Identifying AAA Server Groups and Servers

If you want to use an external AAA server for authentication, authorization, or accounting, you must first create at least one AAA server group per AAA protocol and add one or more servers to each group. You identify AAA server groups by name. Each server group is specific to one type of server: Kerberos, LDAP, NT, RADIUS, SDI, or TACACS+.

The security appliance contacts the first server in the group. If that server is unavailable, the security appliance contacts the next server in the group, if configured. If all servers in the group are unavailable, the security appliance tries the local database if you configured it as a fallback method (management authentication and authorization only). If you do not have a fallback method, the security appliance continues to try the AAA servers.

To create a server group and add AAA servers to it, follow these steps:

Step 1 For each AAA server group you need to create, follow these steps:

a. Identify the server group name and the protocol. To do so, enter the following command:

hostname(config)# aaa-server server_group protocol {kerberos | ldap | nt | radius | sdi | tacacs+}

For example, to use RADIUS to authenticate network access and TACACS+ to authenticate CLI access, you need to create at least two server groups, one for RADIUS servers and one for TACACS+ servers.

You can have up to 15 single-mode server groups or 4 multi-mode server groups. Each server group can have up to 16 servers in single mode or up to 4 servers in multi-mode.

When you enter a aaa-server protocol command, you enter group mode.

b. If you want to specify the maximum number of requests sent to a AAA server in the group before trying the next server, enter the following command:

hostname(config-aaa-server-group)# max-failed-attempts number

The number can be between 1 and 5. The default is 3.

If you configured a fallback method using the local database (for management access only; see the "Configuring AAA for System Administrators" section on page 40-5 and the "Configuring TACACS+ Command Authorization" section on page 40-11 to configure the fallback mechanism), and all the servers in the group fail to respond, then the group is considered to be unresponsive, and the fallback method is tried. The server group remains marked as unresponsive for a period of 10 minutes (by default) so that additional AAA requests within that period do not attempt to contact the server group, and the fallback method is used immediately. To change the unresponsive period from the default, see the reactivation-mode command in the following step.

If you do not have a fallback method, the security appliance continues to retry the servers in the group.

c. If you want to specify the method (reactivation policy) by which failed servers in a group are reactivated, enter the following command:

hostname(config-aaa-server-group)# # reactivation-mode {depletion [deadtime minutes] | timed}

Where the depletion keyword reactivates failed servers only after all of the servers in the group are inactive.

The deadtime minutes argument specifies the amount of time in minutes, between 0 and 1440, that elapses between the disabling of the last server in the group and the subsequent re-enabling of all servers. The default is 10 minutes.

The timed keyword reactivates failed servers after 30 seconds of down time.

d. If you want to send accounting messages to all servers in the group (RADIUS or TACACS+ only), enter the following command:

hostname(config-aaa-server-group)# accounting-mode simultaneous

To restore the default of sending messages only to the active server, enter the accounting-mode single command.

Step 2 For each AAA server on your network, follow these steps:

a. Identify the server, including the AAA server group it belongs to. To do so, enter the following command:

hostname(config)# aaa-server server_group (interface_name) host server_ip

When you enter a aaa-server host command, you enter host mode.

b. As needed, use host mode commands to further configure the AAA server.

The commands in host mode do not apply to all AAA server types. Table 13-2 lists the available commands, the server types they apply to, and whether a new AAA server definition has a default value for that command. Where a command is applicable to the server type you specified and no default value is provided (indicated by "—"), use the command to specify the value. For more information about these commands, see the Cisco Security Appliance Command Reference.

Table 13-2 Host Mode Commands, Server Types, and Defaults

Table 13-2 Host Mode Commands, Server Types, and Defaults

Command

Applicable AAA Server Types

Default Value

accounting-port

RADIUS

1646

acl-netmask-convert

RADIUS

standard

authentication-port

RADIUS

1645

kerberos-realm

Kerberos

—

key

RADIUS

—

TACACS+

—

ldap-attribute-map

LDAP

—

ldap-base-dn

LDAP

—

ldap-login-dn

LDAP

—

ldap-login-password

LDAP

—

ldap-naming-attribute

LDAP

—

ldap-over-ssl

LDAP

—

ldap-scope

LDAP

—

nt-auth-domain-controller

NT

—

radius-common-pw

RADIUS

—

retry-interval

Kerberos

10 seconds

RADIUS

10 seconds

SDI

10 seconds

sasl-mechanism

LDAP

—

server-port

Kerberos

88

LDAP

389

NT

139

SDI

5500

TACACS+

49

server-type

LDAP

auto-discovery

timeout

All

10 seconds

Example 13-1 shows commands that add one TACACS+ group with one primary and one backup server, one RADIUS group with a single server, and an NT domain server.

Example 13-1 Multiple AAA Server Groups and Servers

hostname(config)# aaa-server Authlnbound protocol tacacs+

hostname(config-aaa-server-group)# max-failed-attempts 2

hostname(config-aaa-server-group)# reactivation-mode depletion deadtime 20

hostname(config-aaa-server-group)# exit

hostname(config)# aaa-server Authlnbound (inside) host 10.1.1.1

hostname(config-aaa-server-host)# key TACPlusUauthKey

hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname

config-aaa-server-host)# exit

config)# aaa-server Authlnbound (inside) host 10.1.1.2

config-aaa-server-host)# key TACPlusUauthKey2 config-aaa-server-host)# exit

config)# aaa-server AuthOutbound protocol radius

config-aaa-server-group)# exit

config)# aaa-server AuthOutbound (inside) host 10.1.1.3

config-aaa-server-host)# key RadUauthKey config-aaa-server-host)# exit config)# aaa-server NTAuth protocol nt

config-aaa-server-group)# exit

config)# aaa-server NTAuth (inside) host 10.1.1.4 config-aaa-server-host)# nt-auth-domain-controller primary1

config-aaa-server-host)# exit

Example 13-2 shows commands that configure a Kerberos AAA server group named watchdogs, add a AAA server to the group, and define the Kerberos realm for the server. Because Example 13-2 does not define a retry interval or the port that the Kerberos server listens to, the security appliance uses the default values for these two server-specific parameters. Table 13-2 lists the default values for all AAA server host mode commands.

'A

Note Kerberos realm names use numbers and upper-case letters only. Although the security appliance accepts lower-case letters for a realm name, it does not translate lower-case letters to upper-case letters. Be sure to use upper-case letters only.

Example 13-2 Kerberos Server Group and Server

hostname(config)# aaa-server watchdogs protocol kerberos

hostname(config-aaa-server-group)# aaa-server watchdogs host 192.168.3.4

hostname(config-aaa-server-host)# kerberos-realm EXAMPLE.COM

hostname(config-aaa-server-host)# exit

hostname(config)#

Continue reading here: License Requirements

Was this article helpful?

0 -1