ACS 5.1 - auth against different AD groups from one client?

Hello,
ASA has RA vpn's set up with authentication against TACACS ACS 5.1 based on AD group.
Need to set up access to ASA itself (ssh) based on TACACS as well, to the same ACS box.
Is it possible to have it against another AD group?
Right now, when I create rule, the cryteria to select specific service is based on protocol, client device IP, few other conditions,
and based on that ACS selects rule which in turn may be Network Access or Device Access.
I created two different rules, one is Device Access against Group1 in AD, another is Network Access agains Group2 in AD, and which one is
the first in the list, that is being chosen for VPN access - basing on ASA IP and protocol (TACACS).
Probably workaround would be to enable both RADIUS and TACACS for the ASA and on ACS for this client, and use different protocols for vpn and local device access?
Is this the way?
Thank you
Alexander

Hello,
ASA has RA vpn's set up with authentication against TACACS ACS 5.1 based on AD group.
Need to set up access to ASA itself (ssh) based on TACACS as well, to the same ACS box.
Is it possible to have it against another AD group?
Right now, when I create rule, the cryteria to select specific service is based on protocol, client device IP, few other conditions,
and based on that ACS selects rule which in turn may be Network Access or Device Access.
I created two different rules, one is Device Access against Group1 in AD, another is Network Access agains Group2 in AD, and which one is
the first in the list, that is being chosen for VPN access - basing on ASA IP and protocol (TACACS).
Probably workaround would be to enable both RADIUS and TACACS for the ASA and on ACS for this client, and use different protocols for vpn and local device access?
Is this the way?
Thank you
Alexander

Similar Messages

  • Move Protection Group from One DPM server to another DPM server

    Hi Mike,
    Can we move Protection Group from one DPM 2012 SP1 to another DPM 2012 R2 version? If yes then what is the steps to perform that. Also i am running DPM servers with co-located and non-colocated configuration. What would be best as per best practice? Because
    my 95% backup are SQL backups.

    Hi,
    There are no provisions in DPM to move protection groups or protected data sources to a new DPM server and maintain the recovery points.  The best you can do is to stop protection on DPM1 and retain the replica, then run the setdpmserver.exe on the
    protected server and point it the DPM2 server. On DPM2, run the attach-productionserver.ps1 script to establish agent communications, then make new protection groups and re-protect the same data sources.  After the retention goals are met, delete
    the replica from under inactive protection group on DPM1.
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. Regards, Mike J. [MSFT]
    This posting is provided "AS IS" with no warranties, and confers no rights.

  • Why can't I save Tab Groups from one session to the next? When I restart, tab groups are cleared.

    Why can't I save Tab Groups from one session to the next? Is there a way to save Tab Groups from the last session to the next time I start up?
    Mark Kipperman

    Yeah, if this is the way it's supposed to work its a useless and, dare I say, stupid "feature". Wouldn't the whole point of this be to have quick access to groups of pages. If I have to select them each time to create the group what is it doing for me?

  • How can connect different ejb server in one client program

    hi , every
    i want to make connect ejb server into one client program.
    for that , but i try to change PROVIDER_URL property , it's not correct
    who solve this problem for novice? :(

    You need to create separate initialContext to each of the different servers
    and lookup up the different ejbs.
    -Sabha
    "inking" <[email protected]> wrote in message
    news:[email protected]..
    hi , every
    i want to make connect ejb server into one client program.
    for that , but i try to change PROVIDER_URL property , it's not correct
    who solve this problem for novice? :(

  • Moving the Individual Protection group from one SAN Volume to another SAN Volume

    Hi Professionals
    Dudes !!! There is no much information about migratedatasourcedatafromdpm.ps1
    script on the technet. My question is that I need to move Individual Protection group in an orderly manner from one SAN Storage to Another. I have more than 30 protection groups. I want to move individually 2 to 3 protection groups at one time from
    Old SAN Storage to New SAN storage. Is it possible that I mention  protection group individually and move each protection group bit-by-bit to the new SAN Storage. 

    Hi,
    you can use this GUI Option, to move a whole Disk.
    in the next Version, hopefully published this Week, you can select a whole Protectiongroup to move
    http://gallery.technet.microsoft.com/Migrate-DPM-Disk-or-dea8d4e9
    Seidl Michael | http://www.techguy.at |
    twitter.com/techguyat | facebook.com/techguyat

  • Importing users & groups from one OID to another

    I was wondering what's the fastest and most efficient way of exporting all users, groups, classes & attributes from one OID server and importing them into another OID server. In another way i just need to synchronize both OID servers with the same data. what's the fastest and best way to achieve that please?

    Just use the gray installer discs that came with one of the computers.
    Note that you must then remove from the first computer as you have only a license for one computer.

  • Different schema group for one vendor

    Dear all,
    We come across scenario,Where a vendor import material for us and at same time
    he also acts as a dealer.Here it requires two schema groups for a vendor.
    One possible solution is two different vendor codes for same vendor.
    Here i come across this answered link
    Vendor Schema group
    How to do it through partner functions ?
    or
    Any other solution for it ?
    Thanks
    Jeyakanthan

    Hi
    You can achieve this requirement by using vendor subrange. You can have morethen one subranges for same vendor. It will allow you to have more than one set of purchasing data in vendor master which includes schema group and terms of payment....etc.. You need to create vendor subranges from purchasing view in extra and in additional purchasing view.
    The below link wil help u to understand the Vendor subrange:
    http://help.sap.com/erp2005_ehp_04/helpdata/EN/e2/f3333956bd9f05e10000000a11402f/content.htm

  • How to copy function group from one SAP system to another

    dear all,
    our company will set up a sub-company currently,and the sub-company want to copy some programs from our SAP system.
    how to pack and copy function group?
    pls help me,tks!

    Hello  Snow zeng,
    Will the 2 systems be connected ? I.e Same land scape ?
    If they are non connected systems, check this Wiki by Marcin [How to copy Repository Objects between non-connected SAP systems|http://wiki.sdn.sap.com/wiki/display/ABAP/HowtocopyRepositoryObjectsbetweennon-connectedSAPsystems]
    Regards

  • How do you manage different target platforms from one FLA?

    I am in the throes of trying to publish an app for both iOS and Android mobile devices and am having trouble finding some guides related to how to most easily target these two platforms without duplicating code or FLA files.
    So far, I have one single code base that checks CONFIG::DEVICE constant to know what platform dependant classes it should or shouldn't use, but as for the FLA, I have two copies of this same FLA with different publishing settings (one set for iOS and one set for Android, and each with the appropriate difference set in the config constant). Needless to say, managing two FLAs with nearly identical content is a pain in the butt.
    How am I supposed to do it (using Flash Professional CS6)? I was considering using "Profiles" (upper left corner of Publish Settings panel) but in the past whenever I've relied on Profiles it has been unrealiable. For example, the SWF file name doesn't change, making it a pain to try and make a seperate SWF for iOS and one for Android. If I just change the target platform in the pulldown mennu for that, will it remember the old settings when I come back to a previous selection? (ie: AIR 3.6 for ios, vs AIR 3.6 for Android, etc)
    Suggestions?  I couldn't find anything by Googling.

    Sure but why doesn't Adobe, who has been pitching Flash & Adobe AIR as "author once, publish to multiple targets" fix this very simple problem?
    I experimented some more and I managed to set up one FLA with two profiles. One is configured for iOS and the other is configured for Android. It WORKS fine except the iOS settings loses all the icons except for the 3 it has in common with the Android side. Conversely, the Android side loses extra Manifest parameters I need for Admob extension integration. It's quite frustrating that this works up to 95% and then loses it. All they really need to do is tie separate app.xml files to seperate publishing profiles.
    One way around this would be if I set each profile to publish to a different swf file. AH, but guess what, that is the ONE setting that a profile does NOT save!!!!!!
    Thanks for your tip though.

  • How to make different print jobs from one PC

    Hi
    We have a problem to make 2 different print jobs at same printer with one PC.
    We use Adobe Acrobat X Standard or Acrobat Reader 9 both no sucess.
    we want following
    1. print A4
    2 Print A6
    Program find out itselw when to print A4 or A6 from different location at the same printer or at 2 different printers.
    Bothe print 1 and 2 is PDF file.Print 1 is for invoices - print 2 is for labels
    Is that posibel with Adobe?
    BR
    Flemming

    Hi and welcome to the RoboHelp forums. You may be better placed to ask this question on the Acrobat forums as I expect knowledge about printing PDFs would be limited here. However I suspect that you'll need to set-up different Print Options inside Acrobat to do what you want. This is not my area of expertise though.
      The RoboColum(n)
      @robocolumn
      Colum McAndrew

  • Is there a way to move tab group from one window to another?

    I have several windows open, and some of them have multiple tab groups. Is there an easy way to move these tab groups between the windows?
    I saw the workaround of making bookmarks of all the tabs in one group, move to the target window and open the bookmarks there.
    To be honest I found this one a slow and messy way to do things and hope to find a better solution or raise this as a feature request.
    using up-to-date Firefox (26.0 at the time of writing)

    Hi bsbs,
    I don't think so, there are bugs that do exist about this as well
    *Tab group not available in customize tool bar in a second window if tab groups is open [https://bugzilla.mozilla.org/show_bug.cgi?id=840579]
    Patrick helped me find this add on [https://addons.mozilla.org/en-US/firefox/addon/tabgroups-manager/] where it groups tab groups into other groups, and there are bugs that have the [feature request] title in them.

  • How to copy one user-created Group from one tab to another tab in word 2013 Ribbon

    hi Friends
    in Word 2013 Ribbon, i have created a customized Tab & a customized Group within it which contains some stuff.
    i need this Group & all its contents be copied also to another tab (for example Home tab).
    is there any workaround to copy it to another tab?
    i know i can customize the ribbon, create new Group, find each desired item & add each one to group... but i don't want to do this method because is time consuming & is creating from scratch which is not desired
    any solution?
    thanks in advanced

    Hi,
    As far as I know, we can only export the entire ribbon and QAT with the build-in Export functionality in Microsoft Office, not just part of it.
    However, the exported Customizations.ExportedUI file is a XML text file. We may try to modify the
    Customizations.ExportedUI file to achieve the goal. See:
    http://msdn.microsoft.com/en-us/library/office/ee704589(v=office.14).aspx
    Since it's a development issue to customize the Customizations.ExportedUI
    file and we are not experts on such issues, I'd recommend you post a question in the Word for Developers forum:
    https://social.msdn.microsoft.com/Forums/office/en-US/home?forum=worddev
    The reason why we recommend posting appropriately is you will get the most
    qualified pool
    of respondents, and other partners who read the forums regularly can either share their knowledge or learn from your interaction with us. Thank you for your understanding.
    Steve Fan
    TechNet Community Support
    It's recommended to download and install
    Configuration Analyzer Tool (OffCAT), which is developed by Microsoft Support teams. Once the tool is installed, you can run it at any time to scan for hundreds of known issues in Office
    programs.
    hi Steve
    useful
    thanks a lot

  • How to separate/split different drum tracks from one recorded track

    Hi,
    Pretty hard to explain my intentions in the title, but i've recorded drums with one mic (so there's only one track), and i was wondering whether or not it's possible to separate the hi-hat, snare, toms, etc. from each other? So basically i want to create separate tracks for each of these sounds. I know it's a tricky and pretty specific question, but this would really come in handy since you can replace the drum sounds.
    The biggest problem, if this were possible, is to separate tones that are recorded at the same time.
    And yes, i tried the manual, but i couldn't figure this one out.
    Thank you very much
    Message was edited by: Goossens.Fre

    Goossens.Fre wrote:
    The biggest problem, if this were possible, is to separate tones that are recorded at the same time.
    You are right: This is impossible.
    The next best thing is to use Flex Time to find the attack transients and then split the audio at those transients, so you can move the individual snippets to different tracks.

  • Can I transfer my different iTunes songs from one comp to another

    so I have two iTunes librarys with totally diff songs. Ones on my XP and ones on my MAC. So how can I get the ones from my XP to my Mac without ripping my hair out and burning cds and transferring them. I would LOVE to use my jumpdrive but I think that that it just not the case.

    Click here and follow the instructions even if you're using Mac OS X 10.5, or split the library into pieces which are small enough to fit on the drive.
    (35632)

  • Need to Do 1 Goods Recipt  from Different Purchase orders from one Vendor

    Hi Experts,
    Would like to have a Query, My Client require, As he has raised 10 Purchase.Orders"S with respect to one Vendor depending upon the stock requirement. He wants all the 10 Purchase orders to be inwarded in one attempt itself, Even the vendor has collected all 10 purchase orders at a time and send all 10 Purchase order goods at a time Can be it possible to do GR of all 10 Purchse orders in one Goods recipt.
    Waiting for your reply.
    Best Regards
    Javeed

    Yes, you can do it in MIGO..
    Pls enter the PO number & press Enter and again  enter the PO number & press Enter .
    Continue like this..for all your Po's..
    The prerequisite for this is the Vendor Should be same for all the PO's

Maybe you are looking for