Limit Telnet = ASA to one AD group

I want to restrict CLI access to our ASA 5510 to one Active Directory group. Currently the ASA authenticates against our LDAP/AD server, and anyone in the organization can log into the ASA using HyperTerminal (enable password is another matter, however).
How can I narrow such access to only our IT group, which has its own AD container?
Thanks in advance,
-- Bill

No, this won't restrict access for VPN users in that OU because we are only configuring it for TELNET access.
Here is a config example:
aaa-server protocol ldap
aaa authentication telnet console LOCAL
aaa authorization exec authentication-server
ldap attribute-map
map-name memberOf IETF-Radius-service-type
map-value memberOf service-type 6
aaa-server host
ldap-base-dn
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-dn
ldap-login-password
server-type microsoft
ldap-attribute-map
For more info, you may refer:
Limiting User CLI and ASDM Access with Management Authorization
http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mgacc
ess.html#wp1070306
Hope this helps.

Similar Messages

  • Group Limit items to create one PO

    Hi All,
    while creating limit items, we want to group all limit items in one PO. I am aware that it is SAP standard behavior that we should not have more than one limit item in a PO.
    But is there any BADI available for such an enhancement so that we can gorup multiple limit items to create one single PO ?
    Thanks.

    Hello,
    In case of Extended classic scenario, as per the standard system design, it is not possible to create two limit items in one PO, when a PO is created manually from transaction "Create purchase order" (BBP_POC).                                                                    
    If you want to have two limit items in one PO, this is possible only by a Shopping cart. In shopping cart, you have to create two hierarchies with one limit item in each hierarchy. This will then create a PO with two limit items. This is the only way you can have two limit items in one PO in case of ECS.
    Multiple packages concept is introduced in SRM 5.0.                               
    The prerequisite to have multiple service packages in SRM is to have multiple hierarchy items in one PO. Unfortunately there is nearly no way to create hierarchy items directly from PO. It is only possible by a SC or an RFI process. The multiple service package handling was built exactly for this scenario.                                                                               
    Items need to be hierarchy items so that different packages are created for each item. If you have more then 1 limit item you will end up with 1 package for all of them.
    This results in PO not being created in the backend raising an error message:  #Sum of Percentages > 200.0< exceeds 100%.                              
    I hope this helps.
    Kind regards,
    Ricardo

  • Stmfadm A host group member cannot be a member of more than one host group

    Hello, i setup solaris & make it FC target for my test ESX cluster.
    ESXi nodes has not local disk (to boot from), so on solaris side I setup 3 zvol and try to export them to my ESXi host. 1 & 2 zvol to setup ESXi it self & boot from it.
    3-d zvol to datastore purposes, store & run virtual machine.
    But I have problem with lun masking.
    I need following config:
    ESXi1 - Lun 1,3
    ESXi2 - Lun 2,3
    I plan create 3 host-groups:
    1 - ESXi1
    2 - ESXi2
    3 - ESXi1,ESXi2
    But it is imposible, it seems there is limit in stmfadm
    In manual page I can see: "A host group member cannot be a member of more than one host group."
    Can you advice me any solution?
    Alex
    Edited by: 1009729 on Jun 4, 2013 9:18 PM

    Hello, i setup solaris & make it FC target for my test ESX cluster.
    ESXi nodes has not local disk (to boot from), so on solaris side I setup 3 zvol and try to export them to my ESXi host. 1 & 2 zvol to setup ESXi it self & boot from it.
    3-d zvol to datastore purposes, store & run virtual machine.
    But I have problem with lun masking.
    I need following config:
    ESXi1 - Lun 1,3
    ESXi2 - Lun 2,3
    I plan create 3 host-groups:
    1 - ESXi1
    2 - ESXi2
    3 - ESXi1,ESXi2
    But it is imposible, it seems there is limit in stmfadm
    In manual page I can see: "A host group member cannot be a member of more than one host group."
    Can you advice me any solution?
    Alex
    Edited by: 1009729 on Jun 4, 2013 9:18 PM

  • Free Goods from One Material Group to Another Material Group

    Salute Masters!! 
    I need your valuble suggestion, please provide.
    I need to configure Free Goods of Material Group to Material Group.
    User want:
    1) Free Goods from one Material Group to another Material Group, like F010 to F040
    2) User should have option to change from one Material Group to Other Material Group, which He / She want, like F010 or F020, F030, F040 any one of them.
    Suppose;
    Line Item Material Belongs to One Group Quantity in Gallons Free Goods from Any Material Group Quantity in Gallons
          1            A                                              3                                    F010                                             4
          2            B                                              3                                     F020
          3            C                                              4                                     F040
    Any No. of Line Item Any No. of Material
                                       from One Group      Total 10                   From Any Material Group
    (Comprising of 3-4 Different Material from 1 Group, they should be able to choose/provide Free Goods from other Material Group)
    3) While creating Sales Order what Quantity (Gallons/No./Ltr) to be put?
    How I can configure this scenario?
    Please suggest, is it  possible through KEY COMBINATION?
    Rgds.
    Srivastav
    +91 7829755109
    Skype ID: sanjai.srivastav1

    Hi,
    if you want to give free goods from other group it can be possible only for EXCLUSIVE free good type
    In exclusive free goods, a material different from the orignal material can be specified as the free goods.
    Example: A customer who buys 200 crates of beer, gets 5 boxes of glasses free.
    In VBN1 >> Exclusive
    See column ADD FREE MATERIAL
    While creating Sales Order what Quantity (Gallons/No./Ltr) to be put?
    Maintain alternative units in material master >> Additional data >> Material master,BUT it is only main item
    Those item u want to give free that items unit is derived from free goods condition record and it CANNOT be change in order

  • How can we assign more than one request group to a responsibility?

    Hi
    Can anyone tell me how we can assign more than one request group to a responsibility?
    Thanks
    SS

    Hi SS,
    Its not possible, rather you should create a combination of Requests/RequestSets and create a new Request Group.
    Regards,
    Kiran

  • How to transfer the tables from one file group to another file group in SQL 2008.?

    Hello all,
    I have few issues regarding the transfer of the tables from one file group to another file group  in SQL 2008 and also How can we  backup
    and restore the particular database based on file group level.
    Let’s say I have a tables stored within the different FG. such as
    Tables                                                    
      File group
    Dimension tables                                              
                                                                     Primary
    Fact tables                                               
                                                                              FG1
               FG2…
    zzz_tables                                               
                                                                              DEFAULT_FG    
    dim.table1                                                                                                                          DEFAULT_FG
    dim.table2                                                                                                                          DEFAULT_FG
    Here all I want to transfer the dim.table1 ,dim.table2  from  DEFAULT_FG to the Primary File
    group .So is there simple methods for transfer the dim.table1,2  from one FG to another .I have tried somewhat but I couldn’t get the exact way .So if someone have better idea please share your knowledge that would be really appreciated.
    Secondly after moving those dim.table1 ,dim.table2 from DEFAULT_FG to Primary ,All I want to backup and restore the database only containing  the Primary and FG1,FG2… not
    a DEFAULT_FG.Is it possible or not.?
    Hope to hear from the one who knows better approach for this kind of task .Your simple help will be much appreciated.
    Regards,
    Anil Maharjan

    Well after all my full day research on this topic had paid off, I finally got the solution and am so happy to research on these things. It makes
    us feel really happy after all our research and hard work doesn't goes as waste.
    Finally I got what I am looking for and want to make sure that I am able to transfer the tables from DEFAULT_FG to another FG without tables
    having clustered index on that tables .
    With the help of the link below I finally got my solution where Roberto’s coded store procedure simply works for this.
    Really thanks to him for his great post and thanks to all for your response and your valuable time.
    http://gallery.technet.microsoft.com/scriptcenter/c1da9334-2885-468c-a374-775da60f256f
    Regards,
    Anil Maharjan

  • Unable to use more than one processor group for my threads in a C# app

    Hi,
    I set my .Net 4.5 (or 4.5.1) App.Config to:
    <?xml version="1.0" encoding="utf-8"?>
    <configuration>
    <runtime>
    <Thread_UseAllCpuGroups enabled="true"></Thread_UseAllCpuGroups>
    <GCCpuGroup enabled="true"></GCCpuGroup>
    <gcServer enabled="true"></gcServer>
    </runtime>
    <startup>
    <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.1"/>
    </startup>
    </configuration>
    I run my app on a windows server 2012 with a NUMA architecture: 2 x [cpu Xeon E5-2697 v3 at 14 cores each with Hyper Thread activated] => 2 x 14 x 2 = 56 Logical Processors.
    This is TaskManager screenshot:
    My app start 80 threads either from "Thread Class" or "Parallel.For" and in both case it only takes 28 Logical Processors, all from the same Processor Group.
    According to MSDN documentation
    and
    Stephen Toub answer, it should use every Logical Processor of every Processor Group.
    Why does the Task scheduler assign my threads on only one Processor Group?
    I also reported this question to
    StackOverflow which have a lot more information.
    Eric Ouellet

    One thing before all, is that I suggest that you think through your security model before implementing it in UCM. You should ask yourself questions like :
    - Is security really based on department ?
    - Why two departments need to have access to the same category of document ?
    - Is it really security that I need or classification ? Is it a problem if Accouting have access to Finance or you just don't want Marketing documents in a finance related search ?
    - Maybe what you want is that finance guys to have access to marketing document.
    Without a clear business security model, it's hard to find a UCM security model as it is impossible to associate 2 security groups to one document.

  • How do I consolidate all of my events into one big group of photos so I can see them all?

    The title says it all. How do I consolidate all of my events into one big group of photos so I can see them all? Instead a bunch of events.

    drag them together
    Or click on Photo in the source pane on the left and under the view menu uncheck show event titles
    LN

  • Move a query to from one user group to another user group

    Hi,
    it's possible to move a query (SQ01) from one user group to another user group ??
    Thank you.

    Hi,
    You can copy queries only if you have the authorization to make changes. Within your current user group, you can copy all queries. However, queries of other user groups can only be copied if the InfoSet used to define the query is assigned to both user groups.
    To copy a query, proceed as follows:
    1. Choose the name of the query you want to copy on the initial screen.
    If you do not know the name, use the directory functions to display the query directories and then choose a query to copy from there.
    2. Choose Copy.
    3. Enter the name and the user group of the query that you want to copy in the dialog box. Furthermore, you must enter a name for the copied query. The system proposes values for this.
    4. Choose Continue.
    This takes you to the initial screen. The query is added and appears in the query directory. You can now continue.
    Regards,
    Amit

  • How to move Tablespace from One disk group to another disk group in RAC

    Hi All,
    I have 11gR2 RAC env on Linux.
    As ofnow I have problem with disk group. I have 3 disk group which is almost full - 98%. I have added one NEW disk group and want to move some of the Tablespace(TBS) from OLD disk group to NEW diskgroup and make some free space in OLD disk group.
    Can any one suggest me how to move TBS from one disk group to another disk grup without shutting down the instance.
    DB is in Noarchive mode.
    Thanks...

    user12039625 wrote:
    Hi Helios,
    Thanks for doc id but I am looking for noarchive mode solution. becaues I got ORA-
    "ORA-01145: offline immediate disallowed unless media recovery enabled " when run alter database datafile '...' offline.
    Hence I am trying something and findout below steps but not sure how useful it is:
    1- put tablespace offine
    2- Copy the file to new diskgroup using Either RMAN or DBMS_FILE_TRANSFER.
    3- Rename the file to point to new location.
    4- Recover the file.
    5- Bring the file online.
    I had move 240M TBS from OLE to NEW.
    These steps run successfully so I think this is valid for noarchive mode.Hence want to confirm..so inform me please.
    Thanks :)I have doubt in my mind:
    1. You database is in noarchivelog mode
    2. You're taking tablespace offline
    3. Suppose you're moving a file of size 10GB(or any larger filesize) to another disk group
    4. Now after moving the file, you're trying to bring the tablespace online............NOW
    tablespace will need recovery. if the required data is inside the SGA then it is ok. But if the data has been flushed, then?
    if step 2 and 3 has taken significant time, then most probably you'll not be able to bring that tablespace online.
    Regards,
    S.K.

  • CCME Call Forward from one Hunt Group to another Hunt Group Failure

    Hi I have a couple of hungroups in Cisco Call Manager Express. I am trying to configure a Call Forward no answer from one hunt group to another. Does anybody know if this is possible? If so, is there a config available? Here is my config, but it is not working.
    Thanks,
    Derek
    voice hunt-group 20 parallel
    final 2290
    list 2201,2251,2252
    timeout 30
    pilot 2209

    Hi Derek,
    This is supported with the restriction shown below;
    final number
    Router(config-voice-hunt-group)# final 8888
    Defines the last extension in a voice hunt group.
    If a final number in one hunt group is configured as a pilot number of another hunt group, the pilot number of the first hunt group cannot be configured as a final number in any other hunt group.
    From;
    http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucme/admin/configuration/guide/cmeadm/cmecover.html#72373
    Cheers!
    Rob 

  • Copy a page from one page group to another

    Hi
    Is it possible to copy a page from one page group to another?
    Regards,
    Lene

    Hi ,
    Through Portal it is not possible to copy a page from one page group to another .
    There is a feature in Portal WebDav .
    Through a DAV client you can copy page to your local system as a folder and then drag the page to the pagegroup you want to copy .
    Regards
    Medini

  • Moving Pages from one Page Group to Another Group

    Hello,
    How do you move pages, styles, or items from one page group to another page group?
    On the same machine, I have three page groups called Production, Acceptance, and Test. Once I set up a page that I like on the page group Test, what is the best way to move the page(and its items, portlets,etc) to the page group Acceptance, and then move it into Production?
    Also, how does security and approvals affect this? There is only limited amount of people that are able to get into the Test Page Group, or Acceptance Page Group. Would any copying process make sure the page approvers be copied across correctly? Or will manual intervention be needed.
    I'm using Oracle Portal Release 2 (9.0.2) running on a solaris machine.
    Much thanks for your assistance.
    Anson

    hi There,
    As far as i know, the pages can only be moved within the page group but not from one page group to another page group.
    Regards,
    Deepak

  • Link from one Page Group to another

    It it possible to click on a link in one page group and link to a page in another page group.

    Create a "Page Link" item, one of the built-in item types. When specifying the attributes for this item, you should be able to choose pages in other page groups.

  • Copying page from one page group to another

    I need to copy one page or multiple from one page group DEV to page group TEST. I thought of using Portal Export/Import feature for the same, but it will ask for same page group at import.
    Requirement is to keep one set of page group for DEV stage, when it got completed move it to TEST page group in same instance.
    How we can achieve this functionality using single portal instance?
    Thanks & regards,
    Preet

    I did not understand this and isn't working for me. :(
    The message I receive when I click on the Copy link on the Navigator is:
    Click "Copy Here" next to the page under which you want to create a copy of your page. Click the link next to the page group to create the copy under the root page of the page group. You can create a copy of a page only under a page in the same page group as the original page.
    And it only displays the current page group with a tree structure of all the pages in the current page group (page group name being the root).
    Please help me on this as I have a similar requirement and am using 10.1.2 version of Oracle Portal.

Maybe you are looking for

  • WBS element field blank in MB51 report.

    Dear Experts, I m using ECC 6.00 EHP4, My problem is we issue the project material with movement type 221 Q but in MB51 report if I want to get the output with WBS element with Movement type 221 q data is not showing if I give only movment type 221 Q

  • Create Windows 8.x installation usb drive

    I have a Lenovo k410 desktop that started with Windows 8.0. Then I added the Windows 8.0 Professional Feature pack. Then the machines was upgraded to Windows 8.1. Now I need to run a Windows Repair (not refresh or reset) which requires a Windows Inst

  • Can offset presses actually do 1% increments of C or M or Y?

    When trying to achieve very bright colors, with no black, is it valid to move the other components in 1% increments: for example, 100*5*1*0? Or is that expecting a level of precision that is more than the press can actually deliver. Years ago I worke

  • How to remove photos from camera roll but remain in album?

    I want to delete photos that I have in camera roll but those same pics to remain in the album I create before. Any suggestions?

  • Short name

    How do you change the short name on the user accounts?