Cisco AAA/Identity/Nac :: ASDM 6.5(1) For ASA-SM Doesn't Support RSA / SDI Authentication

Apr 23, 2013

I'd like to configure ASDM access to ASA-SM using RSA SecurID authentication.I've followed instructions in this documen [URL]When I test access from CLI everything looks fine:
 
asa-vss/admin/act# test aaa-server authentication RSA
Server IP Address or name: xx.xx.xx.xx
Username: testuser
Password: **********
INFO: Attempting Authentication test to IP address <xx.xx.xx.xx> (timeout: 12 seconds)
INFO: Authentication Successful

[code]....
 
When I try to use ASDM, I'm unable to login and I can see lot of authentication error (Token reuse) messages on RSA server monitor window.It looks like ASDM 6.5(1) for ASA-SM doesn't support RSA/SDI authentication.

View 9 Replies


ADVERTISEMENT

AAA/Identity/Nac :: Cat4500e ISE Support On Third Party Switch Doing 802.1x Authentication On Interface

Jun 8, 2013

how ISE support on third party LAN switch, if the requirement is doing 802.1X based flexauth.Refer to the diagram i attached; 01 topology.png
 
Concern  1: if the 3com switch with 802.1X feature, but still without the full  feature to support FlexAuth, policy encforcement, DACL etc. In this kind  of situation, will user still able to authenticate (using method  PEAP-MSCHAP v2), but authorization just grant with permit any any?
 
Concern  2: Can i assume i authenticated the 3com switch using  MAB? But this will cause endpoint with no 802.1X, am i right?
 
Concern  3: cisco switch C4507-E, loaded with IOS version  Cat4500e-UNIVERSALK9-M, version 03.04 and Supervisor Engine  :WS-X45-SUP7-E, is this platform is supported in Cisco TrusctSEC?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS V5.3 Identity Selection For Authentication?

Jan 16, 2012

I configured before ACS v4.2 to authenticate network devices using internal users at first, and if the user is not found use AD list users.  But with v5.3 I have some problems doing this, on identity policies I use rule based result selection option, I configured 2 polices for Identity source, one for Internal Users and other policy for AD user, but it only works with the first policy, internal users or AD, but works only for the first policy identity.  how to do that, if the user is not found on first policy, continue to the next policy.

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Identity Base Authentication

Jul 3, 2011

I need a specify users to allow access to particular devices and give privilege only for show command or show run. Here is how I tried to configured.
 
1. Configured two seperate Shell Profile and Command set with privilege level 4-5 and allowing only show run command

2. create seperate service selection rule with adding the require NDG and protocol TACACS and maching service "RestrictAccess"

3. In the RestrictAccess Service I have following configured; Identity: internal users, Group Mapping to a particular group where the user exists, authorization: matching the above created identity group, NDG, shell profile, command sets
 
All the steps are attached in the .doc file. However when I tried with the particular user he is able to access everything and he is not hitting the correct access rule.

View 6 Replies View Related

Cisco AAA / Identity / Nac :: How To See Login History On ASDM Or ASA5510

Apr 22, 2013

How to see the ipsec vpn client users login history, they are authenticating to the local AAA, not to active directory. I am able to see current login session. by going to monitoring vpn statistics sessions this shows me current sessions but I would like to see for example logins for vpn client for the last month.

View 11 Replies View Related

Cisco AAA/Identity/Nac :: Setup AAA For Anyconnect With Active Directory On Asdm 6.4

Aug 20, 2012

Im sure this has been asked before but a quick search has not yielded any exact results so here goes
 
I have anyconnect up and working great on for vpn users using local authentication. Im going over the white papers and seeing a lot of options for NT domain, LDAP, tacacs+ etc
 
we would like remote vpn users to autherticate using their windows domain password, but Im not sure which would be the easiest and quickest option to configure, and I cant find a guide for asdm setup for this topic that doesnt cause more questions than answers . The white papers Im finding are confusing since I am a rookie at this topic.
 
what is the easiest/quickest way to setup windows domain authentication via asdm?

View 1 Replies View Related

Cisco Switches :: SG200 Support For RADUIS Device Authentication

Dec 6, 2011

I am unable to successfully authenticate my SG200 to either a Cisco ACS or Windows2008 RADUIS server. (C3750x on the same network authenticates fine).

Q1. Is this feature (management login authentication to a RADIUS server) supported on the SG200?

Q2. Is so is there any configuration guidance available for both the SG200 and CSACS / WindowsServer2008 NPS?
 
I hav not got as far as 802.1x uthentication yet, but config example of this would laso be useful.

View 1 Replies View Related

Cisco WAN :: 887 Doesn't Support Show DSL Command?

Jun 26, 2011

The Cisco 887 doesn't support the show dsl command, what is the command that I need to use to display the speed my ADSL is operating at? On the Cisco 877 the command I use is show dsl int atm 0 but this doesn't work on the 887

View 4 Replies View Related

D-Link DIR-825 :: Login Page Doesn't Show Authentication Picture

Nov 29, 2011

i have a dir 825 with fw 2.00eu that i wanted to upgrade to the new beta fw.i went to tools and did a factory reset first,when i wanted to log back in to load the new fw,it sudenly asks for a authentication code,problem is the field is marked with a red x so i cant see any code i'm using windows 7 and IE 9?

View 5 Replies View Related

D-Link DIR-655 :: Router Doesn't Support Network

Jan 19, 2011

I have decided to buy a new wireless N enabled wireless router after my house was cleaned out by some robbers. After a long investigation I decided on the D-link DIR 655 as it suited my basic needs the best and since I haven't decided on a broadband supplier yet this should sort any and all possibilities no matter what I choose...

After an equal amount of investigation I decided on a HSPA+ USB dongle only to find that the router does not support the network I have purchased it on. It thenalso seems that it doesn't support the E1820 Huawei dongle either... so fine... I go and buy a Huawei D105 tht should technically be able to connect via the WAN port and would act as an internet gateway. Brilliant.

Now I have tried everything.... static IP on the D105 with a static IP setup on the 655. Connects fine... according to the web interface but NO INTERNET. When I connect my laptop directly to the 105 via CAT5 it works beautifully. DHCP on the D105 with the same on the 655. Connecting... Establishing Link (Please Wait...) FOREVER without ever getting an IP on the 655 (according to the web interface again) ... must be the D105 thats faulty so again plug in the laptop and within milliseconds the IP is assigned and Internet is blazing along again.... The D105 is not Wireless N so I cannot use it as my primary AP and only allows 5 simultaneous wireless connections (that is reserved for my cellphones). Why should I anyway?? the DIR655 should work fine....

Even after having taken it to D-link support at huge cost and effort I still don't have a working rig.... Seems the consultant plugged the D105 straight into the LAN on the 655 and then set his laptop to the same static range to get it to work... SURPRISE - I know that works since plugging the laptop straight into the 105 does the same thing.... But this is not what I want... I want my 655 to be the primary DHCP server for my network and control the allowed workstations that are allowed access to the internet with a working gateway. Bridging is apparently also not an option as that option has been removed so I cannot even bridge my main subnet onto the D105's internet sbnet... What am I to do....

If the 655 3G setup supported more than 2 dongles I might hve been able to use that and not spend anouther R600 on the D105, if the WAN port actually worked in either static or DHCP modes with the D105 that also would have solved the problem and lastly if all else fails and there was still bridging I could hack my own setup together to do what I want. Seems like I was wrong in selecting the D-link product.

Then to make matters worse I find another product with double the features online for half the price that integrates the 3G capability into the route and support more than 2 different models. including all the new Huawei dongles....

View 2 Replies View Related

Cisco Routers :: RV042G Doesn't Support Passwords That Contains Spaces

Jul 6, 2012

I've discovered that the DDNS update client in the RV042G does not support passwords that contains spaces. This is the first router I've run into that didn't like it.

View 1 Replies View Related

Cisco Infrastructure :: Datasheet 4500 Doesn't Support Reflexive ACL

Jul 20, 2011

There is a vlan Finance in my office. The requrement : Vlan Finance is allow to access internet and selected host/network and not allow to access internal network. But from internal network can access to Vlan Finance (Full access). I want to configure using Reflexive ACL, but from Datasheet 4500 doesn't support Reflexive ACL. Intervlan routing is in 4500. Is there any ACL configuration to support my requirement without using Reflexive ACL?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Web-authentication Using ASA And ACS 5.1

Feb 2, 2012

In order to restrict access to websites on our internal network, would we be able to put an ASA in front of the web server and force users to authenticate through the ASA and, once authenticated, allow only port 80 or 443 traffic for that use?  The ASA would query the ACS 5.1 server for authentication/authorization using AD as the identity store.  Is this even possible with TACACS? 

View 1 Replies View Related

Cisco AAA/Identity/Nac :: MAC OS-X And Authentication Via ACS 5.2?

Apr 1, 2012

My customer has a large installed base of MACs, all connected via controller-based (5508) WLAN. He wants to grant access to the network based on the device's mac addresses and move the WLAN-clients to a specific VLAN.I added all devices with their mac addresses to the ACS internal identity store for hosts.According to the following message the client sends the user-login credentials (chegger) within the RADIUS-request instead of the clients mac address and of course it has to fail.  After many configuration changes, I ended up always with the same result.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: EAP-TLS Authentication With ACS 5.2

Jun 13, 2012

I have question on EAP-TLS with ACS 5.2. If I would like to implement the EAP-TLS with Microsoft CA, how will the machine and user authentication take place? Understand that the cert are required on both client and server end, but is this certificate ties to the machine or ties to individual user?
 
If ties to user, and I have a shared PC which login by few users, is that mean every user account will have their own certificates?
 
And every individual user will have to manually get the cert from CA? is there any other method as my environment has more than 3000 PCs.
 
And also if it ties to user, all user can get their cert from CA with their AD login name and password, if they bring in their own device and try to get the cert from CA, they will be able to successfully install the cert into their device right?

View 7 Replies View Related

Cisco AAA/Identity/Nac :: AD Authentication In ACS 5.3

Jan 22, 2012

I have a new ACS 5.3 installation which I have joined to our AD Domain and added the directory groups into.  I have also added all our devices into ACS and their groups etc but I am still only able to authenticate on the our switches with an internal ACS account, when I try with an external AD account the log shows the following error   "Subject not found in the applicable identity Store (s)"

View 1 Replies View Related

Cisco Switching/Routing :: WAG54G2 Doesn't Support A Subnet Mask

Dec 13, 2011

We have 10 ADSL lines and 5 of them goes in the load  balancer (One gateway) and the rests are used as default gateways for  internet access. We use ADSL routers as access points for internet, but those routers  should be part of our network and should be given an address in order  for them to act as default gateways for internet access. I'm facing a  real prob with the ADSL routers Linksys WAG54G2 because they doesn't  support a subnet mask 255.255.0.0 Any recommendation for an ADSL router  model that support a netmask 255.255.0.0 ?
 
My cisco 2811 router interface configuration ip address: 172.20.0.1 255.255.254.0.Load balancer output lan ip address: 172.20.0.5.My ADSL routers will be in the following range : 172.20.0.6 - 172.20.0.10

View 1 Replies View Related

Cisco Wireless :: 1200 DAS Mobile Access 2000 Doesn't Support

Apr 2, 2012

The client currently has DAS solution integrates with cisco ap1200 which has been eos. As per my knowledge DAS mobile access 2000 doesn't support. 802.11n, is this correct? We are planning to separate the dad environment with cisco. Basically positioning new 3600 n indoor AP to replace existing eos 1200. What are the pro and cons of separating two brands and solutions? Other cabling.The client having coverage issue and adding an amplifier and cable loss may add more issues to existing environment.
 
Also, based on experience 80211n AP are required is higher density vs 1200.What are your thoughts or best design option to separate das from WLAN environment?

View 6 Replies View Related

Linksys Wireless Router :: EA4500 Guest Network Re-authentication Doesn't Work

Sep 15, 2012

I have successfully set up a guest network on my EA4500. Guest laptop associates with guest SSID just fine. Then via IE, it gets prompted for the guest password, which is entered and accepted just fine. At this point guest laptop is on the network.
 
BUT... at some point the guest laptop will need to reauthenticate (I don't know what the timeout is, but maybe one or two days?). Anyway, it's at this point that IE presents the guest network login page. But now after typing in the password, "enter" or clicking on the button does nothing. It looks like the guest web page doesn't get loaded properly or completely, so the reauthentication can't complete, therefore can't get to the internet. So, while in this state, I've also tried Firefox and Chrome, and same thing, no action when trying to submit the guest password. Tried rebooting guest laptop, and still same problem. Only thing I've found so far that works is to reboot the router. So I'm guessing there's a problem with the guest/web server on the router?? It's a real pain to have to reboot the router every day or two, when I've had other Linksys routers run for months without having to touch them.
 
I was running CCC 2.1.38 when I first noticed the problem. Since then I've downgraded to Classic 2.0.37, but it seems I still have the same problem. Again, I can connect & authenticate just fine initially, but when reprompted after some period of time, it doesn't work.
 
I've tried contacting Cisco support, but it looks like I'm at 91 days since purchase and thus outside of my 90-day complimentary support, so they happily provided me with the premium support options just to have the honor of talking with them. Guess I shouldn't have spent so much time trying to figure this out myself.

View 9 Replies View Related

Switches On A Network Doesn't Support Remote Port Mirroring?

May 2, 2011

If switches on a network doesn't support remote port mirroring and only local port mirroring, What are the options to still capture all the traffic from all switches on 1 single core switch?

View 1 Replies View Related

AAA/Identity/Nac :: Cisco ACS 5.1 And RSA Authentication Manager 6.1?

Apr 18, 2010

We  got recently a Cisco Secure ACS 1120 and i upgraded the Appliance to 5.1 from 5.0 with all your support
 
Now I need to integrate Cisco ACS 5.1 with RSA Authentication Manager 6.1 . I Successfully Downloaded config file from RSA ACE Server and exported into ACS 1120.
 
I also Added ACS as a NetOS Agent in the RSA Server , during the process i found few warnings . The ACE Server is not able to Resolve the IP Address to NAme ( DOes it Necessary ?? ).
 
I havent created any secret Key file for communication between ACS and RSA and encryption i used is DES.
 
Now when I log into ACS and search for Devices in the Identity Store Sequences i am not able to Look for RSA Token Sever .

View 10 Replies View Related

AAA/Identity/Nac :: IPS / IDS Authentication With Cisco Radius ACS 5.2

Nov 22, 2011

I have been trying to get our IPS (ASA-SSM-10 and 4260) to authenticate with Cisco Radius ACS 5.2 and they are not working. However, I was able to get them working with Microsoft Radius. Below is the logs from the IPS:
  
evStatus: eventId=1321566464942057375 vendor=Cisco  originator:    hostId: NACAIRVIDLAB1    appName: authentication    appInstanceId: 350  time: 2011/11/23 17:50:38 2011/11/23 09:50:38 GMT-08:00  controlTransaction:

[Code].....

View 0 Replies View Related

Cisco AAA/Identity/Nac :: Re-authentication In End Points Using ISE 1.1

Dec 13, 2012

If laptop/desktop goes on sleep mode or keep connected with interface configured for 802.1X for more than 12 hours it does not work or not connect to Exchange server, Cisco ISE console, office communicator..for re authentication i need to restart PC/ Laptop or unplug and replug lan cable from it!but before restarting i am able to ping all DNS, DHCP, OCS, everything..[code]

View 6 Replies View Related

Cisco AAA/Identity/Nac :: Two Factor Authentication On ACS 4.x / 5.x

Mar 9, 2011

I would like to konw does Cisco ACS 4.x / 5.x natively support Two factor authenication, but not act as a Radius Proxy?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Limit AD Authentication With ACS 5.3

Feb 23, 2012

I need to limit to some AD groups, authentication with ACS 5.3.For example, i need that only users os somedomain.com/users/test1 are authenticatet via ACS --> ADS.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 And TACACS + Authentication From VPN?

Mar 4, 2012

I have a Cisco ASA (8.2) setup with remote access for my users using Cisco VPN client. The authentication is passed off to my ACS 5.3 which then checks with AD. What I've done so far is create Access Policy rule where I define specifically the Location and NDG where the ASA is and then a DenyAllCommands command set. This should pass authentications just fine but this also gives those users the ability to remote connect directly into the ASA and login successfully. Even though there is a Deny Commands there I still would prefer they get Access Denied as a message. If I do a Deny Access on the ShellProfile then this stops the login authentication altogether.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: 881 - ACS Authentication Across VPN Tunnel

Jun 14, 2011

We would like to enable ACS authentication to login to different routers (Cisco 881s) we got that are interconnecting with our WAN via VPN tunnels. We would like to avoid using public IP for the router to communicate and relay user/password info with the ACS server and rely on the server's private IP instead. The problem is that all the router's outside interfaces connect to the Internet using public IPs and when the router wants to communicate with the ACS server it will use its public-facing interface IP and that'll fail. We can ping the server obviously when we set the source to the internal LAN IP.
 
The question is is there a way to have the router communicate with ACS across the VPN tunnel using its private IP?
 
config being used and tested succesfully on local devices:
 
aaa new-model
tacacs-server host 10.x.x.x single-connection key xxxxxx
aaa authentication login tacacs-local group tacacs local

[Code].....

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Re-authentication Not Working?

Aug 17, 2011

I have a dot1x client with client certificate working well with my ACS 5.2 and EAP-TLS. Now I would like to configure the Re-Auth periode on the ACS 5.2, I did the following:
 
1. Configure a Access Profile with Reauthentication Timer = static and 30 seconds (see attachment ACS1.png and ACS2.png)
 
2. Enabled authentication periodic and authentication timer reauthenticate server on switchport
 
interface GigabitEthernet1/0/x
description to dot1x clients
switchport access vlan 5
switchport mode access
authentication event fail action authorize vlan 998

[code]....

View 2 Replies View Related

Cisco AAA/Identity/Nac :: SSH Authentication From ASA5505 To ACS 5.3 Not Using PAP

Aug 8, 2012

i am evaluating ACS 5.3 with an ASA5505, by using password management in the IPSec tunnel config i am able to authenticate the VPN clients using mschapv2, however, the SSH sessions are authenticated using PAP
 
I have looked for days and days for an answer without success, is this by design?
 
Cisco documents state that SSH can be authenticated via  TACACS with PAP,CHAP or MSCHAPv1, however, It seems to be default to PAP
 
From Cisco Doc: TACACS+ Server Support # The security appliance supports TACACS+ authentication with ASCII, PAP, CHAP, and MS-CHAPv1

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Dual Authentication - ACS 4.1 And ACS 5.1

May 13, 2011

I am getting ready to install a new ACS 5.1 server to replace my current 4.1 acs box. I wanted to start off with a fresh install rather than upgrading all of my 4.1 data.
 
Can I have devices (ASA for VPN authentication, routers & switches for user authentication) use both for authentication while I get all the users configured in the new box?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Radius Authentication In ACS 5.2 With AD

Mar 10, 2011

I have a questión about radius authenticaction with AD, when I log in into the network with user in AD and I make a mistake in password my radius authenticaction event in ACS 5.2 dont show me this logg. only show the authentication succeeded but dont show me the authentication failed. Maybe i must to enable same service to show the authentiaction failed. The Voice authetication works fine..
 
This is the confg in the port of the switch:
 
interface FastEthernet0/12 switchport mode access switchport access vlan 2 switchport voice vlan 10 authentication port-control auto authentication host-mode multi-domain authentication violation protect authentication event fail action authorize vlan 11 authentication event fail retry 2 action authorize vlan 11 authentication event no-response action authorize vlan 11 authentication periodic authentication timer reauthenticate 60 mab dot1x pae authenticator dot1x timeout tx-period 10 dot1x max-reauth-req 3 spanning-tree portfast end
 
Vlan 2: DATA
Vlan 10: VOICE
Vlan 11: GUEST

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Authentication Error In ACS 5.3

Sep 7, 2012

I configured ACS 5.3 and added AAA clients with TACACS+ server and shared secret key as cisco123. i did the below config on switch also. when i try to authenticate login with ACS it does not respond. Find the configuration and debug output.nd
 
In debug output it gives ruser and rem_addr is null. i did not understand why .
 
I am able to ping to ACS server and i used telnet 192.x.x.10 49 and it gives the proper output.
 
aaa new-model
aaa authentication login default group tacacs+ local
!
tacacs-server host 192.168.60.10 key cisco123
tacacs-server directed-request
ip tacacs source-interface Vlan172

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ASA 8.4(4) Public Key Authentication

May 22, 2012

I notice 8.4(4) now has public key authentication (just like IOS - yay!) and found a couple of issues: The CLI config guide [URL] states incorrect syntax for adding the public key to the ASAThere is an undocumented ASA limit on the public key size supported 

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved