administration authorization exception policy for a defined authorization policy. Results from the exception rules always override authorization policy rules.

Use this page to:

View exception rules.

Delete exception rules.

Open pages that create, duplicate, edit, and customize exception rules.

Select Access Policies > Access Services > service > Authorization, and click Device Administration Authorization Exception Policy.

The Device Administration Authorization Exception Policy page appears as described in Table 10-19.

 

 

User Guide for Cisco Secure Access Control System 5.3

 

 

 

 

 

 

OL-24201-01

 

 

10-33

 

 

 

 

 

Page 297
Image 297
Cisco Systems OL-24201-01 manual 10-33