Cisco AAA/Identity/Nac :: ACS (4.2) Read Only Device Access?

Sep 30, 2010

We are using ACS ver 4.2 and trying to setup users with limited access to our switchs and routers.  Here is what we did:
 
1) Created a user in ACS
 
2) Create Shell command Autorization Set - ReadOnly
Unmatched Commands - Deny
Commands Added
show
exit

* this should limit the user to the show and exit command only (correct)?
 
3) Created a group - HelpDesk with the following TACACS+ Settings

Shell (exec) is checked
Priviledge level is check with 15 as the assigned level
Assign a Shell Command Authorization Set for any network device - selected
ReadOnly - shell command autorization set seleted
 
When the user logs on to the router/switch it appears that he has full access.  He can enter the enable command, config terminal command, etc.  All we want him to be able to do is to issue the show command.

View 13 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: Read Only Access ACS 5.3?

Jun 13, 2012

I am using ACS 5.3 with the internal Database for user authentication, I would like to attribute to some users read only rights on the systems. by not configuring an enable password for these users?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Identity Groups - Restrict Device Access

Apr 14, 2011

I have ACS 5.2 running as a VM.  I'm AD, then local authentication successfully for device access, but I want to define ACS user groups to restrict login. I don;t see any way to do this.  If I use AD groups, they don;t show up as selection options on the policy screens, just the ACS locallyy defined groups. 

View 1 Replies View Related

Cisco Wireless :: WAP4410N Firmware Upgrade Turns AP Into Read-Only Device

Oct 16, 2012

My WAP4410N AP is running version 2.0.2.1 firmware which is quite old. There are newer firmware releases available which I'd like to upgrade to (fix the known bugs, etc.).
 
So I upgrade my firmware from version 2.0.2.1 to any of the following versions:

- 2.0.3.3
- 2.0.4.2
- 2.0.5.3
 
The AP reboots and my settings are all still there.
 
I go to change any of the settings I have - DNS, Time Zone, PSK, any field which can be edited and click Save.
 
The Save takes place and the screen refreshes to the old settings - the new settings don't stay in place after the Save.
 
I've also factory defaulted the AP prior to the upgrade, upgraded and then been in the same place unable to save any changed settings.
 
System details:
Information PID VID:  WAP4410N-E V02
Device: WAP4410N Wireless-N Access Point with Power Over Ethernet Software Version:  2.0.2.1

View 4 Replies View Related

Cisco AAA/Identity/Nac :: Read Only Account ACS 5

May 18, 2011

I can create a read-only account on the ACS 5 server? I have the ACSAdmin account.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Device And Network Access

Oct 15, 2012

I have a question reguarding the Cisco Secure ACS 5.2 and network access vs device admin access. We have our switches,routers,and firewall configured to use TACACS+.  We also have configured our Wireless LAN Controller to use RADIUS for allowing for 802.1X authentication to the wireless network.  We are using Active Directory for the backend user database and have assigned the users to different groups in AD.  We have a Network Admins group to access the network devices and a Wireless Users to access the WLAN.  The problem that we have is that everyone in the Wireless Users group can access the devices and run full commands on them. We want to limit the Wireless Users group from being able to do this.  Is there a policy or config change that we will need to make for this?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Device Access Based Upon NDG Using ACS 5.2?

Mar 15, 2012

I have 2 types of network, DC & Office. I have 3 types of users NOC, Office & DC. Office network devices are in Office NDG, DC network devices are in DC NDG. Becasue of such config, Office network users can only access Office devices & DC network users can only access DC network devices....Now i have NOC users, who wants access to both Office & DC network devices. How can i achieve this?

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 - How To Configure Rules To Allow 802.1x And Device Access

Aug 21, 2011

I am new to ACS 5.1.I need to configure the ACS to act as the 802.1x authentication Server, as well as, act as the Radius Server for the authentication and authorization process when I access the switch.
 
I had created Two rules (under the Access policy) to cater for the two scenario, it will always "stuck" at the 1st rule. For e.g. Rule-1 is meant for the 802.1x, Rule 2 is meant for the AAA process. When I tested with 802.1x, it worked perfectly. But when I tested to login to the switch, it always failed. Based on the log, Rule1 is not able to fulfill my requirement (of course it can't). I thought the rules check process will proceed with Rule-2, but apparently it did not.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ISE 1.1 Differentiate Guest Access Depending On Device

Sep 21, 2012

I'm running an ISE 1.1.1 and i need to authenticate guest users.The goal is apply different Authorization profile to the same guest user based on the thevice he use to connect to the guest wlan.
 
I.E.:
if guest user "user1" connect to the guest WLAN using a windows laptop, than apply "Guest" authorization profile
if guest user "user1" connect to the guest WLAN using an Apple iPad, than apply "Mobile" authorization profile
 
I've tried to deployed the following 2 authorization policy:
1)if "Apple-Device" and "IdentityGroup:Name EQUALS Guest" then "Mobile"
2)if "Guest" then "Guest"
 
but the first rule never match and even if I use and iPad to access the guest network the "Guest" authorization Profile is matched
 
I've verified that the iPad is correctly recognized as an Apple-Device changing for test purposes the rule table in
1)if "Apple-Device" then "Mobile"
2)if "Guest" then "Guest"

View 5 Replies View Related

Networking :: D-LINK 524 Cannot Read Access Point

Apr 13, 2011

I have a wireless router namely D-LINK 524. i know its a prtty old router..but its never let me down ever before..but thn today i decided to play a couple of games online using the psp/ps3 and well both the devices couldnt read the access point..

Then i go onto my pc and the internet on the pc dont work either :'( so then i reboot the modem nd wifi router..but to no avail.So i unplug da routerand connect da modem directly to the pc and it worked..so i was quite stunned..nd i miss playing online..

So to trim it down the problem basically is my phone/ps3/psp cannot find my access point AND my pc doesnt work when connected through the wireless router.

View 4 Replies View Related

How To Remotely Access / Read Or Write And Stream Files

Oct 23, 2011

I have a Windows Home Server 2011 box sitting at home in Washington DC. I have about 1TB worth of stuff on that box. For many reasons, I want to store all my data in a centralized location (that being my WHS box). I then want to access that data through my laptop in London as if the data was in a folder on my computer. I also want to access the data through my mobile phone (android).I just set up filezilla on my WHS box and it works fine if I want to download or upload data. But it won't let me open word files 'off' the server, make changes, and then save it right back. I have to download the word file, make changes, and then reupload that file to the server.

View 3 Replies View Related

Cisco Switching/Routing :: 2960S Http / Https Access With Read-only?

Feb 19, 2012

I configured 2960S switch as http server. I'm unable to access the switch GUI with non privilege 15 user, with privilege 15 user it's working.

View 7 Replies View Related

Cisco LAN :: 3750 Configure Read Access Via User-defined Privilege Level

Mar 11, 2013

I´m looking for the best configuration to restrict a user to read-only. The restriction should be configured via CLI not TACACS+.

-Hardware: 3750 (probably not interesting for this question)
-Oldest IOS: 12.2(53)SE1
 
The user should be allowed to: see the running-configurationtrigger all kinds of show-commandsping and traceroute from the device.The user should not be allowed to: upload/delete/rename files on the flash-memoryget into level 15 (not sure if I can avoid this)all other commands despite those from level 1 and those specified above.

View 2 Replies View Related

Linksys Wireless Router :: Set E4200 To Support Anonymous Access To Ftp Server In Read / Write Mode?

Jul 17, 2011

Is there any possibility to set linksys E4200 for support anonymous acces to ftp server in read and write mode ?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Device Restrictions In ACS 5.3?

Mar 13, 2013

In our scenario, easy vpn users are being authenticated by acs 5.3 successfully. We have created seperate user group for these users. The issue is, these users are also able to access our routers using their username/password. I want to restrict this particular group so that its not able to access any device.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Time And Telnet Device Name?

Sep 12, 2012

This is the great place for ACS discussions , i need two more inputs from experts
  
acsserver
Thu Sep 13 14:35:28 UTC 2012
pughaz
15
[ CmdAV=ip tacacs source-interface FastEthernet 0/1 ]
Device Type:All Device Types:ROUTERS, Location:All Locations:NON DC DEVICES
                  
On the above message
  
1. Need to chang time from UTC to IST
 
2.  The Device column is not showing the exact device name ; i telnet and config changed , it is showing the device group name only , how to get the exact device name i telnet on this message

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Integration ACS 5.2 With Other Device (sandvine)

Sep 18, 2012

I have a ACS version 5.2 (TACACS) where I require equipment integrated with Sandvine, I currently looking information and very little to manage the integration of ACS with these teams Sandvine.
 
I have an information on the provider Sandvine with a guide to the case where only states:

TACACS + server
On a TACACS + server, each user entry must allow the service "Sandvine". Within this
service, the attribute-value pairs Following can exist:
• An attribute named "Sandvine-Group" of type string.

[Code]......

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Device Admin Privilege Assignment?

Dec 1, 2011

my admin user is still being assigned privilege level 1, as shown in AAA Protocol > TACACS+ Authentication Details report.The report seems to show that the user is getting the right shell profile (Selected Shell Profile: Net-Admin -- is the one I setup for this user's group with both Default Privilege and Maximum Privilege set to Static 15). But still not the right privilege (Privilege Level: 1).Also, I found this document via Google: [URL] The router configuration examples all show this "aaa authorization exec tacacs+|radius local" command, which my device does not have.So I am wondering if I am not reading the ACS report right, or the device actually was assigned the correct privilge but that does not work without the "aaa authorization exec" command in the configuration?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 RADIUS Network Device Authentication

Apr 19, 2011

I am trying to integrate Cisco ACS 5.2 in a network to do device authentication of switches for administrators.

I am not sure if Cisco ACS 5.2 support RADIUS protocol to do device authentication. In the configuration of the Cisco ACS 5.2 I can only see TACACS authentication for device authentication and  I have configured it and it works. If CISCO ACS 5.2 supports RADIUS auth for device authentication?

View 1 Replies View Related

AAA/Identity/Nac :: ACS 5.3 Single Device On Multiple NDG Groups?

Jan 14, 2013

I have multiple campuses and a Central Admin...I've created Groups for all, except I need a few devices within Central to be available to the Campus Admins... (ie..a Cisco WCS System) How do I allow a device to be put into multiple NDG groups?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 1142 How CDP Device Sensor Probe Works With ISE

Jan 24, 2013

how the CDP device sensor probe works with ISE ?What I am trying to do, is to identify different Cisco Wireless Access Point models (i.e. LAP 1142) with ISE.Since the APs do speak CDP (I can see the AP devices on the switch), this should be possible with the CDP device sensor on the switch, shouldn't it  I have done the following so far: Configured the switch to talk to ISE via radius accounting: [code] Should this config make the switch send CDP information about connected devices to the ISE (via radius accounting) ?How do the device sensors work ?

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Radius Device Administration Error 11033

Jul 20, 2010

I'm trying to configure ACS 5.1 as radius server for a catalyst switch but i can't make it work.I keep on getting the "11033 Selected Service type is not Network Access" error message.
 
Tacacs works fine but radius does not. Any sample device administration config to use with RADIUS?it seem the service type does not work with radius in this scenario ( radius + device admin).

View 10 Replies View Related

Cisco AAA/Identity/Nac :: 3315 ISE Integration With Mobile Device Management

Jul 19, 2012

We are conduction a Proof Of Concept (PoC) on  Secure Bring Your Own Device ( BYOD ) using Cisco ISE and gonna test all the scenarios like Wired, Wireless and VPN user access.
 
Our Setup has  ISE VM acting as Admin, Monitor and Profiling Device, we have NAC 3315 physical Appliance as Inline posture Device, Wireless LAN controller, Access point and the Identity source as Microsof Active Directory.Having Plans to Integrate Mobile Device Management ( MDM ) and Citrix VDI setup also.
 
As of now we have tested the Wired Scenario Authentication and authorization for guest users and gonna carry out the profiling and posture.
 
-MDM can be integrated to ISE ? 
-How the MDM can be integrated to Cisco ISE configuration or Guide to show the same?
-What is the demarcation between MDM and ISE ( i.e. What is the role of ISE and MDM on Mobile Devices ) ?
-If MDM is available so then when the control of ISE ends, does MDM do management or ISE will do management of the devices ?
-Is MDM will do client provisioning or ISE should do ?
-Is MDM send or update patches of Mobile Devices ?

View 5 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Error When Changing Device Group Or Location

Jun 13, 2012

I am trying to move a device from the Default location to a sub group and get the following message when I try (either with IE or Firefox)
 
This System Failure occurred: Index : 0, Size: 0. Your changes have not been saved. Click OK to return to the list page.
 
it also gives me the same error if I try and change the Device type from default to a sub group. I'm sure I could do this previously. The ACS build is (VMWARE install):
 
Cisco Application Deployment Engine OS Release: 1.2ADE-OS Build Version: 1.2.0.228ADE-OS System Architecture: i386
Copyright (c) 2005-2009 by Cisco Systems, Inc.All rights reserved.Hostname: ACS1
Version information of installed applications---------------------------------------------
Cisco ACS VERSION INFORMATION-----------------------------Version : 5.3.0.40Internal Build ID : B.839
 
I'm suspecting it a read/write issue with the database or a database corruption. I have stopped and started the application acs via the console and show application status acs has the following to say about itself.
 
ACS1/admin# show application status acs
ACS role: PRIMARY
Process 'database'                  runningProcess 'management'                runningProcess 'runtime'                   runningProcess 'view-database'             runningProcess 'view-jobmanager'           runningProcess 'view-alertmanager'         runningProcess 'view-collector'            runningProcess 'view-logprocessor'         running

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Managed Device Count Exceeded Error

Jul 6, 2010

I've just installed ACS 5.1 and noticed that it seems to count managed devices differently than previous versions.
 
I have a 500 count license which should be fine as I have about 100 devices which will use ACS for TACACS.  On ACS 3.x and 4.x, I would set up AAA clients by using a wild card for the subnets that host our routers/switches, say 192.168.1.0/24, 172.16.1.0/24 and 10.1.1.0/24.  when I do this with ACS 5, I get a Managed Device Count Exceeded error messasge becasue of the potential of more than 500 AAA clients.  It seems to be counting every IP address in the subnet as a managed device, even if there are only a handful actually in use.  Is there a way around this short of having to manually enter (and maintain) the exact IP Address of every managed switch and rotuer which will use the ACS server for TACACS?

View 10 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 - Radius Attributes And Device Administration / Shell

Sep 18, 2012

Under 'Policy Elements/Authorization and Permissions/Network Access/Authorization profiles' I have defined a profile and the following Attribute:Attribute = F5-LTM-User-RoleType = Unsigned Integer 32Value = 300.
 
My question is:How can I define the same as above using 'Device Administration/Shell Profiles' ?

There is a Custom Attributes tab but I cannot figure out how to specify the 'Type' field. (Under Custom Attributes tab there is only space for 2 fields and not 3 fields).

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Using Active Directory To Manage Network Device Admin

Jun 14, 2012

we've configured an ACS 5.1 and integrated it with active directory Win2K3, we created two groups in the AD for managing network devices one for Administrators and the other for operators (read-only),  so we configured a device admin policy and both groups work fine, but now we are facing a little problem any user who exists in the AD can login (user exec mode) in the network devices and we want to restric the login with the policy, but we just don't know how. Is there a way to get a user be authenticated against external group or internal acs but at user level, just like you can do it in the ACS 4.X?

View 8 Replies View Related

Cisco AAA/Identity/Nac :: WLC 5508 - ISE Alarm / Dynamic Authorization Failed For Device

May 30, 2013

I am using ISE 1.1.1.268 and WLC 7.2.111.3 and NAC agent version 4.9.1.6 on Windows 7 Client machines.
 
About once a day i get the error "ISE Alarm (WARNING): Dynamic Authorization Failed for Device".
 
The device it is referring to is my NAD, a WLC 5508 running 7.2.111.3
 
I have looked at the logs and I cannot see anything in the logs which corresponds to this message so that I can troubleshoot further. Maybe I can if I am enabling the correct logging level on the correct ISE component.
 
What are the components and the logging level that I should set to get some more detail about this error?
 
At the moment, I have only set debug logging on Active Directory. I have TRACE logging set on Posture, Run time AAA & prrt-JNI.
 
I do not want to enable too much debug logs, so what is the specific element that I should be debugging.
 
I thought debugging the posture element would be enough but when I look at the logs there is nothing there that relates to this message.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 / Authenticating Device Admin Users Against AD Specific Groups

Jan 28, 2013

I am using ACS 5.3 What I am about is setting user authentication against existence of the user in specific AD group, not just being a member in any AD. What is happening now, users get authenticated as long as they exists in the AD, luckily they fail on authorization, as it is bound to specific AD group.
 
how can I bind the authentication aginst specific group in AD, not just using AD1 as the identity source.

View 1 Replies View Related

AAA/Identity/Nac :: ACS 5.2 Using AD To Manage Network Device Admin Policy Creation

May 22, 2012

we managed to integrate our newly setup ACS 5.2 to our regional domain.  now im creating a Device Admin access Policy for Regional Network Admin group and Regional Network Operators group. each having full  and read access respectively. 
 
i already have the default  identity policy and authorization policy with with command sets  fullaccess and showonly for each group, now i dont know how can i match the AD group regionaladm and regionalops so that  each user falls under one of these groups will have a correct  read/write access.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: 1113 - Multiple Network Device Groups Using One Windows Remote Agent?

May 4, 2011

I'm working with a 1113 ACS device running the 4.2.0.124 software.  I'm trying to get multiple network device groups to use an existing Remote Agent set up for authentication against our Windows domain.   For instance, we want our infrastructure switches to authenticate agains the local Active Directory and our WLC to authenticate users agains the same Active Directory.  When I try and set both network device groups to use the same remote agent, it fails and reports either the host name is already in use or the IP address overlaps with an existing remote agent.
 
The question is:
 
Can I have multiple network device groups use the same remote agent?   Or do I have to install the remote agent software on separate Windows servers in order to have different types of devices authenticate against the Windows AD? 

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ASA 5520 / Dynamic Access Policy VPN And Management Access

Jun 8, 2011

ASA 5520 to get it to authenticate VPN users against and Active Directory environment plus allow management access as well. I created a Dynamic Access Policy on the ASA stating that if you are a member of the Active Directory group "Managment" the continue. I chagned the DefaultAccessPolicy to "Terminate". So with that, VPN users cannot connect because they are not a member of that group, but the access to manage the ASA is allowed because of that policy.Is there a way through using Dynamic Access Policies that I can allow management access (SSH, ASDM, etc) by matching to a group membership and will allow normal users to VPN in successfully but not allow them access to managing the ASA?

View 1 Replies View Related

Cisco WAN :: 1841 Cannot Read EEprom

May 10, 2011

i have a 1841 Router that hang up @ boot.

Output:
 
program load complete, entry point: 0x8000f000, size: 0xcb80
program load complete, entry point: 0x8000f000, size: 0xcb80
program load complete, entry point: 0x8000f000, size: 0xcdc3e0

[Code].....

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved