Identifying AAA Server Groups and Servers

If you want to use an external AAA server for authentication, authorization, or accounting, you must first create at least one AAA server group per AAA protocol and add one or more servers to each group. You identify AAA server groups by name. Each server group is specific to one type of server: Kerberos, LDAP, NT, RADIUS, SDI, or TACACS+.
The security appliance contacts the first server in the group. If that server is unavailable, the security appliance contacts the next server in the group, if configured. If all servers in the group are unavailable, the security appliance tries the local database if you configured it as a fallback method (management authentication and authorization only). If you do not have a fallback method, the security appliance continues to try the AAA servers.
To create a server group and add AAA servers to it, follow these steps:
Step 1 For each AAA server group you need to create, follow these steps:
a. Identify the server group name and the protocol. To do so, enter the following command:
hostname(config)# aaa-server server_group protocol {kerberos | ldap | nt | radius | sdi | tacacs+}
For example, to use RADIUS to authenticate network access and TACACS+ to authenticate CLI access, you need to create at least two server groups, one for RADIUS servers and one for TACACS+ servers.
You can have up to 15 single-mode server groups or 4 multi-mode server groups. Each server group can have up to 16 servers in single mode or up to 4 servers in multi-mode.
When you enter a aaa-server protocol command, you enter group mode.
b. If you want to specify the maximum number of requests sent to a AAA server in the group before trying the next server, enter the following command:
hostname(config-aaa-server-group)# max-failed-attempts number
The number can be between 1 and 5. The default is 3.
If you configured a fallback method using the local database (for management access only; see the "Configuring AAA for System Administrators" section on page 40-5 and the "Configuring TACACS+ Command Authorization" section on page 40-11 to configure the fallback mechanism), and all the servers in the group fail to respond, then the group is considered to be unresponsive, and the fallback method is tried. The server group remains marked as unresponsive for a period of 10 minutes (by default) so that additional AAA requests within that period do not attempt to contact the server group, and the fallback method is used immediately. To change the unresponsive period from the default, see the reactivation-mode command in the following step.
If you do not have a fallback method, the security appliance continues to retry the servers in the group.
c. If you want to specify the method (reactivation policy) by which failed servers in a group are reactivated, enter the following command:
hostname(config-aaa-server-group)# # reactivation-mode {depletion [deadtime minutes] | timed}
Where the depletion keyword reactivates failed servers only after all of the servers in the group are inactive.
The deadtime minutes argument specifies the amount of time in minutes, between 0 and 1440, that elapses between the disabling of the last server in the group and the subsequent re-enabling of all servers. The default is 10 minutes.
The timed keyword reactivates failed servers after 30 seconds of down time.
d. If you want to send accounting messages to all servers in the group (RADIUS or TACACS+ only), enter the following command:
hostname(config-aaa-server-group)# accounting-mode simultaneous
To restore the default of sending messages only to the active server, enter the accounting-mode single command.
Step 2 For each AAA server on your network, follow these steps:
a. Identify the server, including the AAA server group it belongs to. To do so, enter the following command:
hostname(config)# aaa-server server_group (interface_name) host server_ip
When you enter a aaa-server host command, you enter host mode.
b. As needed, use host mode commands to further configure the AAA server.
The commands in host mode do not apply to all AAA server types. Table 13-2 lists the available commands, the server types they apply to, and whether a new AAA server definition has a default value for that command. Where a command is applicable to the server type you specified and no default value is provided (indicated by "—"), use the command to specify the value. For more information about these commands, see the Cisco Security Appliance Command Reference.
Table 13-2 Host Mode Commands, Server Types, and Defaults
Table 13-2 Host Mode Commands, Server Types, and Defaults
|
Command |
Applicable AAA Server Types |
Default Value |
|
accounting-port |
RADIUS |
1646 |
|
acl-netmask-convert |
RADIUS |
standard |
|
authentication-port |
RADIUS |
1645 |
|
kerberos-realm |
Kerberos |
— |
|
key |
RADIUS |
— |
|
TACACS+ |
— |
|
|
LDAP |
— |
|
|
ldap-base-dn |
LDAP |
— |
|
ldap-login-dn |
LDAP |
— |
|
ldap-login-password |
LDAP |
— |
|
LDAP |
— |
|
|
ldap-over-ssl |
LDAP |
— |
|
ldap-scope |
LDAP |
— |
|
nt-auth-domain-controller |
NT |
— |
|
radius-common-pw |
RADIUS |
— |
|
retry-interval |
Kerberos |
10 seconds |
|
RADIUS |
10 seconds |
|
|
SDI |
10 seconds |
|
|
sasl-mechanism |
LDAP |
— |
|
server-port |
Kerberos |
88 |
|
LDAP |
389 |
|
|
NT |
139 |
|
|
SDI |
5500 |
|
|
TACACS+ |
49 |
|
|
server-type |
LDAP |
auto-discovery |
|
timeout |
All |
10 seconds |
Example 13-1 shows commands that add one TACACS+ group with one primary and one backup server, one RADIUS group with a single server, and an NT domain server.
Example 13-1 Multiple AAA Server Groups and Servers
hostname(config)# aaa-server Authlnbound protocol tacacs+
hostname(config-aaa-server-group)# max-failed-attempts 2
hostname(config-aaa-server-group)# reactivation-mode depletion deadtime 20
hostname(config-aaa-server-group)# exit
hostname(config)# aaa-server Authlnbound (inside) host 10.1.1.1
hostname(config-aaa-server-host)# key TACPlusUauthKey
hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname hostname
config-aaa-server-host)# exit
config)# aaa-server Authlnbound (inside) host 10.1.1.2
config-aaa-server-host)# key TACPlusUauthKey2 config-aaa-server-host)# exit
config)# aaa-server AuthOutbound protocol radius
config-aaa-server-group)# exit
config)# aaa-server AuthOutbound (inside) host 10.1.1.3
config-aaa-server-host)# key RadUauthKey config-aaa-server-host)# exit config)# aaa-server NTAuth protocol nt
config-aaa-server-group)# exit
config)# aaa-server NTAuth (inside) host 10.1.1.4 config-aaa-server-host)# nt-auth-domain-controller primary1
config-aaa-server-host)# exit
Example 13-2 shows commands that configure a Kerberos AAA server group named watchdogs, add a AAA server to the group, and define the Kerberos realm for the server. Because Example 13-2 does not define a retry interval or the port that the Kerberos server listens to, the security appliance uses the default values for these two server-specific parameters. Table 13-2 lists the default values for all AAA server host mode commands.
'A
Note Kerberos realm names use numbers and upper-case letters only. Although the security appliance accepts lower-case letters for a realm name, it does not translate lower-case letters to upper-case letters. Be sure to use upper-case letters only.
Example 13-2 Kerberos Server Group and Server
hostname(config)# aaa-server watchdogs protocol kerberos
hostname(config-aaa-server-group)# aaa-server watchdogs host 192.168.3.4
hostname(config-aaa-server-host)# kerberos-realm EXAMPLE.COM
hostname(config-aaa-server-host)# exit
hostname(config)#
Continue reading here: License Requirements
Was this article helpful?