Posture Validation

Setting Network Access Restrictions for a User

You use the Network Access Restrictions table in the Advanced Settings area of User Setup to set NARs in three ways Apply existing shared NARs by name. Define IP-based access restrictions to permit or deny user access to a specified AAA client or to specified ports on an AAA client when an IP connection has been established. Define calling line ID Dialed Number Identification Service (CLI DNIS)-based access restrictions to permit or deny user access based on the CLI DNIS that is used. _ Note...

Enabling Password Aging for the ACS Internal Database

You use the Password Aging feature of ACS to force users to change their passwords under one or more of the following conditions After a specified number of days (age-by-date rules). After a specified number of logins (age-by-uses rules). The first time a new user logs in (password change rule). Varieties of Password Aging Supported by ACS ACS supports four distinct password-aging mechanisms Protected Extensible Authentication Protocol (PEAP) and Extensible Authentication Protocol-Flexible...

EAPTLS and ACS

ACS supports EAP-TLS with any end-user client that supports EAP-TLS, such as Windows XP. To learn which user databases support EAP-TLS, see Authentication Protocol-Database Compatibility, page 1-7. For more information about deploying EAP-TLS authentication, see Extensible Authentication Protocol Transport Layer Security Deployment Guide for Wireless LAN Networks at ACS can use EAP-TLS to support machine authentication to Microsoft Windows Active Directory. The end-user client may limit the...

PEAP and ACS

ACS supports PEAP authentication by using the Cisco Aironet PEAP client or the Microsoft PEAP client that is included with Microsoft Windows XP Service Pack 1. ACS can support the Cisco Aironet PEAP client with PEAP(EAP-GTC) only. For the Microsoft PEAP client in the Windows XP Service Pack 1, ACS supports only PEAP(EAP-MS-CHAPv2). For information about which user databases support PEAP protocols, see Authentication Protocol-Database Compatibility, page 1-7. When the end-user client is the...

About the ciscoavpair Radius Attribute

The first attribute in the Cisco IOS PIX 6.0 RADIUS implementation, cisco-av-pair, supports the inclusion of many AV pairs by using the following format where attribute and value are an AV pair supported by the releases of IOS implemented on your AAA clients, and sep is for mandatory attributes and asterisk (*) for optional attributes. You can then use the full set of Terminal Access Controller Access Control System (TACACS+) authorization features for RADIUS. Note The attribute name in an AV...

NAC Architecture Overview

Figure 14-1 shows the components of a typical NAC deployment. Figure 14-1 Components of a Typical NAC Deployment Figure 14-1 Components of a Typical NAC Deployment End-user or host Also known as the endpoint. The endpoint is a device such as a PC, workstation or server that is connected to a switch, access point, or router through a direct connection. In a NAC deployment, the host that is running the Cisco Trust Agent (CTA) application, collects posture data from the computer and from any...

EAP Configuration

EAP is a flexible request-response protocol for arbitrary authentication information (RFC 2284). EAP is layered on top of another protocol such as UDP, 802.1x, or RADIUS and supports multiple authentication types EAP-TLS (based on X.509 certificates) EAP-MD5 Plain Password Hash (CHAP over EAP) New extended EAP methods have been added to EAP for NAC EAP-TLV Carry posture credentials, adding posture AVPs, posture notifications. Status Query You can use this new EAP method for securely querying...

Cisco VPN 3000 ConcentratorASAPIX 7x Dictionary of Radius Vsas

ACS supports Cisco VPN 3000 ASA PIX 7.x+ RADIUS VSAs. The vendor ID for this Cisco RADIUS Implementation is 3076. Note Some of the RADIUS VSAs supported by Cisco virtual private network (VPN) 3000 Concentrators, Adaptive Security Appliance (ASA), and Project Information Exchange (PIX) 7.x+ appliances are interdependent. Before you implement them, we recommend that you refer to your respective device documentation. For example, to control Microsoft Point-to-Point Encryption (MPPE) settings for...

About Network Access Restrictions

A network access restriction (NAR) is a definition, which you make in ACS, of additional conditions that you must meet before a user can access the network. ACS applies these conditions by using information from attributes that your AAA clients sent. Although you can set up NARs in several ways, they all are based on matching attribute information that a AAA client sent. Therefore, you must understand the format and content of the attributes that your AAA clients sends if you want to employ...

Loading the ACS Internal Database from a Dump File

You can use the -l option to overwrite all ACS internal data from a dump text file. This option replaces the existing all ACS internal data with the data in the dump text file. In effect, the -l option initializes all ACS internal data before loading it from the dump text file. Dump text files are created by using the -d option. You must use the same password used to encrypt the dump files. You can use the -p option in conjunction with the -l option to reset password-aging counters. Note Using...

About Radius Authorization Components

Shared Radius Authorization Components (RACs) contain groups of RADIUS attributes that you can dynamically assign to user sessions based on a policy. Using the Network Access Profile configuration, you can map a policy type with set conditions, such as Network Device Groups and posture, to a shared RAC. In ACS, RACs contain attributes that can be specific to a single network service (also referred to as a network-access policy). The access policy can map from various groups and postures to a...

Types of PACs

ACS provisions supplicants with a PAC that contains a shared secret that is used in building a TLS tunnel between the supplicant and ACS. ACS provisions supplicants with PAC that have a wider contextual use. The following types of PACs are provisioned to ACS, as per server policies Tunnel (Shared Secret) PAC, user or machine Distributed shared secret between the peer and ACS that is used to establish a secure tunnel and convey the policy of what must and can occur in the tunnel. The policy can...

Configuring a Radius Token Server External User Database

Use this procedure to configure RADIUS Token Server external user databases. Before You Begin You should install and configure your RADIUS token server before configuring ACS to authenticate users with it. For information about installing the RADIUS token server, refer to the documentation included with your token server. To configure ACS to authenticate users with a RADIUS Token Sever In the navigation bar, click External User Databases. ACS lists all possible external user database types. The...

Downloadable ACLs

Downloadable per-user ACL support is available for Layer 3 network devices that support downloadable ACLs. These includes Cisco PIX security appliances, Cisco VPN solutions, and Cisco IOS routers. You can define sets of ACLs that you can apply per user or per group. This feature complements NAC support by enabling the enforcement of the correct ACL policy. When used in conjunction with NAFs, you can apply downloadable ACLs can differently per device, allowing you to tailor ACLs uniquely per...

Accounting Logs

Accounting logs contain information about the use of remote access services by users. By default, these logs are available in CSV format, with the exception of the Passed Authentications log. You can also configure ACS to export the data for these logs to an ODBC-compliant relational database that you configure to store the log data. Table 11-1 describes all accounting logs. In the web interface, all accounting logs can be enabled, configured, and viewed. Table 11-2 contains information about...

Preparing for ODBC Logging

The following procedure explains how to prepare for ODBC logging. After you have prepared for ODBC logging, you can configure individual ODBC logs. Step 1 Set up the relational database to which you want to export logging data. For more information, refer to your relational database documentation. Step 2 Set up a system data source name (DSN) on the computer that is running ACS. For instructions, see Configuring a System Data Source Name for an ODBC External User Database, page 13-43. Step 3...

ODBC Database

As with Windows user database support, you can use ACS ODBC-compliant relational database support to use existing user records in an external ODBC-compliant relational database. Configuring ACS to authenticate against an ODBC-compliant relational database does not affect the configuration of the relational database. To manage your relational database, refer to your relational database documentation. _ Note As with all other external databases that ACS supports, the ODBC-compliant relational...

Stateless Session Server Resume

To provide better support for server performance, load balancing and peer roaming to different servers, EAP-FAST supports the stateless-server session resume by using the short-lived Authorization PACs. Once a peer establishes a TLS session and is authenticated, the EAP server can provision it with a Tunnel PAC. The tunnel PAC can be used to establish a TLS session much more quickly than a normal TLS handshake. With the normal TLS session resume, the EAP server must maintain the TLS session...

LEAP Proxy Radius Server Database

For ACS-authenticated users who access your network via Cisco Aironet devices, ACS supports PAP based MAC Exception Handling, LEAP, and EAP-FAST (phase zero and phase two) authentication with a proxy RADIUS server. Other authentication protocols are not supported with LEAP Proxy RADIUS Server databases. This feature is useful if your own RADIUS-based user database can support MS-CHAP but not LEAP EAP-FAST. ACS manages the LEAP EAP-FAST protocol handling and forwards just the MS-CHAP...

System Performance Specifications

The performance capabilities of ACS are depend mostly on the Windows server it is installed on, your network topology and network management, the selection of user databases, and other factors. For example, ACS can perform many more authentications per second if it is using its internal user database and running on a computer that is using the fastest processor and network interface card available than if it is using external user databases and running on a computer that complies with the...

Microsoft MPPE Dictionary of Radius Vsas

ACS supports the Microsoft RADIUS VSAs used for MPPE. The vendor ID for this Microsoft RADIUS Implementation is 311. MPPE is an encryption technology developed by Microsoft to encrypt PPP links. These PPP connections can be via a dial-up line, or over a VPN tunnel such as PPTP. MPPE is supported by several RADIUS network device vendors that ACS supports. The following ACS RADIUS protocols support the Microsoft RADIUS VSAs Cisco VPN 3000 ASA PIX 7.x+ To control Microsoft MPPE settings for users...

Configuring Cisco Airespace Radius Settings for a User Group

The Cisco Airespace RADIUS parameters appear only when the following are true. You have configured A AAA client to use RADIUS (Cisco Airespace) in Network Configuration. Group-level RADIUS (Cisco Airespace) attributes in Interface Configuration > RADIUS (Cisco-Airespace). Cisco Airespace RADIUS represents only the Cisco VSAs. Interface Configuration will display IETF RADIUS and Cisco IOS PIX 6.x RADIUS attributes. You must configure the specific attributes manually. Note To hide or display...

Cisco IOS Dictionary of Radius Ietf

ACS supports Cisco RADIUS IETF (IOS RADIUS AV pairs). Before selecting AV pairs for ACS, you must confirm that your AAA client is a compatible release of Cisco IOS or compatible AAA client software. For more information, see Installation Guide for Cisco Secure ACS for Windows for information about network and port requirements. Note If you specify a given AV pair on ACS, the corresponding AV pair must be implemented in the Cisco IOS software that is running on the network device. Always...

Configuring Fail Open

You can configure fail open for errors that can prevent the retrieval of posture token from an upstream NAC server. If fail open is not configured, the user request is rejected. You can select whether to enable fail open for Audit Server for profiles that are associated with an audit server External Posture Validation Server for profiles that are associated with an External Posture Validation Server If you enable fail open, you will need to select the posture token to be granted when an error...

Enabling PEAP Authentication

This procedure provides an overview of the detailed procedures that are required to configure ACS to support PEAP authentication. Note You must configure end-user client computers to support PEAP. This procedure is specific to configuration of ACS only. Step 1 Install a server certificate in ACS. PEAP requires a server certificate. For detailed steps, see Installing an ACS Server Certificate, page 10-25. Note If you have previously installed a certificate to support EAP-TLS or PEAP user...

NAC Agentless Host

This template is used for access requests for NAC Agentless Hosts (NAH), also known as agentless hosts. These requests use EAP over UDP (EoU). Table 15-16 describes the Profile Sample in the NAH Sample Profile Template. Table 15-16 NAH Sample Profile Template Table 15-16 NAH Sample Profile Template ( 26 9 1 Cisco av-pair aaa service ip-admission) AND ( 006 Service-Type 10) Table 15-16 NAH Sample Profile Template (continued) Table 15-16 NAH Sample Profile Template (continued) Include RADIUS...

Backing Up ACS with CSUtilexe

You can use the -b option to create a system backup of all ACS internal data. The resulting backup file has the same data as the backup files that are produced by the ACS Backup feature found in the web interface. For more information about the ACS Backup feature, see ACS Backup, page 8-7. _ Note During the backup, all services are automatically stopped and restarted. No users are authenticated while the backup is occurring. On the computer that is running ACS, open an MS-DOS command prompt and...

Setting Cisco Airespace Radius Parameters for a User

The Cisco Airespace RADIUS parameters appear only if all the following are true AAA clients (one or more) are configured to use RADIUS (Cisco Airespace) in Network Configuration. Per-user TACACS+ RADIUS Attributes check box is selected under Interface Configuration > Advanced Options. User-level RADIUS (Cisco Airespace) attributes that you want to apply are enabled under Interface Configuration> RADIUS (Cisco Airespace). Cisco Airespace RADIUS represents only the Cisco Airespace proprietary...

Cisco Airespace Dictionary of Radius Vsa

Table C-6 lists the supported RADIUS (Cisco Airespace) attributes. In addition to these attributes, Cisco Airespace devices support some IETF attributes for 802.1x identity networking Tunnel-Private-Group-Id (81) ACS cannot offer partial support of IETF hence, adding an Cisco Airespace device (into the Network Configuration) will automatically enable all IETF attributes. Table C-6 Cisco Airespace RADIUS Attributes Table C-6 Cisco Airespace RADIUS Attributes Name of the user being authenticated....

Setting Bbsm Radius Parameters for a User

The Building Broadband Services Manager (BBSM) RADIUS parameters appear only if all the following are true AAA clients (one or more) are configured to use RADIUS (BBSM) in Network Configuration. Per-user TACACS+ RADIUS Attributes check box is selected under Interface Configuration > Advanced Options. User-level RADIUS (BBSM) attributes that you want to apply are enabled under Interface Configuration > RADIUS (BBSM). BBSM RADIUS represents only the BBSM proprietary attributes. You must...

User Defined Attributes

User-defined attributes (UDAs) are string values that can contain any data, such as social security number, department name, telephone number, and so on. You can configure ACS to include UDAs on accounting logs about user activity. For more information about configuring UDAs, see User Data Configuration Options, page 3-4. RDBMS Synchronization can set UDAs by using the SET_VALUE action (code 1) to create a value called USER_DEFINED_FIELD_0 or USER_DEFINED_FIELD_1. For accountActions rows...

Decoding Error Numbers

You can use the -e option to decode error numbers in ACS service logs. These error codes are internal to ACS. For example, the CSRadius log could contain a message similar to csRadius Logs RDs.iog RDs 05 22 2001 10 09 02 E 2152 4756 Error -1087 authenticating geddy - no NAs response sent In this example, the error code number that you could use csutii.exe to decode is -1087 c Program Fiies ciscosecure Acs vX.XXutiis csutii.exe -e -1087 csutii v3.0(1.14), copyright 1997-2001, cisco systems Inc...

Chapter 5Shared Profile Components

802.1X Example Setup 5-2 Network Access Filters 5-2 About Network Access Filters 5-3 Adding a Network Access Filter 5-3 Editing a Network Access Filter 5-5 Deleting a Network Access Filter 5-6 RADIUS Authorization Components 5-6 About RADIUS Authorization Components 5-7 Understanding RACs and Groups 5-7 Migrating Away from Groups to RACs 5-7 Vendors 5-7 Attribute Types 5-8 Before You Begin Using RADIUS Authorization Components 5-8 Enabling Use of RAC 5-9 Adding RADIUS Authorization Components...

Exporting User List to a Text File

You can use the -u option to export a list of all users in the ACS internal database to a text file named users.txt. The users.txt file organizes users by group. Within each group, users are listed in the order that their user accounts were created in the ACS internal database. For example, if accounts were created for Pat, Dana, and Lloyd, in that order, users.txt lists them in that order as well rather than alphabetically. Note Using the -u option requires that you stop the CSAuth service....