Setting access for one user

Hi,
Our client has ACS server and implemented AAA fro logging into switches and routers through ACS which is being cofigured RADIUS . They are telnet into rotuers and switches from any user but they are want to setting access from only one user . Can someone plz tell me what can i do to solve yhis problem ?

Hi,
If I understand this right, you have multiple users that can access the routers and switches right now but would like it so only 1 username has access?
If so, you could use NARS (network access restrictions) and deny access to everyone else but the one specific user.
Just select
1.Group Setup
2.Select the group which "already has" router switch access, edit the group settings
3.Then scroll down to the "per group defined network access restrictions" Enable it with a checkmark.
4. Select deny calling/point
5. AAA client = routers and switches (NDG)
6. Ports = *
7. Address = *
8. Hit enter and the new rule will be added to the window above.
9. Click submit (not submit and restart until you create the other NAR for the other group)
***Remember that groups that are mapped to and outside group (ldap, AD) will be able to connect to your routers and switches UNLESS to tell the ACS not to. By default the ACS doesn't know not to let USER1 access the routers but not allow USER2.
That being said, you'll need to deny access to your routers and switches (network device group) to all groups that are not allowed to connect to those devices.
Click submit and restart but remember this will stop authenticating users for the time its restarting.
Hope this helps and feel free to ask anymore questions.
Craig
Pls rate helpful posts.

Similar Messages

  • After installing Mountain Lion, why is there Yahoo access for one user but not another?--both are administrators.

    After installing Mountain Lion, why is there Yahoo access for one user but not another?--both are administrators.

    We've had several instances where we have had to run chkdsk on arrays with over 1m files. Average completion time is approximately 72 hours. The maximum downtime window they have available is the 64 hour weekend window. File sizes and number of files were
    much smaller then than they are now.
    The idea, in theory, was to use VHDs to compartmentalize the data into smaller volumes which could be more easily managed. It would also improve performance when transferring these compartments of data as they would use sequential read/write rather than
    fragmented/random. This idea was never fleshed out in entirety, they don't split data up into little containers, but simply into big ones per project. Hence the 11m files in one container that I am currently trying to diagnose.
    Some other important facts: The VHD in question is mounted in B:/project/ as this server also allows remote workers to log in, but they are restricted to see only data in E:. Disks A-D are hidden via group policy.
    Update: icacls is failing on a large number of files within this dataset. I counted the path characters to ensure it wasn't the 255 character limit I was encountering and verified that the paths being blocked are only about 150 characters long. Once it finishes,
    I'll have to try taking ownership and then re-running it. At this point I still have no idea how long to expect. I'm running out of time as the environment will be in use again at 9AM tomorrow morning.

  • Make PDF formular only accessable for one user at the same time?

    Hello!
    I designed a formular which needs to be filled in by different departments of our company. Unfortunatly the DF can be opened by several people at the same time. Is there any way to "lock" the PDF, fot that only one user has access to the formular at the same time, like e.g in MS Word Docs?
    Please help, I coudn´t find a solution myself.
    Thanks!
    K.B.

    This needs to be done on an OS level not by the application.

  • How to limit file access for different users in 10.7.4 Server

    We had everything working perfectly with an earlier version of Lion Server. The update to 10.7.3, or 4, seems to have opened access to all files for all users. Much to our surprise, this wide-open access started without warning.
    - We have an external drive that contains all of the company's archives
    - We had set access for one employee to get to the files he needs, and different access for another employee. Neither saw sharepoints outside of their access settings.
    After an update, each employee can see and log in to all sharepoints. There doesn't seem to be a way to limit access for each employee now. I can set 'read' access for one employee, but it doesn't stop the other employee from accessing that sharepoint/folder.
    Is there some new way to go about this? Or is something simply broken with the current release?

    That is good to know. If the file share is seeing the drive and ignoring its permissions, that is why everyone can see everything. I have found, in Lion Server, that it is best to get the permissions set before turning on File Sharing. I don't know if you have the luxury of turning the file share off for a little while, but I would unshare the drive and see if the issue persists if you plug the external drive into another machine. The settings for permissions are set on the file or folder itself, so the issue should follow you to the other machine.
    Again, if you can, I would unshare the drive and reshare it with the permissions that you want and turn file sharing back on. However, if you can get the drive to respect permissions rather than ignoring them, I think it will save you a lot of work.

  • Giving Access for an User On One Schema.

    Hi all,
    I want to give read,write and execute access for an user in one schema and only read access to another two users.
    How can I give..Please suggest.

    Hi,
    Well in that case you may have to give the select privilege to a particular user for all tables.
    Or
    You may like to create two roles, and give select privilege to a particular role for all tables. And give write i.e. insert/update privilege to the other role. Then assign this role to the user whom you like to give the access.
    Regards
    Anurag Tibrewal.

  • HELP needed on Remote Management set to allow access for all users

    my mac mini snow leopard server runs in a data center and i use screen sharing to interact with it. i played with the sharing settings remotely yesterday and changed "allow access for" to all users. i was disconnected immediately and i couldn't logon again. i have no luck changing to other users. i don't want to make a special trip to the center to change it back to whatever it used to be. i can still use afp to connect but the screen sharing option is no longer available. what does "allow access for all users" mean anyway?
    thanks!

    As its name implies, allow access for all should allow any valid user account to access the server. I'm not sure why it's no longer working. It almost sounds like the ARDAgent crashed.
    Either way there's a command-line interface to the ARD preferences:
    /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/ki ckstart
    man kickstart discusses the options, including examples of how to enable access for specific users.

  • OBIEE/EBS R12 - works, except for one user - ORA-06512 error

    OBIEE 10.3.1.4 / EBS 12.0.4
    Oracle 11g
    HPUX 11.31 64 bit Itanium
    We are successfully using EBS integration with OBIEE, but for one user that we have created it doesn't work. When they try to access OBIEE from EBS we get this error in NQServer.log:
    *[nQSError: 13011] Query for Initialization Block 'EBS Security Context' has failed.*
    *[nQSError: 17001] Oracle Error code: 6510, message: ORA-06510: PL/SQL: unhandled user-defined exception*
    ORA-06512: at "APPS.APP_SESSION", line 313
    at OCI call OCIStmtExecute: call / 101507300 */ APP_SESSION.validate_icx_session('NIOWQbvOlCFpGilcGDvlBIY-:S').*
    *[nQSError: 17011] SQL statement execution failed.*
    This is when the query is run against EBS to authenticate the user:
    select FND_GLOBAL.RESP_ID,
    FND_GLOBAL.RESP_APPL_ID,
    FND_GLOBAL.SECURITY_GROUP_ID,
    FND_GLOBAL.RESP_NAME,
    FND_GLOBAL.USER_ID,
    FND_GLOBAL.EMPLOYEE_ID,
    FND_GLOBAL.USER_NAME from dual
    It is only for one user that has the problem. All others users work fine.
    Has anyone else seen this problem?
    Our EBS DBA has checked that the above sql can be run with the session set to the problem user, and compared with a user who can successfully connect to OBIEE. The results were the same for both.

    I was on the wrong lines with this one.
    The error in the NQServer.log was not from the problem user, it was a separate user.
    The real cause of a specific user not being able to login was a corrupt web catalog (which we're still trying to resolve)

  • How to get number of failed log atempt for one user ( schema )

    Hi All,
    If one use try to connecte with wrrong password he will get this message ORA-1017. and the nombre of failed log atemp will increase.
    Then who can i check this number for one user in my date base ?
    Cheers
    Fayçal.

    Enable the audit by setting
    alter system set audit_trail=true scope=spfile;.
    Setting this parameter bounce of database
    Enable the following audit option
    SQL>AUDIT ALL BY ACCESS WHENEVER NOT SUCCESSFUL
    Then query AUD$ as the following example
    SQL> select returncode, action#, userid, userhost, terminal from aud$
    Regards,
    Anand

  • Adjusting the display area's size for one user

    For one user account, the display is larger than the area of the monitor such that when we move the mouse the whole picture scrolls since it does not fit on to the display's area.
    I would have thought this had to do with the hardware adjustments with which you can adjust the hor/vert positioning, etc., but I have not been able to address this problem with these controls - In any case, those hardware controls effect all users and this is only an issue for one (of four) users.
    It seems it has to do with the resolution since the fonts are slightly distorted.
    The display system preferences are set correctly - and no matter what resolution is set, the problem is consistent for that user.
    Any suggestions?!

    System Preferences->Universal Access and check that Zoom is off.

  • Work flow Icon Is Greyed out for One user

    Hello SAP Guru's ,
    We are facing issue for one user in SAP easy Access .
    Workflow Icon,User Menu ,SAP Menu buttons is Greyed out but user able to access transaction SBWP.
    Can you please give solution why those buttons are greyed out and few button's are (Enabled attched In scrren shot)?Do I need to maintain any where user settings
    Please let me any user specific settings is missing for that user ?
    My Analysis - I have checked with user and I tried to change in SAP Easy Access ->Extras->Settings Still not able to achive any .
    I gone thorough the link - http://scn.sap.com/thread/1737679
    Still not able to resolve this issue.
    Thanks In Advance,
    Shiv

    Hi,
    Please check the following authorization objects are assigned to the user or not in SU24.
    S_BDS_DS BC-SRV-KPR-BDS: Authorizations for Document Set
    S_OC_DOC         SAPoffice: Authorization for an Activity with Documents
    S_OC_FOLCR     SAPoffice: Authorization to Create Shared Folders
    S_OC_ROLE        SAPoffice: Office User Attribute
    S_OC_SEND       Authorization Object for Sending
    S_OC_TCD          SAPoffice: Transaction Code Authorizations
    S_WFAR_OBJ    ArchiveLink: Authorizations for access to documents
    Regards,
    Murali Krishna.

  • Control Feature set access for a supervisor

    Hello,
    I have the following case which i need help.
    I have a precofigured supervisor on the UCCE, the supervisor can access reporting , login to the CSD , everything is fine.
    However i need to add a control feature set access for this supervisor in order to give him access to the AW to configure agent, this is not happening with me, is there a way that i can merge the same user for both supervisor user and a control feature setup user at the same time.
    Thanks.
    Amer

    OK, I think I can do this one. In the supervisor When you clear the check box and press save, you see this.
    So after this, DCVP\30002 should not exist in the AD. Let me check. Yep - gone.
    Now I go to user list tool and create this same guy 30002.
    Now checking Domain - yep, 30002 is under the Cisco OU.
    What was the question?
    Regards,
    Geoff

  • Page should be accessed by one user at a time

    Hi friends,
    I have a new requirement where webpage should be accessed by one user at a time.Suppose if one user is using the page ,the other user should not be having the privilage to access tht page.NOw how to go about..If possibel pls help me with the code..
    Thanks in advance..
    Waiting for ur suggestion.

    Finally i am using a method..
    <script language="JavaScript">
      window.onbeforeunload = confirmExit;
      function confirmExit()
          document.LoginForm.action="next.php";
          document.LoginForm.submit();
        return "Are you want to exit this page?";
        return false;
    </script>
    </HEAD>
    <BODY onbeforeunload="confirmExit()">
    <form name="LoginForm">
    </form>
    </body>
    </html>I am using onbeforeunload ,so when ever the page is refreshed or user tries to move from the page i call function from tht i go to a page where i do file creation . when ever user access the page, simultaneously other users wiil be detained access for tht page..
    But the problem i am facing here is..whenever the user tries to change focus from the page a pop up comes up saying do u want to continue or not..if user press cancel actually the control has to remain in the same page but still the control is passed to the different page...
    pls advice on this..

  • JSP page doesnt load for one user on machine1, but does 4 all on same box

    Hi,
    I have a Citrix application on a box to enable many users to connect remotely to different applications on differnt boxes using the browser on this box. Just like terminal Services or remote desktop
    I tested 15 users and all of them are able to login to the machine and able to open a jsp page of an application located on a differernt box using the browser on this box.
    But for one user I am facing an issue. For this user, I am not able to get the page and instead I only see a message as "page loading" and nothing more than that, Its getting stuck there itself with no progress.
    Please help me,
    Thanks a lot in advance,
    Srinivas.

    Hi,
    I suspect there is something missing as far as the JRE for this guy is concerned. Sothing to do with permissions. java policy, security etc.
    I am not sure if that helps. I am not in the development of the application, and will check with those guys. I only neeed to provode support on this machine and be able to give access to that application which is on Linux. The browser is in Windows machine,
    Thanks,
    Srinivas.

  • ODBC--connection to 'SQL Serverservername' failed for one user but not another

    In Win7, we're linking tables in an MS Access 2010 db to tables in a SQL Server 2008 R2 db. The driver user by the File dsn is SQL Server version 6.01.7601.17514 & we're using SQL Server Authentication.
    For some reason, one user gets the msg "ODBC--connection to 'SQL Serverservername' failed" before they're even asked for a password, but for other users, the prompt comes up and when they uncheck the Windows Auth box, they enter their password
    and connect successfully to the SQL Server db.  Both users have db_datareader access to the SQL Server db.
    I had the user that gets the error msg log onto my PC and they get the same error (yet it works for me.)
    This user was, however, able to successfully relink the tables, but then when we closed the access db and opened it again, the user got the "ODBC--connection..." error agin.
    I'm stumped as to why this is happening for one user.

    Hello Knellen,
    Please help to collect more log information regarding this issue, such as windows event log, SQL Sever log information. They are helpful for us to troubleshoot it.
    Regards,
    Elvis Long
    TechNet Community Support

  • How to open multiple sessions for one user?

    Sorry for the silly question but I couldn't find it googling or searching through this forum, so I started wondering whether it's possible in SQL Developer to open multiple sessions for one user. I'm fairly new to SQL Developer and databases in general.
    When I open SQL Developer and connect to a schema, a worksheet opens named MYSCHEMA. If I disconnect then connect, another worksheet opens, named MYSCHEMA~1. I assumed these were different sessions, but if I enter into one worksheet:
    select col1 from my_table where row_id = 1
    -- shows result is 1
    update my_table set col1 = 0 where row_id = 1
    select col1 from my_table where row_id = 1
    -- shows result is 0and then enter into the second worksheet:
    select col1 from my_table where row_id = 1
    -- shows result is 0I would have expected the second worksheet to report 1 because the first worksheet did not issue a COMMIT. Thus, I'd guess both worksheets are the same session? Is that right? If so, how do I have two sessions open simultaneously (opened by same user)?
    I'm trying to implement the code at the bottom of this post, for which testing requires at least two sessions:
    Re: Help with Procedure
    Edited by: tem on Apr 18, 2012 6:44 AM

    Thanks Jim,
    Ctrl-Shift-N doesn't do anything for me. I'm on a mac -- by experimenting it looks like command-N does what you're looking for. This appears to be the same as left-clicking on the "New" icon in the top left corner of SQL Developer, or selecting from the pull-down menu, File > New.
    This opens "Create a New" window that appears to be a wizard. What would I select at this point? Options are: Database Connection, Table, View, Package, ...
    I don't see an option for "Worksheet".
    UPDATE:
    OK, I found that if I select "SQL File", a worksheet becomes available. Perhaps this is what you intended. However, when I issue the command
    select col1 from my_table where row_id = 1;it still returns 0 instead of 1. Hmm, maybe my initial assumption was wrong -- if this is a second (e.g. different) session, should I expect the changes made in the first session in SQL Developer (the UPDATE command) WITHOUT a commit, to be observed in this second session? I thought that changes made in one session were not viewable in a different session until these changes are committed in the first session? If so, how to show this in SQL Developer? I must be missing something basic here.
    Or, is SQL Developer issuing some sort of "auto-commit" without my knowledge?
    Edited by: tem on Apr 18, 2012 8:00 AM

Maybe you are looking for

  • Error in Generating a Report

    Hello everyone am a Novice in Business Objects.I have created all the tables and the corresponding classes and objects using Universe.But when i am trying to run the report in Deski its showing the following error " The Query does not reference a tab

  • Strange folder "tmp" in "private" folder.   virus?

    an alias folder just recently showed up on my harddrive in the main window/directory (the one that has "applications, library, system and users" It's called "tmp" and is an alias folder. inside there's a folder called 501 and some files like cscache_

  • CO: Statistical reposting from NWA to Cost Center

    Hi Gurus, My client expecting the travel expenses statistically post to Cost Center which would not affect the true posting to NWA. Is there any transaction allow us to achieve that. I've tried with the Manually reposting of cost, not sure the repost

  • I can't open Firefox when I first startup, I have to reboot to open it, why?

    I can't open Firefox when I first boot up. I have to reboot to open it. Does anyone know why?

  • Print Problems with 3600n printer

    I am having problems printing certificates with a 3600n color laserjet printer.  The certificate blanks are cardstock thickness and have a foil emblem embossed on the upper portion of the certificate.  When I print a certificate out, I often get a re