Cisco Systems OL-24201-01 Camera Accessories User Manual


 
2-6
User Guide for Cisco Secure Access Control System 5.3
OL-24201-01
Chapter 2 Migrating from ACS 4.x to ACS 5.3
Functionality Mapping from ACS 4.x to ACS 5.3
Command sets (command
authorization sets)
One of the following:
Shared Profile
Components >
Command
Authorization Set
User Setup page
Group Setup page
Policy Elements > Authorization
and Permissions > Device
Administration > Command Set
See Creating, Duplicating, and
Editing Command Sets for
Device Administration,
page 9-28.
You can add command sets as
results in authorization policy
rules in a device administration
access service.
Shell exec parameters User Setup page System Administration >
Dictionaries > Identity >
Internal Users
See Managing Dictionaries,
page 18-5.
Defined identity attribute fields
appear in the User Properties
page.
You can use them as conditions
in access service policies.
Shell profiles (shell exec
parameters or shell command
authorization sets)
Group Setup page Policy Elements > Authorization
and Permissions > Device
Administration > Shell Profile
See Creating, Duplicating, and
Editing a Shell Profile for
Device Administration,
page 9-23.
You can add shell profiles as
results in authorization policy
rules in a device administration
access service.
Date and time condition (Time
of Day Access)
You cannot migrate the date
and time conditions. You have
to recreate them in ACS 5.3.
Group Setup page Policy Elements > Session
Conditions > Date and Time
See Creating, Duplicating, and
Editing a Date and Time
Condition, page 9-3.
You can add date and time
conditions to a policy rule in the
Service Selection policy or in an
authorization policy in an access
service.
RADIUS Attributes One of the following:
Shared Profile
Components >
RADIUS
Authorization
Component
User Setup page
Group Setup page
You cannot migrate the
RADIUS attributes
from user and group
setups. You have to
recreate them in ACS
5.3.
Policy Elements > Authorization
and Permissions > Network
Access > Authorization Profile >
Common Tasks tab
or
Policy Elements > Authorization
and Permissions > Network
Access > Authorization Profile >
RADIUS Attributes tab
See Creating, Duplicating, and
Editing Authorization Profiles
for Network Access, page 9-18.
You configure RADIUS
attributes as part of a network
access authorization profile.
You can add authorization
profiles as results in an
authorization policy in a network
access service.
Table 2-1 Functionality Mapping from ACS 4.x to ACS 5.3 (continued)
To configure... In ACS 4.x, choose... In ACS 5.3, choose... Additional information for 5.3