06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Network <strong>Access</strong> Profiles Pages Reference<br />

Authorization Rules <strong>for</strong> profile_name<br />

14-50<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Chapter 14 Network <strong>Access</strong> Profiles<br />

Use this page to list the set of authorization rules <strong>for</strong> a Network <strong>Access</strong> Profile.<br />

To display this page, click Authorization in the Network <strong>Access</strong> Profiles Page, page 14-39.<br />

Table 14-27 Authorization Rules <strong>for</strong> profile_name<br />

Field Description<br />

Condition<br />

<strong>User</strong> Group The ACS group to which the user was mapped. This field defines the group of users <strong>for</strong> this rule. If you are<br />

not basing authorization rules on authentication, select Any.<br />

System<br />

Posture Token<br />

Action<br />

The posture token that was returned as a result of posture validation. ACS checks the token status be<strong>for</strong>e<br />

proceeding to follow the configured actions. You can use posture tokens to validate user groups. If you are<br />

not using posture validation, select Any.<br />

Deny <strong>Access</strong> Denies access <strong>for</strong> requests that do not match any configured policy.<br />

Shared RAC The list of RACs defined in the Shared Profile Components > RADIUS Authorization Components option.<br />

Note If you configure an external posture validation audit server to use session-timeout settings in the<br />

Authorization policy, you must select a shared RAC. See Configuring Policies, page 13-15 and<br />

External Posture Validation Audit Setup Pages, page 13-36.<br />

Downloadable The list of downloadable ACLs defined in Shared Profile Components > Downloadable IP ACLs.<br />

ACL<br />

If a condition A default action when a matched condition is not found.<br />

is not defined<br />

or there is no<br />

matched<br />

condition:<br />

Include<br />

RADIUS<br />

attributes from<br />

user's group<br />

Include<br />

RADIUS<br />

attributes from<br />

user record<br />

Enable to use RADIUS attributes per user’s group.<br />

Enable to use RADIUS attributes per user record.<br />

Related Topics<br />

Configuring an Authorization Rule, page 14-36<br />

Configuring a Default Authorization Rule, page 14-37<br />

OL-14386-02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!