Figure 119 Common LDAP Configuration Parameters
Ai J '-J- J -Sim nilinn rhnrsrt n1 frnm lb IVtl ITiti- ttH-rTyp UintflfHlClut Cii uupLVkfci iTvjip Domain hli i ii , r n n F -X 'l'unliutiiJliiiii i fi J y_anH -Spff lyy E,T> AF Snrvm Sjpfliftrlfce ii-.fTffor r * LDAP, or DS, iaabM D , xt fof Droemy Senses., rrfwi io Mff gtuttn L.4--V. jmiJtat-s ri IX'AT u ri itifcair. uih u Hitrape ftrtrtonr Sowf tf l ir > an Fitna tabk I drcct Mdbetttlb i by firme --mar. not i < IV*i r s i tI3 ai raa loiri *vl 4> fsL< Wui Cri...
Testing Your Configuration
Now that you have configured some users and a NAS, you are ready to test your configuration. The way to test AR locally without configuring an AAA client is to use a utility called radclient. The radclient utility uses the default Clients entry in AR of 127.0.0.1. The radclient utility simply creates and sends a RADIUS packet to AR. The following step sequence creates an Access-Request packet for user john with password john and the packet identifier p001. It displays the packet before sending...
Acknowledgments
There are so many people that I regard as my reason for this book. I would not feel right without mentioning them and how much each one of them has inspired me in some way or another. Ascolta Training Company, for your support along the way, especially Irene Kinoshita, Ted Wagner, William Kivlen, Jack Wood, Kevin Masui, Dennis Ogata, Colby Morita, Ann Mattair, Karl Homa, Chris Smith, Hilson Shen, Fred Cutaran, Randi Rubenstein, John Rauma, and the rest of the gang The Verizon Gang, especially...
Configuring the Radius Server
At the top level of AR is the Administrator object that you just configured and the Radius object. The Radius object specifies the name of the server and other parameters that are related to the way AR handles user requests. In configuring this site, you need to change only a few of these properties. This section of the chapter shows you how to configure some basic RADIUS parameters for AR. Step 1. Change to the Radius object, as seen in Example 155. localhost Radius Name Radius Description...
Tacacs Format and Header Values
The TACACS+ ID defines a 12-byte header that appears in all TACACS+ packets. This header is always sent in clear text format. The following defines the TACACS+ ID fields, which are also shown in Figure 2-1 Major_version This is the major version number of TACACS+. The value appears in the header as TAC_PLUS_MAJOR_VER 0xc. Minor_version This field provides revision number for the TACACS+ protocol. It also provides for backward compatibility of the protocol. A default value, as well as a version...
Figure 1112 Successful ODBC Database Configuration Screen
J -** Jt -jy J - J < ** MiKJftiVG.fr I.WOU' iutttLibaif tmntxbzS '< 11-,-jl < ofr.> j ci ri . h iCIWIK L'HAP-'ANAP A--1 -Jii jiacr. ipfAPSUl IWnHm, - Svnin tTLS tftlMUltlI EAE3)k6 *y C-. MX HiAibcn icf DSO- iiT lirir'liU i rr iii-Li--.rr tkU Ox bjU. blfenc lil 'JjtfiJ u iCnJigirA Ig -.rrr-J cirmmiAfli rfli ygir ODEiC-coqiji * reluMulusrr itwkw Note that this cannot be successful unless the ODBC drivers are properly configured. After the ODBC drivers are configured, you...
Figure 1111 External ODBC Database Parameters
J**'1- cr J V J- - _' i UrifSriiirr ODBC AMMtsflm OnI tHr-*t *rt. Sj ttm DSN D5i< UMMK DSN F'*tlWUnl DSN C*tuMcaon K bi* . ODBC Yiniinr rhrp Js DSN VaKtA iirTjfpB Room de 3 Suppini PAP auriifiuvfiiHii PAP SQL IYKcdtu - IcsiTTAutiUs .Pot ' Suppuil iHAf ES riS.-U' AHA 1 JM i tacit *b an r Suppen EAP-TI.S g wiu c3iwii EAP SQL Piou-duio C5NTF fthM S ggort j ' KAjyji 1 ii C HAPAK AJ AgJ tWdjl tlm ta-ij*Ft MEUS .Nm nr nar, lA & L ftacfj tti* Crnigjie 0-r -n MniMisn for you C- d 1- itfeti...
Figure 1115 Configuring Radius Token Server Parameters
Y.l.i . _> Qfwfi J V J I FfM TilS ScVtt iurft t H VJ , JV.-.Jin Ink' Strvrrnfwjra'w . KAIMIG ( hfamqMi i lAi'.WK'-M.r i'uiiiuiuifliiiii Ute p-jfi* 6--- (- girr Cor - Sf ewe ACS M dbr Kite vwn weh. i ifiSTfc. token serrer ihK a RADIUS tiubki Ell K F jiX lJL- C t & jHiHi* li Jr, pcemit JiA JD q la rnJrk C ftO t ACS t* BiTWK RADIUS 1cOwn J ver driabjee i Thn n-y SVr-rir imi' II -Tjf < hp ltianr oi If1 iiirij of h jimwT RAP'PJS rtr Swendkiy Stn HuniAP Tyj* tbe toeb ta* U' hi ofcb tenday...
Note
The significance of these possible message types is that TACACS+ has the ability to perform authentication, authorization, and accounting as separate functions. RADIUS does not have this capability. Seq_no This determines the sequence number for the current session. TACACS+ has the ability to perform multiple TACACS+ sessions or to use one TACACS+ session per AAA client. The beginning packet of a session is identified by the sequence number 1. All subsequent packets are an increment from that...
Figure 1114 LEAP Proxy Radius Server Configuration
J J ) to*ch ,J J - J , I'.-- -, St i . i-i .V.imr 1 1 i f ifiifr& BI ftfMidi) 1 H> lri> t I ftiifc IPi TT rrtir fmhrrlrrl > H*k. - . J J ) to*ch ,J J - J , I'.-- -, St i . i-i .V.imr 1 1 i f ifiifr& BI ftfMidi) 1 H> lri> t I ftiifc IPi TT rrtir fmhrrlrrl Ttf ths r.- j rriif i- IP ri n c tfc piimiy Tjpt tti tr-ifriWTi EP iddkVII dw KCrfriuy RADIUS ioru.
Using Remote Accounting
When you deploy proxy in your network and you are using a Proxy Distribution Table, you increase the amount of accounting that you can do within your network. You can use accounting in the distributed system in three ways You can log accounting information locally. You can forward accounting information to the destination AAA server. You can log accounting information locally and forward a copy to the destination AAA server. The benefits of remote accounting are that the remote AAA server logs...
Categories of aregcmd Commands
The aregcmd CLI commands are entered after you are logged onto the AR cluster. To log in to the cluster, you actually invoke the aregcmd CLI. The commands can be grouped into the categories discussed in the following sections. These commands navigate within the Cisco AR hierarchy commands include cd, ls, pwd, next, prev, filter, and find. We discuss the first three in detail. The cd and ls commands were already discussed however, let's recap. The cd command simply allows you to move through the...
LEAP Proxy Radius Server
J2 For Cisco Secure ACS-authenticated users accessing your network via Cisco Aironet devices, Cisco Secure ACS supports ASCII, PAP, MS-CHAP (versions 1 and 2), and LEAP authentication with a proxy RADIUS server. Other authentication protocols are not supported with LEAP Proxy RADIUS Server databases. Cisco Secure ACS uses MS-CHAP version 1 for LEAP Proxy RADIUS Server authentication. To manage your proxy RADIUS database, refer to your RADIUS database documentation. Lightweight Extensible...
Backing Up the Cisco Secure Database
Another important aspect of maintaining your ACS configuration is to perform frequent database backups of the ACS database. This section covers the steps needed to perform manual backups, schedule backups, cancel scheduled backups, and recover ACS from a backup. Under the umbrella of database backup, you have the following options Schedule a backup to take place at periodic intervals, or at a given time Database backups are performed from the System Configuration subsection ACS System Backup...
VASCO Token Server
To configure ACS to work with a VASCO Token Server, begin with the following steps Step 1. From External User Databases, select Database Configuration. Step 2. Select VASCO Token Server. Step 3. Select the Create New Configuration button. Step 4. Enter a name for your new configuration. To configure the database parameters, follow these steps Step 1. Select the Configure button. Step 2. Enter the primary server name IP. Step 3. Enter the secondary server name IP. Step 4. Enter the shared...
Microsoft Radius VSAs
Microsoft Point-to-Point Encryption MPPE is an encryption technology developed by Microsoft to encrypt point-to-point PPP links. These PPP connections can be via a dialup line or over a VPN tunnel such as PPTP. MPPE is supported by several RADIUS network-device vendors that Cisco Secure ACS supports. The following Cisco Secure ACS RADIUS protocols support the Microsoft RADIUS VSA Additional Description If Necessary Signifies whether the use of encryption is allowed or required. If the Policy...
Nortel RADIUS
Table A-7 lists the Nortel RADIUS VSAs supported by Cisco Secure ACS. The Nortel vendor ID number is 1584. ipaddr maximum length 15 characters ipaddr maximum length 15 characters ipaddr maximum length 15 characters ipaddr maximum length 15 characters ipaddr maximum length 15 characters
Aregcmd Syntax
We said that the aregcmd command when invoked from the Solaris command line accesses the CLI that AR commands are entered into. The commands entered into aregcmd are not case sensitive and just like the Cisco IOS provide some context-sensitive help and command completion using the Tab key. If the command element that you are requesting is unique, you have to enter only a portion of the command for it to execute. Also, the aregcmd commands are command-line order dependent. This means the...
Using aregcmd to Configure AR
To configure AR, you use the aregcmd command-line interface CLI . Accessing this CLI allows you to enter commands directly into AR. When using aregcmd, you need to know a few important commands. First off, you can think of aregcmd as a modified UNIX command line. You can use the UNIX command cd to change directories, or in the case of AR, configuration objects. You can use the UNIX command ls to list the elements in your current location of AR. To back out of a configuration object, use cd...

