Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Changing access list on virtual-access interface?

Reply
Thread Tools

Changing access list on virtual-access interface?

 
 
Yehavi Bourvine
Guest
Posts: n/a
 
      08-25-2004
Hello,

I would like to do some processing on our dialin users (modems & ADSL) by
implementing the following mechanism:

- The user dials-in, authenticates, and then granted a limited access
(via an interface access list).

- After we are done our checks (some client-server application running from our
control center to the home user) I would like to change his access rights
by changing (or removing) the access list.

The problem is that we are using virtual templates from which each user gets a
virtual-access interface; it is not possible to change an access list on this
specific virtual-access interface.

Any idea how can I implement such a thing easily? We are using a home-built
Tacacs+ server (based on one of the early public implementations of it).

Thanks! __Yehavi:
 
Reply With Quote
 
 
 
 
Hansang Bae
Guest
Posts: n/a
 
      08-26-2004
In article <2004Aug25.133849@hujicc>, says...
> Hello,
>
> I would like to do some processing on our dialin users (modems & ADSL) by
> implementing the following mechanism:
>
> - The user dials-in, authenticates, and then granted a limited access
> (via an interface access list).
>
> - After we are done our checks (some client-server application running from our
> control center to the home user) I would like to change his access rights
> by changing (or removing) the access list.
>
> The problem is that we are using virtual templates from which each user gets a
> virtual-access interface; it is not possible to change an access list on this
> specific virtual-access interface.
>
> Any idea how can I implement such a thing easily? We are using a home-built
> Tacacs+ server (based on one of the early public implementations of it).



The first part is easy. Just use Lock & Key ACL.

http://www.cisco.com/univercd/cc/td/...os122/122cgcr/
fsecur_c/ftrafwl/scflock.htm

Not sure if I can help you with the second requirement though.
--

hsb

"Somehow I imagined this experience would be more rewarding" Calvin
*************** USE ROT13 TO SEE MY EMAIL ADDRESS ****************
************************************************** ******************
Due to the volume of email that I receive, I may not not be able to
reply to emails sent to my account. Please post a followup instead.
************************************************** ******************
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Changing style of the numbers in a CSS <ol> without changing the style of the <li> Aaron Beall HTML 2 09-14-2007 08:07 PM
403 Forbidden: You were denied access because: Access denied by access control list Southern Kiwi NZ Computing 6 03-19-2006 05:19 AM
changing file extension without changing filename jamy Computer Support 4 03-04-2005 01:03 AM
I'd like to know about the difference of between access-list and ip access -list. PS2 gamer Cisco 6 06-09-2004 01:37 PM
Difficulty in changing the Connection Server control path changing ... Samridhi Kumar Shukla ASP .Net 1 11-30-2003 02:31 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57