Re: Security: how to correlate services to users ?

From: Carlos G Mendioroz <tron_at_huapi.ba.ar>
Date: Wed, 01 May 2013 17:44:32 -0300

Trying to: have local database with one user able to access management
(i.e. local exec) and other able to use webvpn.

I guess ACS 5 with service selection rules would do, with the policy
being defined at the ACS instead of at the service.

-Carlos

Thomas Perrier @ 01/05/2013 16:10 -0300 dixit:
> Hi Carlos,
>
> It's unclear to me what you're precisely trying to do, but have you looked
> at ACS 5.x's service selection rules?
>
> -Thomas
>
>
> On Mon, Apr 29, 2013 at 3:25 PM, Carlos G Mendioroz <tron_at_huapi.ba.ar>wrote:
>
>> Hi,
>> I've run a couple of times into a situation where you have more than one
>> service at a gateway and different sets of users.
>>
>> Classic is management users and remote access users.
>>
>> What are the options to have this implemented ? Is there a way to have
>> multiple "local" databases ? Or to mark the tacacs request to indicate a
>> given set of users is intended ?
>>
>> I've resorted to multiple tacacs servers, or tacacs and local, but is
>> cumbersome...
>>
>> Appreciate any hints.
>> -Carlos
>> --
>> Carlos G Mendioroz <tron_at_huapi.ba.ar> LW7 EQI Argentina
>>
>>
>> Blogs and organic groups at http://www.ccie.net
>>
>> _______________________________________________________________________
>> Subscription information may be found at:
>> http://www.groupstudy.com/list/CCIELab.html
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
>
>
>
>
>
>
>

-- 
Carlos G Mendioroz  <tron_at_huapi.ba.ar>  LW7 EQI  Argentina
Blogs and organic groups at http://www.ccie.net
Received on Wed May 01 2013 - 17:44:32 ART

This archive was generated by hypermail 2.2.0 : Mon Jun 03 2013 - 06:34:34 ART