Question

Cisco ACS Radius configuration

Asked by: peterelvidge

Need some help to use Cisco ACS server to provide login authentication to cisco devices on the network....



Not sure of the best way to set up ACS to act as radius server , if anyone with any experience can point me in the right direction , will be great....


for the devices on the network, have configured it as the following....



aaa new-model

aaa authentication password-prompt Password:
aaa authentication username-prompt Username:
aaa authentication login default group radius local enable

radius-server host (IP adddress of ACS) auth-port 8812 acct-port 8813 key secretkey

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2007-10-15 at 02:27:03ID22893036
Tags

cisco

,

acs

,

radius

Topics

Networking Protocols

,

Miscellaneous Networking

,

Network Management

Participating Experts
3
Points
0
Comments
19

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Configuring radius with backup authentication on a cisco ro…
    I have a cisco 2600 series router that I am attempting to use radius authentication. I would like to be able to log into the router using radius under normal circumstances. The radius server is currently providing authentication. However, if the there is no connection to th...
  2. Can someone provide a sample Radius configuration for a C…
    I am trying to configure radius authentication & accounting using microsoft IASas my RADIUS server, & a Cisco 3500 series XL switch as the client. Heres my config so far whats missing? aaa new-model aaa authentication login radius-local group radius local radius-ser...
  3. Radius Query
    I'm trying to use Radius as AAA server for login to cisco router. The commands aaa new-model, aaa authentication, radius-server host command setup okey. Initially, the commands "aaa authentication login default group radius" work and I can login to the router. I th...
  4. Cisco 837 Radius Config
    Hi, Im working my way through our network to try and get all of our routers authenticating telnet and ssh logins using radius. I've done most of them, but when I get to the Cisco 837's all running IOS 12.3 it will accept all of the below commands except the "radius-s...
  5. Help needed with RADIUS authentication on cisco switch
    I have the following configuration on a cisco switch that I'm testing for RADIUS authentication: aaa new-model aaa authenticaton login default group radius local aaa authentication enable default group radius enable aaa authorization exec default group radius local enable se...
  6. Cisco Radius User Authentication Privilege Level
    Hi I want to set up our switch environment to authenticate via our radius server and set each user to the appropriate privilege level. So far I have been able to set up authentication but everybody is given level 15 access! I had to set the vender specific attribute to Cis...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: PeteLongPosted on 2007-10-15 at 02:54:03ID: 20076772

Typical - Ive got a full walkthough on my website - and my broadband is down :(

Heres the official link you need to read  http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00800b6099.shtml#configuringthemicrosoftserverwithias

If my site gets back up this evening www.petenetlive.com go to tech info - cisco and there a full walkthrough :)

 

by: peterelvidgePosted on 2007-10-15 at 04:40:21ID: 20077125

hey Pete -- i think ill wait for your website!

 

by: pkapoorPosted on 2007-10-15 at 08:20:07ID: 20078909

I would recommend TACACS+ as a preferred protocol for Cisco device AAA setup. Take time to read the difference between TACACS+ and RADIUS protocols to make an informed decision on what you would like to implement. Here is a pretty good article on it from Cisco: http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a0080094e99.shtml.

If you have already decided on RADIUS, then here is what is required.
1. AAA setup on the router:

****Define the AAA parameters****
aaa new-model
aaa authentication login default group radius local enable
!
****Define the ACS Server RADIUS setup****
radius-server host <IP_Addr_of_ACS> auth-port 1645 acct-port 1646
radius-server retransmit 30
radius-server key <shared_secret>

****Apply the AAA configuration to the access method****
****Here I am saying that anyone accessing the router on "line vty 0 4" needs to be AAA authenticated****

line vty 0 4
 login authentication default

2.  ACS Server setup
- Under "Network Configuration", you can either create a new group for network devices. I group mine based on location of device or type of device (routers, firewalls, vpn, etc.).
- Once your group is created, you can start adding devices under it. Click the group name you just created under Network Configuration and then click Add Entry.
-  In the "Add AAA Client" page, enter the fields.
i.  Hostname of Cisco device
ii. IP address of Cisco device
iii. The <shared_secret>, which you have setup on the device as well
iv. Drop-down and select the group to which you want to add this device. The groups listed in the drop-downs are those that you configured in the first step.
v.  For "Authenticate Using" select the appropriate RADIUS "version".  Typically for routers and PIX firewalls, you would use the "RADIUS (Cisco IOS/PIX)" protocol. These "versions" are pretty obvious in their description.
vi. Click "Submit + Apply"

Now you can test and see whether your authentication works or not.

 

by: PeteLongPosted on 2007-10-15 at 12:10:04ID: 20080684

 

by: peterelvidgePosted on 2007-10-16 at 05:21:14ID: 20084825

hey pete -- thanks for the guide -- but was after ACS configuration -- not ASA ,  pkapoor , your guide looks great -- but in 'network configuration' -- i cant seen to add a network device group-- the only options i have is to add either an AAA client  or an AAA server or a proxy distrubution table... any reason why this is?  

many thanks

 

by: peterelvidgePosted on 2007-10-16 at 05:31:40ID: 20084899

seem to be getting somewhere .... the device is communicating to radius -- but access is rejected -- can i build local database of users i want to be able to acess the devices -- i would like anyone who has access to have priviledge level 15



5d02h: RADIUS: Pick NAS IP for u=0x1818C30 tableid=0 cfg_addr=0.0.0.0
5d02h: RADIUS: ustruct sharecount=1
5d02h: Radius: radius_port_info() success=1 radius_nas_port=1
5d02h: RADIUS(00000000): Send Access-Request to 10.99.1.12:1645 id 1645/1, len 72
5d02h: RADIUS:  authenticator 70 A0 E0 8D 3D 8A C0 8B - 4A 9A F7 07 DF 0C 53 02
5d02h: RADIUS:  NAS-IP-Address      [4]   6   10.87.162.109
5d02h: RADIUS:  NAS-Port            [5]   6   2
5d02h: RADIUS:  NAS-Port-Type       [61]  6   Virtual                   [5]
5d02h: RADIUS:  User-Name           [1]   4   "ra"
5d02h: RADIUS:  Calling-Station-Id  [31]  12  "10.0.0.117"
5d02h: RADIUS:  User-Password       [2]   18  *
5d02h: RADIUS: Received from id 1645/1 10.99.1.12:1645, Access-Reject, len 32
5d02h: RADIUS:  authenticator 3B 13 38 1A 38 48 F7 86 - 1D 06 BB C0 85 49 E2 87
5d02h: RADIUS:  Reply-Message       [18]  12
5d02h: RADIUS:   52 65 6A 65 63 74 65 64 0A 0D                    [Rejected??]
5d02h: RADIUS: saved authorization data for user 1818C30 at 0
5d02h: RADIUS: Pick NAS IP for u=0x1818C30 tableid=0 cfg_addr=0.0.0.0
5d02h: RADIUS: ustruct sharecount=1
5d02h: Radius: radius_port_info() success=1 radius_nas_port=1

 

by: peterelvidgePosted on 2007-10-16 at 05:45:00ID: 20084972

can i just add -- that i would like to use windows AD database to allow the users priviledge level 15...

i have made this work by making a new user in a new group

 

by: pkapoorPosted on 2007-10-16 at 07:57:15ID: 20086099

In Network Configuration, you can add AAA client (without creating groups). This could be because of the version of ACS you are running. However, if you just add the AAA client, that will suffice.

Once that is done, let's talk about integrating the AD authentication. Note that for assigning privilege levels, you need to do it with the ACS itself. Active Directory does not have attributes that will assign out privilege levels with RADIUS authentication. However, you can create a group in AD which has all users you want to give access to as its member.

To have the ACS refer to the AD for user credentials, do the following:
1.  External User Database > Database Configuration > Windows Database > Configure
2.  I usually check the Dialin Permission (for this, in the AD account of the user, you must grant Dial-in permissions.
3.  I do not enable Windows callback.
4.  In "Configure Domain List", you will see your domain in the "Available Domains" list. Select and add it to the right side.
5.  Submit

Sometimes the ACS prompts you to restart the service control. For this, go to System Configuration > Service Control and then click the Restart button at the bottom.

Let us know how it goes.

 

by: pkapoorPosted on 2007-10-16 at 08:01:13ID: 20086140

FYI, if you refer to an external database, the ACS builds a local cache of the credentials once a user authenticates successfully for the first time. Therefore, if any user leaves and you disable his AD account, don't forget to check the ACS local database to make sure that you delete the cached account as well.

 

by: peterelvidgePosted on 2007-10-16 at 08:37:18ID: 20086458

thanks for this -- however i still cant seem to get a user to be able to get privilege level 15 straight away

 

by: peterelvidgePosted on 2007-10-16 at 08:45:09ID: 20086535

In the ACS i have created a local  group of 7 members , they can all  login to the cisco

in the ACS group i made , i edited in the settings> Cisco IOS/PIX 6.x RADIUS Attributes

i added: priv-lvl=15

but i dont actually get privilege level 15 , maybe i need to adjust this?

5d03h: RADIUS:  NAS-Port            [5]   6   2
5d03h: RADIUS:  NAS-Port-Type       [61]  6   Virtual                   [
5d03h: RADIUS:  User-Name           [1]   5   "rob"
5d03h: RADIUS:  Calling-Station-Id  [31]  12  "10.0.0.117"
5d03h: RADIUS:  User-Password       [2]   18  *
5d03h: RADIUS: Received from id 1645/16 10.99.1.12:1645, Access-Accept, l
5d03h: RADIUS:  authenticator 80 88 38 88 14 70 57 87 - 23 00 05 DB F6 17
5d03h: RADIUS:  Vendor, Cisco       [26]  25
5d03h: RADIUS:   Cisco AVpair       [1]   19  "shell:priv-lvl=15"
5d03h: RADIUS:  Framed-IP-Address   [8]   6   255.255.255.255
5d03h: RADIUS:  Class               [25]  24

 

by: pkapoorPosted on 2007-10-16 at 09:20:05ID: 20086811

What version of ACS do you have?

 

by: peterelvidgePosted on 2007-10-17 at 03:46:07ID: 20092090

v 4.0

 

by: pkapoorPosted on 2007-10-17 at 11:35:22ID: 20095835

So what is it that you get when the users log in? Have you made sure that you have enabled Shell (exec) access?

 

by: peterelvidgePosted on 2007-10-18 at 01:29:27ID: 20099371

i get the normal exec prompt  .. >

i need the priviledge exec prompt #

i think the problem is that the cisco does not understand...priv-lvl=15   , is there a different way this should be written?


6d22h: RADIUS:   Cisco AVpair       [1]   13  "priv-lvl=15"

 

by: peterelvidgePosted on 2007-10-18 at 05:19:17ID: 20100105

think ive just worked this out...


you need...

aaa authorisation login ....default radius  etc command  to authorise priv lev 15

 

by: Computer101Posted on 2008-02-22 at 14:41:46ID: 20962260

PAQed with points refunded (500)

Computer101
Community Support Moderator

 

by: PeteLongPosted on 2010-05-05 at 08:38:45ID: 32644522

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...