Cisco AAA/Identity/Nac :: ACS 5.3 - Configuration Of MAB Table

Mar 25, 2012

Any good link to find how to configure MAB table on acs 5.3? I cannot find one by myself. If it is possible a guide with picture in it.

View 7 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: Use Of Proxy Distribution Table In ACS V4.0

Feb 10, 2013

We are running with Cisco ACS v4.0 AAA server, Here I need the use of Proxy distribution table.

View 5 Replies View Related

Cisco WAN :: WS-SUP720-3B - 2 Full BGP Table - Maximum Routing Table?

Jan 16, 2013

In datasheet of  WS-SUP720-3B - link- was said that are only supported around 256K routes (fib?rib?).With this value I can't get 2 full bgp - that is around 850K ..
 
The supervisor is that control this or just memory ? I said this because I have a 7204-npe-g1 whith 2 fullrouting and 1G of and he are ok..

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Basic Configuration Through CLI?

Oct 21, 2011

step by step ACS 5.1's basic configuration through CLI?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Backup Configuration On ACS 5.2?

Jun 8, 2012

How to backup the configuration on cisco acs 5.2 and how to restore it , if some thing wrong happened

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.x RADIUS VSA Configuration?

Dec 3, 2011

I need to configure RADIUS VSA configuration for a my alvarion device. Following are the attributes that need to be configured.
 
- Packet Data Flow ID (ID 1, integer16)
- Direction (ID 4, integer8)
- Transport Type (ID 6, integer8)
- UplinkQoSID (ID 7, integer8)
- DownlinkQoSID (ID 8, integer8)

[code]....

I was able to configure the first 6 attributes, how can I add the Sub - TLV's ClassifiedID, Priority, VLAN-ID and Classifier Direction which come under Classifier. Don't see any option for that in ACS 5.x

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.x / How To Backup Configuration

Mar 10, 2013

Cisco ACS 5.x appliance?How to back up Config?What is best way, via TFTP? COPY Startup-config tftp:?COPY Running-config tftp:?I currently use Solarwinds CatTolls to back my Cisco Switches, can I use this for Cisco ACS also?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Configuration Web Services

Feb 20, 2013

I am trying to do a query, according to chapter 4 in the ACS 5.3 Secure Access Control System 5.3
 
doing a PUT request have a header of Content-Type: application/xml and my payload is: [code] All I want to do is get a list of users who belong to that group?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Syslog Configuration In ACS 5.2.0.26?

Feb 18, 2012

I want send ACS logs to a syslog server .I have configured syslog under  System Administration --> Configuration -->Remote Log Targets .
 
Name : Syslog Server
IP     : x.x.x.x
Port : 514
Facility Code:Local 6
Maximum length :1024
 
I have open the respective ports also in firewall .But Syslog server is not getting any logs from ACS .I have another log target ,which is ACS secondary server to collect the log from primary and secondary with below config.whch is working fine
 
Name :Logcollector
IP     : x.x.x.x
Port : 20514
Facility Code:Local 6
Maximum length :1024

View 7 Replies View Related

AAA/Identity/Nac :: ACS 5.1 Looking For Sample Configuration

May 30, 2011

I'm having trouble getting Tacacs+ to work correctly with ACS5.1 and a simple catalyst 3750 switch.I can authenticate with AAA, however i cannot get a single command to work once i'm in; "Command authorization failed" even on "enable".

Any useful resource that will walk me through the process?

View 3 Replies View Related

AAA/Identity/Nac :: Cisco 881w - Way To Get AAA Configuration Through Server

Jun 3, 2011

configure AAA (Radius server, access list) There are two devices An access point and cisco 881w. It is necessary to set up authentication through a radius server. You can configure detailed how to do this?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 And 8.2 Remote Access VPN Configuration

Feb 11, 2012

ACS 5.2 , and I can't find document about how to configure remote access vpn authentication in ACS 5.2.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ISE & 3750 Switch MAB Configuration

Jan 16, 2013

I am writting in response to MAB issue which I noticed a few days ago and I am still not able to undestand what exactly happend. First of all I would like to say that I configured MAB authentication and according to the MAC the ISE configure a VLAN. All worked well: the test computer can change VLAN based on its MAC. The problem appear when I cut the connection to ISE server. Accourding to configuration the switch authorize the new device to VLAN 11 (critical VLAN) That is fine ! When the ISE server is up again I had a configuration which should reauthorize all ports assign in critical VLAN. But why that is not happend ??? It looks as the switch didn't notice that the RADIUS (ISE) was up and working again. [code]

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 1120 And RAID Configuration?

Jul 4, 2011

I encountered some strange issues with one of our appliances in the field. Reinstalled and encountered the strange issues. No errors.. did some memory test and the seagate harddisk test and encountered SMART errors. The device didn't log those errors anywhere.. First reason to check the second harddisk. The appliance is shipped with two so the first thing I was thinking of was RAID. I saw that raid wasn't configured. Try to boot the second harddisk and saw that nothing was on that disk.. so what is the mean reason you got two of those? Got the new machine and try some options to configure RAID.You got two options.. didn't see this before, most of the time you got only one option. Raid driver on or no RAID configuration at all. First tried the intel storage matrix, configured both of the disks for mirror and install the ACS 5.2. The machine boots after installs and rejects the DVD. Result: The installation doesn't boot! Checked the partition with gparted but the partition is active (or flagged as boot) Second option was LSI, got the raid configured for mirror and the installation was also completed. Result: working installation. Tried to test if the installation is still working after removing one of the disks. Appliance is complaining the the RAID is missing one disk (so this works). After that the machine tries to boot, result: no working ACS.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: How To Enable ACS 5.2.0.26 Configuration Audit

Oct 12, 2011

ACS and i would like to know how to enable the "Configuration Audit" for someone login to my network devices using their ACS login and i can monitor what they did on it.
  
ACS Version : 5.2.0.26

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ASA 5510 - Cut Through Proxy Configuration

Jan 11, 2009

I would like to configure limited internet access to olnly a select group of Windows AD users. 
 
I beleive cut-through proxy will allow me to do this, just not sure how to configure it on a Cisco ASA-5510

View 7 Replies View Related

Cisco AAA/Identity/Nac :: Recommended VMware Configuration For ACS 5.x

Feb 9, 2012

Are there any recommendations for configuring the VM for the ACS 5.x? What are the required minimum CPU-Cycles to dedicate and also the minimum RAM to dedicate?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Configuration Between ACS 4.2 And ISE Latest Version

Jan 26, 2013

We are a Small company with 400-Users and currently we are using ACS 4.2  at our company.we want to upgrade and use Cisco ISE Appliance instead.
 
I want to know is there any major changes in configuration between  ACS 4.2 and the ISE Latest Verizon.?
 
Is there any Hardware (Switch or Cisco AP ) compatibility issues with using Cisco ISE. (we are currently using Cisco Cat 3550 and Cisco Aironet 2600 APs  with the existing ACS4.2) What ISE Series & what Soft version are the latest so i can order ?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ISE 1.1.3 Configuration Changes Has Been Recorded But Remain Pending

Mar 19, 2013

Cisco ISE 1.1.3 is running in standalone mode, when I made any configuration it show me the notification that "Configuration changes has been recorded  but remain pending" .

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 2960 Configuration Combination Not Working

Mar 3, 2013

We have a configuration that work fine but one of the combinations it don´t work.  When we connect a guest laptop, the first time work fine. The configuration is when the laptop don´t authenticates with radius, the dhcp server assigned vlan guest and ip guest. The first time was ok. After, We connect a laptop with users authenticates work ok, the radius asigned vlan of users and dhcp server assigned ip users. The problem was when we connect for two time a guest laptop, radius didn´t validate and laptop didn´t negociate ip with dhcp server. In this time, the administrator of dhcp server, tell us that they didn´t see nothing traffic of my mac. and anymore run fine. If Whe change the port of switch , the laptup start working again.

Radius=NPS
Server dhcp: is typical.
 
Our scenario is with a ip cisco phone. the ip phone don´t have the authentication. The administrator of radius tell us that the configuratation is fine and the configuration of dhcp is fine. When we connect only laptop, everything run ok.
 
Configuration Port.
 
interface GigabitEthernet1/0/3
switchport access vlan 202
switchport mode access
[Code]...

View 4 Replies View Related

Cisco AAA/Identity/Nac :: NAC 4.9 Invalid Switch Configuration OOB Error

Dec 10, 2012

I am having the Cisco NAC enviroment (Software Version is 4.9.1) and OOB VG.
 
We are getting the below and attached Error while deploying on some machines.
 
"Invalid switch configuration-OOB Error:OOB client "mac/ip" not found."
 
Some users on same switches are working fine but some are not....
 
What would be the possibilities and any work around? other than keeping the port shudown for long time means that atleast 10 - 20 secs or more or a PC restart. Customer is not feeling comfortable with the current situation.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 Configuration With Windows 2003 Active Directory?

Apr 22, 2011

i have installed system (Windows Server 2003) and i have configure Active directory for testing and configure one user under it ( TEST01)now on the same machine i have installed Cisco ACS 4.2.i'm trying to Authenticate (TEST01) using ACS but it's not working, i can't even see the logs under EVENTVIWER.  simple and easy to configure since both AD and ACS is on the same machine.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS5.2 - Allow Show Running Configuration Without Enable

May 24, 2012

I am using ACS5.2 I want user to access the device with all necessary command like show run/ver/int/log… I try to set user privilege using Shell from 1 to 10 but show run doesn't work.

View 15 Replies View Related

Cisco AAA/Identity/Nac :: Delete Proxy Configuration On Secure ACS 4.1 For Windows?

Feb 6, 2012

We have a pair of ACS 4.1 servers (Windows Server 2003 R2). Let's call them ACS1 and ACS2. We don't want either one of them to proxy to any AAA server, including each other. We're using mostly TACACS authentication.
 
While troubleshooting a general problem, I'm guessing that one of us did this on ACS1:
 
pressed the Network Configuration button,saw the Proxy Distribution Tableclicked (Default)moved ACS1 from the AAA Servers column to the Forward To column. 
So, essentially, we're telling ACS1 to proxy all requests to itself, which doesn't seem to make sense. I don't know for sure whether it should work when configured to "self proxy," but in that state, it does not authenticate anyone and gives merely "Internal error" as the reason.
 
If I change the configuration so that "ACS2" appears in the Forward To column, and I move "ACS1" back to AAA Servers and restart, ACS1 starts responding correctly to TACACS requests. Of course, ACS1 is just proxying all requests to ACS2, so having two servers isn't doing much good.
 
I cannot simply remove ACS1 from the Forward To column and leave it empty. The interface complains that it can't forward to zero servers. Of course, on ACS2, there are no servers in the Forward To column, since we never touched the Proxy Distribution Table there.
 
Is there any way to return the Proxy Distribution Table to its default setup, that is, no servers appear in the "Forward To" column?
 
We're planning to upgrade to version 4.2 very soon, so this question is mostly academic, unless the same problem exists in 4.2.
 
For full disclosure, I should mention that the problem we were troubleshooting was loss of connectivity to our Windows Domain Controllers from our ACS servers. We had missed adding some exceptions in our firewalls to allow for four new DCs. As far as we can tell from testing, connectivity to the DCs is now fine. The firewall rules group ACS1 and ACS2 together, so connectivity should be the same, and ACS2 authenticates users correctly.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ASR 9010 Configuration To Connect To A Tacacs+ Server

Jun 10, 2013

We have an ASR 9010 with IOS XR, and we are making the configuration to connect to a tacacs+ server, this tacacs+ server works and is givins service to many other MPLS equipments. We have been following the guide:
 
Configuring AAA Services on
Cisco ASR 9000 Series Routers
 
but we have had a lot of troubles, in fact we have loose the administration of the box, at this moment the only lines that are in the ASR900 are: [code]

View 8 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Primary-secondary Radius Server Configuration

Apr 21, 2013

I have a couple of ACS 5.2 configured as active and backup and I am   doing dot 1x authentication using these servers . I have configured the  switch with the bellow configuration.
 
radius-server host 10.0.10.15 auth-port 1645 acct-port 1646
radius-server host 10.0.10.16 auth-port 1645 acct-port 1646
radius-server key 7 aaaaaaaaaaaaaa
 
please help to understand what will happen in switch
 
1) in case of primary failure
2)in case if primary returns alive .

View 8 Replies View Related

Cisco AAA/Identity/Nac :: 3845 - Enable Secret Password Missing In Configuration

Jun 23, 2011

Recently I came across a router (Cisco 3845,  IOS 12.4) configured for TACACS, one local username and an enable  password. Going through the configuration I noticed the router didn't  have an enable secret password which I thought was strange. The TACACS  config is below, comments regarding the  TACACS config and the consequences of not having an enable secret or if  there is a need for one.
 
aaa authentication login default group tacacs+                                  aaa authentication login no_tacacs enable                                       aaa authorization exec default group tacacs+                                    aaa authorization commands 1 default group tacacs+                              aaa authorization commands 15 default group tacacs+                             aaa accounting exec default start-stop group tacacs+                            aaa accounting commands 1 default start-stop group tacacs+                      aaa accounting commands 15 default start-stop group tacacs+                     aaa accounting network default start-stop group tacacs+

View 7 Replies View Related

Cisco Firewall :: ASA 5510 Identity NAT Configuration For Remote Access VPN And Site-to-Site

Mar 9, 2011

I am try to configure ASA 5510 with 8.3 IOS version.My internal users are 192.168.2.0/24 and i configured dynamic PAT and are all internet .

i want configure identity NAT for remote access VPN.Remote users IP pool is 10.10.10.0 to 10.10.10.10
 
i know to configure NAT exemption in IOS 7.2 version. But here IOS 8.3 version. configure NAT exemption for 192.168.2.0/24 to my remote pool( 10.10.10.0 to 10.10.10.10).

View 6 Replies View Related

Cisco :: Nexus 5K Mac Address-table?

Aug 20, 2012

Can someone throw me a bone on what might be occurring here?

View 7 Replies View Related

Cisco :: BGP Routes Not In Routing Table?

Feb 4, 2013

We have a BGP / OSPF configuration as shown in the topology picture. When the connection towards Internet is taken down, we expect the traffic to be forwarded toward WAN 2 (preferred) or WAN 1. The problem is that the BGP learned routes disappears when the Internet connection is taken down. The IP routing table on R2 only shows internal networks and the networks between R2 and WAN 1 and 2. No routes to internet is shown. We run "show ip bgp neighbors <ip-to-wan-1-router> received-routes" it contain internet routes. And when we run "show ip bgp neighbors <ip-to-wan-1-router> routes" it contains no routes at all.

View 2 Replies View Related

Cisco :: Show Dynamic PAT Table?

Nov 6, 2012

Trying to get a Cisco ASA 5505 to show me all the current dynamic PAT. (I don't want to see hard-coded port forwarding, just dynamic stuff the router is doing to allow various hosts on the network to talk to the WAN.)

View 8 Replies View Related

Cisco Switches :: ARP Table Limit In SG 300-10?

Mar 24, 2013

When we configure a SG 300-10 switch in layer 3 mode to do so some static routing, I would like to know the ARP table limit (association between IP address and MAC address) ? The documention talks about MAC (association between MAC and port) table limit, routing entries limit ... what about ARP limit ?

View 1 Replies View Related

Cisco WAN :: Full BGP Table With 6500

Feb 19, 2013

My comany is planning get full bgp table from our providers we have mutliple egress providers in order to load balance we are looking for a full table from all of them what would be minumu requiremts we have all edges as 6500 with sup 720 ,is there any memory requrements that need to be upgraded ??

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved