Solved

cisco routers users setup privileges through a radius server

Posted on 2015-02-19
4
75 Views
Last Modified: 2015-07-31
We have some users that will require additional privileges on cisco routers, like executing commands  such as no shut on an interface, etc. Is it possible to set specific privileges levels on a radius server and apply to users.
0
Comment
Question by:Shen
  • 2
  • 2
4 Comments
 
LVL 4

Assisted Solution

by:askincakir
askincakir earned 500 total points
ID: 40620697
Hi,

Mostly solution for your request is done by Cisco Tacacs+ server. There you can use command level permit actions.
But, here i am giving you some another cli level privilege enablements.
Just check and let me know is this what you need ?
Module-Bonus-7-user-priviledges.pptx
0
 

Author Comment

by:Shen
ID: 40625727
Is there a way to setup a radius group named say:  "test" that belongs to example: domain users

then on the cisco device do :
aaa authentication login "test" group radius local

setup the privilege in the router :
Like example:   privilege exec level 1 show ip  
                            username group  "test" privilege 1
I am trying to avoid setting  users and passwords  in the router. Use radius to provide the users and authentication and assign the privilege exec level to a radius group "test"
0
 
LVL 4

Accepted Solution

by:
askincakir earned 500 total points
ID: 40628178
Hi,

Which radius you are planning to use ?

Microsoft NPS ?

Cisco ACS ?
br,
0
 

Author Comment

by:Shen
ID: 40649436
nps
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Monitoring Exchange 2013 8 135
DHCP Failover Relationship caveats 6 117
network monitoring tools / software 5 139
Classlful vs Classless subneting 18 73
The use of stolen credentials is a hot commodity this year allowing threat actors to move laterally within the network in order to avoid breach detection.
Outsource Your Fax Infrastructure to the Cloud (And come out looking like an IT Hero!) Relative to the many demands on today’s IT teams, spending capital, time and resources to maintain physical fax servers and infrastructure is not a high priority.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question