Configure Shared Profile Components
The Shared Profile Components section enables administrators
to develop and name reusable, shared sets of authorization components, which
might be applied to one or more users, or groups of users, and referenced by the
assigned name within their profiles. These include network access restrictions
(NARs), command authorization sets, and downloadable PIX ACLs.
-
NARs enable the administrator to define additional
authorization conditions that must be met before a user can gain access to the
network.
-
Command authorization sets provide a central mechanism to
control the authorization of each command on each network device.
-
Downloadable PIX ACLs enable the creation of an ACL once, in
Cisco Secure ACS, and then load that ACL to any number of PIX firewalls that
authenticate using the Cisco IOS/PIX protocol.
These shared profile components enhance the scalability of
the selective authorization feature. Shared profile components, once configured,
can be applied to many users or groups, and they eliminate having to configure
the authorization explicitly for each user group for each possible command on
each possible device.