Configure Tacacs Command Authorization for Cisco Routers and Switches
You can use the TACACS+ feature of Cisco Secure ACS to authorize the command sets that MARS is allowed to execute on a reporting device. The use of this feature is not required by MARS. However, if you are using this feature on your routers and switches, you must ensure that MARS is allowed to execute specific commands. Required commands are grouped under two operations: configuration retrieval and mitigation.
The following commands support configuration retrieval:
• all show commands
• changeto system
• changeto context <context_name>
• terminal length 0
|
Install and Configure the PN Log Agent H |
|
|
• terminal pager lines 0 |
|
|
• write terminal |
|
|
The following commands support mitigation: |
|
|
• conf terminal |
|
|
• interface <interface_name> |
|
|
• shutdown |
|
|
• set port disable <port_name> |
|
|
For more information on configuring command authorization sets in Cisco Secure ACS, see the |
|
|
following URL: |
|
|
http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a00 |
|
|
802335ec.html#wp697557 |
|
|
Install and |
Configure the PN Log Agent |
|
MARS includes the PN Log Agent to monitor Cisco Secure ACS active log files (failed attempts, passed |
|
|
authentications, and RADIUS accounting). This agent pushes these log files via syslog to MARS. You |
|
|
can download the PN Log Agent from the software download center at the following URL: |
|
|
http://www.cisco.com/cgi-bin/tablebuild.pl/cs-mars-misc |
|
|
% |
|
|
Note |
If you are upgrading to a new version of the PN Log Agent, see Upgrade PN Log Agent to a Newer |
|
Version, page 14-9. |
|
|
As part of its operation, the PNLog Agent service writes error and informational message to the |
|
|
Application Log, which can be viewed using the Event Viewer. To learn more about these messages, see |
|
|
Application Log Messages for the PN Log Agent, page 14-10. |
|
|
To install and configure the PNLog Agent, follow these steps: |
|
|
Step 1 |
Download the PN Log Agent and install it on the server running Cisco Secure ACS or on the remote |
|
% |
logging host to which the Cisco Secure ACS Solution Engine is publishing its logs. |
|
Note |
If installing on a remote logging host, you must have configured the Cisco Secure ACS Remote Agent |
|
for Windows and Cisco Secure ACS Remote Agent for Solaris on the target remote logging host. |
|
|
For instructions on installing and configuring the remote agent, see Installation and Configuration Guide |
|
|
for Cisco Secure ACS Remote Agents. |
|
|
Step 2 |
Select Start > All Programs > Protego Networks > PNLogAgent > Pn Log Agent |
|
Step 3 |
Click Edit > PN-MARS Config. |
|
Result: The PN Log Agent Configuration dialog box appears. |
|
Step 4 In the MARS IP Address field, enter the address of the MARS Appliance, and click OK. Step 5 Select Edit > Log File Config > Add.
Step 6 From the Edit pull down menu select Add.
Result: The Add/Edit File Details dialog box appears.
Step 7 From the Application Name list, select the Cisco ACS-Failed Attempts.
Step 8 Click on the ... button to select the appropriate log where all Cisco Secure ACS logs are stored. In this example after selecting Failed Attempts application, be sure to select the matching log file, Failed Attempts active log.
Result: The Open dialog box appears.
Step 9 Add all 3 applications and their active log files:
• Failed Attempts active
• Passed Authentications active
• RADIUS Accounting active Result: The configured files appear in the List of Log Files to Monitor list.

- Step 10 Select File > Activate.

Post a comment