Restrict access to specific network devices

Is there a way through ACS to limit user logons to only specific devices? I know through NAR, I can restrict the source address, but how can I restrict the destination?
Thanks

I'm having the same problem.
The ACS in NAR is mandatory to use a AAA Client plus the client and I would like to limit only by the AAA client.
It means, the ACS uses the attributes
Calling-station-ID (Final client)
Called-station-ID (Network Access Server NAS)
I would like to limit only based on Called station.
If you get somehow to solve it please post here.
Thanks

Similar Messages

  • HT201304 Is it possible to restrict access to specific IOS apps based on the WIFI profile that a user has connected to?

    Is it possible to restrict access to specific IOS apps based on the WIFI profile that a user has connected to?

    you might be able to block it if the app uses Internet access
    and depending on your wireless you might be able to block a specific user
    accessing the backend host that the app uses
    some firewalls offer application filtering but I'm not aware of any that work with ios apps

  • HT1178 How do I restrict access to my network to mac addresses?

    I am setting-up a new Time Capsule and wish to restrict access to my wireless network to only those mac addresses of my equipment.  I can't find instructions on how to do this.  Any help in pointing me to the correct resource would be appreciated.

    Suggest that you check the Help area in AirPort Utility for instructions.
    Open AirPort Utility
    Click the Help menu at the top of the screen
    Click AirPort Utility Help
    Wait for Help to load
    Click Setting up a Wi-FI network on the left side of the main page
    Click Control when a user can access your network
    Click Control access to your wireless network

  • Error 23002 when restricting access to specific TS

    I am a bit stumped at the moment on my TSGW.  I am attempting to restrict which Terminal Servers the TSGW will redirect to.
    I am doing this via RAP > Network Resource > "RD Gateway-managed group"
    I created a new group and added the FQDN of the TS I want to connect to and I was unable to connect (received error 23002)
    I then modified the group to use the IP address of the TS and received the same error.
    I then set the Network Resource option in RAP to "Allow users to connect to any network resource" and I was able to connect.  I naturally don't want to do this and want to restrict access as we have other Terminal Servers for other groups.
    I must be missing something, but I am not sure what.  Any thoughts from anyone?

    OK... I may have solved my own issue here.  Sometimes typing it out makes me think...
    One thing I didn't try was the NetBIOS name within the RD Gateway-managed group.
    I entered the 3 entries:  IP/FQDN/NetBIOS  and things came alive.  Now, I shouldn't need all three, so I will need to do some more checking, but at least I'm now in the right direction.

  • HT2688 How do I restrict access to *specific* songs (or give access to a specific playlist) in Home Sharing

    http://support.apple.com/kb/HT2688?
    This article describes two different things:
    Music Sharing and
    Home Sharing
    Music Sharing allows you to select playlist(s) to share, and allows you to play the song from another device. It does *not* allow you to transfer the song to another device.
    Home Sharing allows you to share your ENTIRE music library and transfer the songs to another device. It does not allow you to restrict the share to a specific playlist(s).
    Try it. You can set a password and check the boxes to restrict your playlists, but that only restricts while Home Sharing is turned off. EVERY file is accessible when you have Home Sharing running.
    I have a bunch of music I don't want my kids listening to. I've created a playlist for them, and I want them to be able to load their ipods with music from that list without accessing other music.  Any ideas?

    say suppose i have no control over wcf client. so i want to do it at client side. so what is your suggestion. thanks
    If you can't  implement role based secuirty on the client-side, the you may want to look at what is in the link.
    http://blog.clauskonrad.net/2010/04/wcf-restrict-which-clients-can-call.html

  • Disabling DataSocket Access to Specific Network Connection

    Hi Group,
    I have DataSocket server running on a PC with two active LAN connections (2 x Network cards).  The main connection is to our corporate LAN/WAN.  The secondary connection is to a fixed set of several computers for our monitored process.
    The way the system is currently configured, the Datasocket server broadcasts datasocket data to both connections.  For this application I want to disable data broadcast on the Corporate LAN while retaining it on the secondary LAN system.
    Is there a setting in Datasocket Server that I can use to prevent it from broadcasting to the primary network connection?
    Is there some other solution (eg. Port blocking) etc that I can use that may be more suitable to this requirement?
    Any advice is appreciated,
    Thanks,
    Laurie

    Hello,
    I don't think I understand exactly the functionality you are looking for.  Is it that you would like DataSocket to be available on the LAN, but not to someone who imitates a valid IP address?  This would be tricky, because it comes down to a network security problem I guess.  The server can be launched and configured programmatically; would it be possible to monitor and change the number of allowed connections to restrict imitations?  That is, you could have an application which allowed a user to login... if they login, they get access and you increment the number of allowed connections.  When they logout, you would decrement the number of allowed connections.  This way you would at least have the added security feature that a user would have to know certain login parameters in order to gain access, and not simply connect a PC to the network.  i realize there would be some details to deal with if this is even sufficient, but perhaps you can comment on the plausibility of this, and perhaps clarify precisely what network activity you would like to restrict!
    Thank you, and I hope we can find a clean solution to this problem!
    Best Regards,
    JLS
    Best,
    JLS
    Sixclear

  • DBLINK - restrict access to specific objects

    I have created private DBLINK to connect to a particular user. I want to restrict only select access to only selected tables under that schema?. Could someone let me know how to restrict the access?.

    Boochi wrote:
    I have created private DBLINK to connect to a particular user. I want to restrict only select access to only selected tables under that schema?. Could someone let me know how to restrict the access?.Create a new schema (on the remote database), grant SELECT on only the tables you want to allow access to. Create the private DB link to the new schema.

  • Restricting access to unknown networks.

    I am configuring school district iPads.  I would like the iPads to ONLY connect to the schools district's secure network.  What setting controls which networks they can log into?  I already have the profile allowing them to the schools district's secure network.  I am trying to exclude all others such as public networks at star bucks.  This would reduce the desire to steal the i pads. 

    Hi Doug,
    No, the Data Mart itself is unaware of the user who is accessing data.It is possible to permission reports, and data mart access, but not the data in the data mart.

  • EA6400 - Unable to access other local network devices

    This is odd and it just recently started acting this way.  No, I didn't have any configuration changes recently.
    I have an EA6400 wireless router.  Many devices are connected to it via Wireless (2 iPhones/2 iPads/3 Blu-Ray Players/1 Ubuntu laptop/1 Windows XP Laptop/1 Windows 8 desktop/1 Ubuntu Server/1 Epson Printer/1 Ubuntu Workstation).  Now prior to last night I didn't have any problems, wife had been printing from Windows 8 to Epson all day.  Sometime last night, she stopped being able to print to the Epson.  I looked, sure enough, error printing. 
    Here's some more details:
    All device are DHCP.  EXCEPT for the following 3 static devices:  Ubuntu Server, Epson Printer, Ubuntu Workstation
    Tried pinging the Epson from Windows 8, no go.  Tried pinging the router from Win8, no problem.  Ping www.google.com from Win8, no problem.  Ping Ubuntu server from Win8, no go.  Ping Epson from Ubuntu server, no go.  Ping Win8 from Ubuntu, no go.  Ping iPad from Win8, no problem. Ping iPhone from Win8, no problem.  Ping Ubuntu from WinXP laptop, no go.  Ping Epson from WinXP laptop, no go.  Ping from router to Win8, no problem.  Ping from router to Ubuntu server, no problem, ping from router to Epson, no problem.
    Wireshark of Win8 shows ping ARP request and reply for pings to iPad/iPhone.
    Wireshark of Win8 shows ping ARP Who Has request for pings to Epson, but no responses back.
    What the heck is going on?  No Windows firewall issues, I turned off Windows firewall for testing and still had the problems.
    Any ideas?  The EA6400 has the Smart WiFi software which makes it difficult to troubleshoot things on the router itself.

    it usually occurs with older devices which do not support 5ghz. glad you got it sorted.
    Cheap Homeowner Loans London UK

  • Is there any way to bind CoreMidi to a specific network device?

    Currently, I have my iMac connected via ethernet to a wireless bridge (to get to the rest of the LAN).
    I want to use some iPad/iPhone apps which use networked CoreMidi.
    So, I enable AirPort, set up an ad hoc network on the Mac (via Create Network in the Airport menu).  When I try to set up a networked MIDI controller, I can never connect.  If I reboot without the ethernet cable connected, everything works fine.
    I'd like to be able to run both at the same time, so is there any way to force CoreMidi to bind to the Airport rather than ethernet?

    The songs from the Sony MP3 player need to be imported into your iTunes library first before they can be synced or added to your iPod Classic. 
    Regarding the songs that didn't import into iTunes, what format are they in and what seems to be different from them compared with the tracks that did import?
    B-rock

  • Features supported by RT engine on specific network devices RT0001

    when i enter RT0001 info code on site www.ni.com/info
    the browser does not display these info.please f some
    have these RT0001 notes provide me.
    regard

    zalmay,
    Thank you for letting us know that this info code is not working. 
    The issue has been reported to our web team.  You can find a lot
    of information on all of our Real-Time products at ni.com/realtime. 
    Doug M
    Applications Engineer
    National Instruments
    For those unfamiliar with NBC's The Office, my icon is NOT a picture of me

  • Restricting Access To Specific Groups

    Can security be set such that a portal administrator can only edit individual profiles under a select group? How do I do this?

    Look at following 9026 plsql API doc link for usage of wwsec_api.remove_group_acl
    http://portalstudio.oracle.com/pls/ops/docs/FOLDER/COMMUNITY/PDK/PLSQL/DOC/PLDOC_9026/wwsec_api.html

  • How do I restrict access to 4 devices using ACS

    Currenlty in our ACS we have Group A configured to have access to all network devices-f with ull privilege level 15 access to all devies
    We are now trying to implement 4 new users, however we only want them
    to have access to 4 devices-routers (4 IP addresses)-and only have
    basic level 1 functions in the router
    Is this done under Network Access Filter or Network Access Group?
    Do I need to create a new group or can I somehow implent that into

    I'm using ACS v 4.2 on windows server-TACACS
    Under NAF I have configured the IP's of the server I want them to access under Selected Items
    Under NAR I have permitted calling point
    with the NAF and  *  *
    Under the Group Settings
    Network Access Restrictions (NAR)
      Shared Network Access Restrictions
    Only Allow network access when
    All selected NARs result in permi
    all selected NARs result in permit..with the NAR i just configured in the selected NAR list

  • F_LFA1_BEK - access to specific vendor

    Hello,
    my first posting....hope someone has an answer...
    We need to give 2 users transaction FBL1N (vendor line items) with only access to 2 specific vendors.
    As far as we know there is no authority object for the vendor account number itself.
    So we thought we can use object F_LFA1_BEK. We entered an  authorization group (LFA1-BEGRU) to this 2 vendors and added this group to F_LFA1_BEK. So far so good.
    Problem is now that it is still possible to access all vendors where no authorization group is maintained in the vendors master record. (No authorization group is the default case and it is not possible to add another one the other vendors)
    Is it possible to achieve this with F_LFA1_BEK or is there any other solution? 
    Thanks a lot!
    Christian

    Hi Alex,
    of course it is possible to do it that way and we already use the LFB1-BEGRU to restrict access to specific vendors.
    But we have a lot of different accounting groups and a lot of users who create/maintain vendors each being responsible for one or more accounting groups. And furthermore this is relevant for 2 company codes.
    And what I haven't mentioned yet: This also needed for customers (FBL5N).
    So you are right it is possible and it is the standard way but in our case currently too much effort.
    Thanks.
    Christian

  • How do I restrict wireless network access to specific devices/computers, using an Airport Extreme, when the WPA2 password is able to be found by other devices?

    I have set up a wireless network in my office using a couple of Airport Extremes, and, for some reason, our Windows computers are able to view the password of the network. Well, given that we employ teenagers, you can imagine what happens when they all find out the password. We want to restrict network access to only those devices we deem necessary. How do I accomplish this?

    SidMed wrote:
    We need 18-20 devices to access, all wirelessly.
    You can keep using your Apple routers as AP devices.. but get a router running a secure OS as the actual router that controls the network..
    If you have 18-20 teens on the network.. then setting quota and restrictions on bandwidth is far more important than time..
    Gargoyle on a cheap router can do it.. eg WNDR3800 or the newer W1024ND v2.
    Simply turn off the wireless in these devices.. and use the ethernet connection to the airport as WAP.
    Honestly you just will never get the security or control using apple domestic routers.

Maybe you are looking for

  • Calculate measures in DW or Cube

    Our OLTP data source contains multiple measurement records for a single day from multiple sites (date time stamped) Our DW has granularity of a day (Year - Quarter - Month - Week - Day) If we are interested in the average value of each measurement fo

  • TS1717 2 months ago, my iTunes dj (on my PC) lost its ability to "Shuffle"   (I cannot get shuffle on) as well as its shuffle function.  Anyone out ther know how to fix this?

    2 months ago my iTunes dj (0n my ASUS PC) lost its ability to shuffle.  It will not allow me to turn "shuffle" on, and "refresh" does not work either.

  • Latest itunes version

    HELP PLEASE !!! I upgraded to the latest itunes version a couple of days ago and getting desperate doing the most simple things, like putting a playlist together . Everthing is so unnecessarly complicated  For example, before, when i needed a special

  • Connection with Netweaver and ECC6 how to??

    Hi SDNers I am doing research at the possibilities of SAP Netweaver CE 7.1, I want to set up a small "Live Demo" where my netweaver is connected with my ECC6 For example, i made a process with some validations where i want to insert new employee data

  • Olsoidsync error

    I noticed in our OID environment, using the oidadmin tool I can see several users. But in our client DB, the lbacsys.lbac$user table does not have all these users. So, I tried using the olsoidsync tool but it failed with a java sqlexception error: or