Cisco :: 5500 - Changing Radius Server

Nov 19, 2012

We are retiring our current radius server. It is windows 2003 IAS server (also a DC) that we use for 802.1X authentication. We are moving to server 2008r2. I have already installed NPS and Network Authentication services on the server.

On the existing IAS server I exported the settings (using iasmig reader.exe) and was able to import the profiles (I see the 5500 as a radius client etc) Our 5500 is still pointing to the old server.
 
Is it as simple as changing the ip of the RADIUS server to point to the new server? It looks like I actually have to add the new server and create a new pres hared key on the NPS server but only find documents on adding a new 5500 (vs flipping it to a new NPS server).

View 9 Replies


ADVERTISEMENT

Cisco Firewall :: License And Hardware Changing 5500 Series

Aug 8, 2011

I bought a 5500 series ASA and SecPlus license for example. Suddenly my ASA hardware got broken and changed for a new one. What about my old license? How i could activate this license on new ASA?

View 2 Replies View Related

Cisco VPN :: Changing The Server IP In A ASA 5505?

Sep 28, 2012

I know know nothing about cisco devices. Just wanted to get that out there. I recently came to a job that has a 5505 setup as the network gateway, and as a vpn for employees to work from home via the Cisco VPN remote client program. We had one main server that was domain controller, dns, and dhcp. It was a old 03 box, and I setup a new 08 r2 box on a different IP, and migrated all the above functions to it. Old server was a xxx.xxx.xxx.31, new server xxx.xxx.xxx.6. I found the java ASDM program(6.1) and connected to the ASA, and I have changed .31 to .6 in as many places as I can find, however, vpn clients on the outside can no longer connect to their desktops, as when i open a command prompt on their computer, the only IP they can ping is xxx.xxx.xxx.31, pinging xxx.xxx.xxx.6, or any other address fails. I'm guessing maybe it's in the firewall of the asa, but have no ideal really. Was there anything else I was suppose to do? Someplace I overlooked?

View 7 Replies View Related

Cisco :: LMS 3.2.1 Changing Smtp Server

Nov 13, 2011

Running lms 3.2.1   CS 3.3.1  on Windows 2003
 
I need to point the LMS server to a new mail relay, but when I make the change in
 
CS->SERVER->Admin->System Preferences  smtp server
 
It claims to have made the change successfully but the old IP address remains.

View 3 Replies View Related

Cisco VPN :: 515E Changing DNS Server For VPN Clients

Jan 25, 2012

I am trying to change the DNS server that my VPN gives to VPN clients on a Cisco PIX 515E. What command will change it from 10.6.0.2 to 10.6.0.4? The software version is 7.2(3)

View 3 Replies View Related

Cisco Firewall :: ASA 5510 Server's NAT Address Not Changing

Nov 16, 2011

I added a new server and created a new static NAT assignment on the ASA 5510 to the server's IP.  When I browse to the web to check what public IP it's reporting, it shows the wrong IP.  I disabled the network interface on the server, ran "clear xslate", reenabled the network interface, ran "sho xlate" and while the correct translation was in the table, the server still reported the wrong IP address.I even ran a packet trace and it showed the IP address being correctly translated to the proper public IP, but when I browse to the web I get the same erroneous public IP. [code]

View 8 Replies View Related

Cisco Infrastructure :: Using Catalyst 5500 As A TFTP Server?

Mar 11, 2003

I need to do one Catalyst 5500 as a TFTP server.Can I do it?Is the catalyst available to be a tftp server?

View 4 Replies View Related

Cisco Wireless :: 5500 Controller - Change IP Of WCS Server?

Aug 27, 2011

I have two 5500-controllers and one WCS-server. Now I will have to move the WCS-server to another subnet and change the IP, but it will keep the name.Will that effect the connection between the controllers and the WCS?Do I have the change anything in the configuration on the controllers or the WCS-server?

View 3 Replies View Related

Cisco Firewall :: ASA 5500 - Cannot Access Website From Server

Feb 16, 2011

My web server sits behind an ASA 5500.When I access the web site from outside, it works fine.  When I try and access it from the server itself, I get"Internet Explorer cannot display the webpage" error.  I can access other web sites, such as Yahoo.com, Google.com, etc. I have rules setup to restrict/enable incoming traffic, but I don't have any rules setup to "loop back". 

View 18 Replies View Related

Cisco :: Free Radius Server For Lab?

May 1, 2012

Any free radius server for lab purpose?

View 5 Replies View Related

Cisco :: Configuring RADIUS Server For It?

Jan 25, 2012

Does anyone have or know of a tried and true method of configuring a Windows Server 2008 box to provide authentication/accounting services for Cisco devices. I've read a few websites already and a lot of them seem to be geared toward VPN and some of the settings each site goes through are different.I've got NPS installed and a RADIUS client configured with the shared key. Right now I'm in the process of creating the Network Policy which only allows a Windows "admin" group to log in. Curious about the "Constraints" section where the NAS Port Type is selected and the "Settings" section where the service-type and vendor specific options are configured.

View 18 Replies View Related

Cisco :: How To Configure Radius Server

Oct 15, 2012

How to configure Radius server on router in packet tracer

View 1 Replies View Related

Cisco :: AP1252 AG And Radius Server

Jun 8, 2011

i have problem with my 3 new cisco AP1252AG and Radius server (windows 2000 IAS).On the 3 AP, i have two ssid :,One with Wpa pre-shared key,the other one with EAP/radius,the one with preshared key works well  but the other have some trouble, here is the error message ,i have check the shared secret in radius and ap and it's ok.The error appears randomly.

View 1 Replies View Related

Servers :: Prevent Changing DNS Server IP / Disable LAN Properties

Jan 10, 2011

I am using Vista and have only one user accounts.Now I want to prevent changing the DNS server IP. I can prevent changing the DNS server IP or disable the LAN Properties.

View 4 Replies View Related

Changing Default Server Setting For Outlook Account?

Feb 23, 2013

Can I receive an answer to how can I remove the default smtp.cwjamaica.com from my Windows Outlook Account. This is a pop-up server that I wish to disconnect so I can use other facilities. This is the default server and it is no longer relevant to my location our current

View 1 Replies View Related

Program Changing DHCP Server IP Address Scope

Jul 11, 2011

My Network is running Windows Server 2003 and with more than 150 Users. But last week, I notice that a program is changing my DHCP server IP Address scope.

View 2 Replies View Related

Cisco Wireless :: 5508 Controller And Changing Windows Dhcp Server

Dec 5, 2012

We have a 5508 controller authenticates with WPA2-enterprise to 3 possible AAA servers.  Today I tried migrating our DHCP server from a Windows 2003 machine to Windows 2008 R2.  Migration went smoothly and all wired clients could get IP's.  Reservations intact, scopes intact, etc.. you name it.  I though it was a great success.
 
Fast forward about an hour when people started coming into work for the day. Calls started coming in about their laptops not able to connect to the network.  I double checked with a spare laptop in our IT department and also my iPhone.  Same issue.  Seems the only thing I changed today was the DHCP server (from 10.1.1.1 to 10.1.1.2).
 
After racking my head on it for awhile, I re-enabled the "old" dhcp server (10.1.1.1) and disabled it on the new (10.1.1.2).  Instantly wireless clients were able to connect.
 
Am I missing some configuration step in the 5508 controller when moving DHCP servers?  I do plan on running 2 DHCP servers (10.1.1.2 and 10.1.1.10) for redundancy once I get the primary one moved over and working correctly.
 
I want to decommision the older 2003 server.  Its time to raise the domain functional level.

View 6 Replies View Related

Cisco Firewall :: ASA 5500 / 5580 Syslog Keeps Sending To Old Server

Oct 26, 2011

We use multiple ASA 5500/5580 cluster systems running  8.3 software versions.Actually we send all our FW syslog data to a SIEM appliance in a DMZ on a remote firewall (non-asa). Recently we suffered a strange incident while implementing a new SIEM collection station now situated in a dmz that is located on one of the ASA contexts. We redirected the syslog streams to the new client for one of the contexts on the ASA cluster that holds the new SIEM agent DMZ..since we did this and redirected the syslog we see double traffic and spoofing errors on that context
 
a/ the ASA keeps sending out the syslog traffic to the OLD SIEM agent server ip (there is however no trace of its ip in the config)

b/ the traffic leaving the interconnection interface towards the OLD SIEM agent gets a SPOOFING error on the traffic

c/ strangely the data gets also correctly forwarded to the new SIEM collection stations.
 
We started out with redirecting traffic on only one of the 5 contexts to the new environment and kept logging the others to the old system.I finally got out of the issue by reconfiguring al the other contexts to forward their syslog towards the same new server , since that moment we no longer have the double logging and spoofing error , all syslog traffic goes correctly to the new SIEM agent. It looked like some remenants of the old syslog config remainded on the asa event after deleting and introducing a new config line (we used the asdm to execute the action) as said either it kept the old config or it looked in the other context and "decided" to keep sending to the old server also mentioned in that syslog can find the behaviour in any buglists either way.

View 1 Replies View Related

Cisco VPN :: ASA 5500 IP Sec Connection Profile - Multiple Dhcp-server?

Jun 10, 2013

We assign in our IPSec VPN the tunnel-address from our centralized dhcp server pools.In the profile we have two server's ip configured.In test (whireshark) we noticed that the discover always go to the first configured ip.
 
I do not understand and could not finf hints how the function is.

- backup server with a timeout when no answer comes from primary ?

- should ASA do simultaneous discover to all configured ip's ?
 
=>Problem is, that although the first server not answered in a timely manner, we noticed no discover to the second.
 
Here the partial CLI - Config:
 
++
tunnel-group AZInt07 type remote-access
tunnel-group AZInt07 general-attributes
authentication-server-group ActivPack
default-group-policy AZInt
dhcp-server 10.x.x.y
dhcp-server 10.x.y.y

[code].....

View 3 Replies View Related

Cisco WAN :: Best RADIUS Server For 802.1x Wired Authentication?

Sep 2, 2012

which is the best RADIUS server for 802.1x wired authentication?

View 1 Replies View Related

Cisco :: WAP4410N Not Talking To RADIUS Server

May 13, 2013

I am trying to configure a WAP4410N, with latest firmware, for disabled security (i.e.: no WEP/WPA, user passwords etc) but enable MAC authentication control using RADIUS.If I test the WAP using disabled security and disabled authentication control, the WAP works fine. When I enable the RADIUS MAC authentication (ensuring I have entered the correct RADIUS server details) nothing happens, the WAP connection just fails. Also, the RADIUS server doesn't log any attempts from the WAP to connect.Is there a known problem with this WAP simply not working with RADIUS under this configuration?

View 1 Replies View Related

Cisco :: Can Aironet1040 AP Set Local Radius And Act As Server

Mar 7, 2012

I am testing a Aironet1040 in AP setting. During the process of trial run of GUI on this 1040, I saw a local radius setting and it can set something like FAST-EAP.
 
Is it after using this setting (plus other steps), I can set this Aironet1040 as an AP with the capability of simple Radius Server for authentication purpose?
 
If not by this way as I mentioned above, can Aironet1040 be set as simple Radius Server? This is because if it can set as simple Radius Server and not need to work with an external Radius Server, that would be great and save trouble to find another server.

View 5 Replies View Related

Cisco :: EAP-TLS With Radius Server Configuration (1130AG)

Jan 24, 2013

I am currently trying to get eap-tls user certificate based wireless authentication working. The mismatch of guides im trying to follow has me coming up trumps with success so far.
 
My steps for radius:- (i think this part ive actually got ok) [URL]
 
Steps for the wireless profile on a win 7 client:- this has me confused all over the place [URL]
 
My 1130 Config:-
 
[code]
Current configuration : 3805 bytes
!
! Last configuration change at 11:57:56 UTC Fri Jan 25 2013 by apd

[Code].....

View 14 Replies View Related

Cisco WAN :: 2811 How To Configure RADIUS Server Using CLI

Oct 28, 2012

I have a 2811 router and how to configure a RADIUS server using the CLI.

View 3 Replies View Related

Cisco :: WLC 2504 With RADIUS Server Authentication And EAP-TLS

Mar 6, 2013

Can the 2504 WLC be configured to work with one RADIUS Server for Authentication of Management Users and with a second server for 802.1x EAP-TLS certificate authentication for the end users.
 
Management Users will authenticate on RADIUS Server 1.Wireless End users will request 802.1x EAP-TLS authentication certificate from AAA server 2.

View 5 Replies View Related

Cisco AAA/Identity/Nac :: 5508-WLC Using MS NPS As RADIUS Server For EAP-TLS

May 18, 2011

getting a Cisco WLC to work with MS NPS server? We've done it before albeit with differnt code versions.
 
I have a Cisco 5508 WLC running 7.0.116.0 code hosting a WLAN configured for WPA2 with 802.1x for authentication.  I have two Windows NPS servers configured as the RADIUS servers for EAP-TLS authentication. Via debug info on the WLC I can see the 802.1x handshake take place with the wireless client and the WLC as well as a successful transmission of an Authentication Packet from the WLC to one of the RADIUS servers. However on the WLC I see repeated RADIUS server x.x.x.x:1812 deactivated in global list and on the NPS server I'm seeing event log errors indicating "The Network Policy Server discarded the request for a user"  along with the pertinent auth request info that I would expect the NPS server to receive from the WLC.  Based on the WLC debug info I'm never actually getting to the EAP-TLS certificate authentication part. It seems the NPS servers don't like the format of the initial RADIUS authentication request coming from the WLC and so don't respond whcih in turn casues to WLC to switch to the other NPS server which produces the same issue.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 / ISE As Standalone RADIUS Server

Apr 7, 2013

Is there any way to set up our ISE to provide Radius instead of acting as Radius Proxy? In our Company we use ACS 4.2 to provide AAA via Tacacs+ and this works proper with all our Cisco-Switches. Now we are testing the ISE 1.1.1 as NAC-Solution.
 
I know how to set up the ISE as 'Radius Proxy', configuring the Sequences and Policies, but till now we are using only Tacacs+ for AAA. The current version of ISE does not support Tacacs+ and I don't want to set up a Radius-enviroment in ACS if not necessary. Somewhere ( I think the specs) I read, the ISE is a merge of ACS and NAC. So in my Opinion there should be a way to provide AAA via Radius on the ISE without ACS and without 'Radius Proxy'.

View 2 Replies View Related

Cisco Firewall :: ASA 5500 - HTTP Inspection Spoof Server String

Aug 11, 2011

I'm looking fot a way to do static URL blocking with ASA and when the URL is blocked present a "Web Page" to the user saying that it's been blocked.

So, i was wondering if i can use the http parameter "spoof server string" to replace the original URL sent by the user for another URL that points to an internal web server holding a basic page saying "Your URL request has been blocked".
 
The point is to have a way to tell users that the page they are trying to browse is blocked by a policy.

View 1 Replies View Related

Cisco :: Possible To Have ASDM And SSH Authenticate Via Different Means On RADIUS Server

Apr 3, 2013

Is it possible to have ASDM and SSH authenticate via different means on a RADIUS server? In particular, I have a single aaa-server group that's used for both ASDM and SSH, but I want to limit ASDM access to only a particular group in Active Directory (for example). I looked at various different requests (from the server's perspective) to see if there was a way that they (ASDM requests and SSH requests) were differentiated but was unable to find any. It would be ideal if there was something inherent about the RADIUS request coming from ASDM vs SSH so that I could build that decision making into the RADIUS server.I know I could do this by just using a different aaa-server group for each access method, but I want to avoid that if possible.

View 7 Replies View Related

Cisco Wireless :: 5508 WLC With ISE As Radius And Also External Web Server

Jan 30, 2013

I am biulding a wireless network with 5508 WLC and trying to use ISE as radius server and also to redirect the web-login to it.I was trying to understand that to achieve the external web-login, do i need to use the raduius-nac option under advanced on the guest wireless where i am trying this out. and if not, where do i actually use it?So far what i have understood that i do need to have preauth ACL on the Layer 3 security, but the issue is there is no hit reaching the ISE.

View 9 Replies View Related

Cisco VPN :: ASA 8.4.x - Sending A Client Attribute To Radius Server

Dec 11, 2011

I'm using an ASA version 8.4.2 and a Radius Server.
 
Is-it possible to configure ASA for sending the name of the connection profile to the Radius Server ?
 
By default, the radius server doesn't receive this information.

View 1 Replies View Related

Cisco Wireless :: Radius Server Requirement With Wlc 2504?

Jul 12, 2012

I want to know if its nessary to install Certificate authority on your radius server. If we have a CA server already in the domain can we use that for this purpose or we have to install certificate authority on our DC. 

View 1 Replies View Related

Cisco Wireless :: Radius Server Authentication AIR-AP1231G-A-K9

Apr 30, 2012

Below is he output from debug radius authentication from my AP.
 
I can see request is forwarding from AP to radius but Radius is not sending any response.Not sure why its not responding.
 
I also did not under stand few out outputs also
no sg in radius-timers and
RADIUS/DECODE: parse response no app start; FAIL
what does it mean.
 
I  restarted radius server , changed secret key but no luck.
 
019639: May  1 16:15:08.727: RADIUS:  User-Name           [1]   32  "host/3KYGRH1.idcap.intdata.com"
019640: May  1 16:15:08.727: RADIUS:  Framed-MTU          [12]  6   1400
019641: May  1 16:15:08.727: RADIUS:  Called-Station-Id   [30]  16  "0012.01d6.f691"
[Code]...

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved