Chapter6 Setting Up and Managing User Groups
Common User Group Settings
6-8
Cisco Secure ACS 3.0 for Windows 2000/NT Servers User Guide
78-13751-01, Version 3.0
page of the Interface Configuration section for single group IP-based filter options
and single group CLI/DNIS-based filter options to appear in the
Cisco Secure ACS HTML interface.
Note When an authentication request is forwarded by proxy to a Cisco Secure ACS
server, any NARs for TACACS+ requests are applied to the IP address of the
forwarding AAA server, not to the IP address of the originating AAA client.
To set NARs for a user group, follow these steps:
Step 1 In the navigation bar, click Group Setup.
Result: The Group Setup Select page opens.
Step 2 From the Group list, select a group, and then click Edit Settings.
Result: The Group Settings page displays the name of the group at its top.
Step 3 To apply a previously configured shared NAR to this group, follow these steps:
Note To apply a shared NAR, you must previously have configured it under
Network Access Restrictions in the Shared Profile Components
section. For more information, see the Shared Network Access
Restrictions Configuration section on page 5-7.
a. Select the check box labeled Only Allow network access when.
b. To specify whether one or all shared NARs must apply for a member of the
group to be permitted access, select one of the following two options:
All selected shared NARS result in permit
Any one selected shared NAR results in permit
c. Select a shared NAR name in the Shared NAR list and then click > (right
arrow button) to move the name into the Selected Shared NARs list.
Tip To view the server details of the shared NARs you have selected to apply, you
can click on either View IP N A R or View CLID/DNIS NAR, as applicable.