Cisco AAA/Identity/Nac :: Best Method Of Migration From ACS 4.1.(1) Windows To ACS 5.2

May 9, 2011

we currently have 4x ACS 4.1 (1) build 23 windows based and we are going to migrate to ACS 5.2 appliance 11211.the first pair we are using simply local authentication for multiple vendor firewall and routers, with one custom radius vendor-specific attributes, with now she exec.the second pair we are using for wireless clients authentication through AD, with dynamic mapping.
 
 in order to migrate what would be the most suitable migration, whether to use Migration utility or export those ACS objects and import them into the new ACS 5.2.

View 1 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: Method To Control Access To Different WLAN On Same ACS 5.2 And WLC

Aug 6, 2012

is there any method to control an access to the different WLAN(PEAP) on the same ACS 5.2 and WLC?That is, there is two AD groups the one have access to domain network only the other group have access to internet only and may be third group that have access to both networks.Currently if i add new authorization policy the user will have access to both networks.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS Server 5-2 Appliance Gentle Shutdown Method?

Mar 29, 2011

I need to move our (secondary instance, version 5-2) ACS server to a different server rack and I have not been able to find a gentle way to shut down the appliance (not the windows version).  Does one exist or is it just the power button/cord?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Best Way To Do Migration

May 19, 2013

I have an ACS 5.2 deployment and i want to upgrade it to 5.4 version.I have 2 server in my deplyement:
 
1/ Primary Server as Authentication server & log collector

2/ Secondary server as Authentication server.
 
What is the best way to do the migration? Normaly, i can proceed as follows:
 
1/ Deregidter each server from the deployement ==> Make both the servers standaone
2/ Upgrade the Secondary server.
3/ Upgrade the Primary server (without migrate the log server).
4/ Join Servers to the deployement.

View 11 Replies View Related

Cisco AAA/Identity/Nac :: Migration From ACS 4.0 To ACS 5.0?

Mar 22, 2011

what is the key point to note for migrating data from ACS 4.0 to ACS 5.0? how can I use Migration utility to migrate data from old version to new version??
 
I have ACS setup running with 1000 devices and more than 2000 users and 60 groups dont want to build new acs from scratch want to import data from old version?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS Migration From 4.1.1.23 To 5.2?

Jan 14, 2012

I need to upgrade my ACS for windows 4.1.1.23 to 5.2 as we have come across the windows 2008R2 AD problem. Now reading the migration document it says I need  to go to at least 4.1.1.24 first which will not be a problem, then I need a migation server, so that means I need another ACS server as the migration server. As I already have 2 ACS servers could I use one of them as the Migration server, ie take it out of production?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 Migration To 5.3

Jun 11, 2012

If we need to migrate ACS 4.2 installed on appliance 1113 to ACS 5.3 what all the prerequisites...?

whether any hardware dependencies and the same configurations on 4.2 could be operated on 5.2 even after appliance changes...?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS Migration From 4.1 To 5.4

Jun 12, 2013

I need to Migrate from ACC 4.1(1) to ACS 5.4, Have configured Network Access Restrictions and Networks Access profiles in ACS 4.1(1), can i go for staright away migration and is the same supported in ACS 5.4

View 5 Replies View Related

Cisco AAA/Identity/Nac :: Data Migration From ACS 4.2 To 5.2?

Jul 1, 2012

We have to ACS cisco Box running software as 4.2 & 5.2. We want to upload all the data present in 4.2 ACS to 5.2 ACS.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: Migration From ACS 3.3 To A New Machine

Jun 13, 2011

I'm planning migration from ACS 3.3 to a new machine, so I'm thinking about new Cisco ISE.I have the following question: ACS 3.3 acts as AAA RADIUS with LDAP repositoriy for wireless deployment, using PEAP-GTC. Is possible, with ISE, to use a different EAP method, such as PEAP-MsCHAPv2 or EAP-TTLS?
 
 In ACS 5.X I think it's only supported PEAP-GTC and EAP-TLS when identity repository is LDAP. Is the same in Cisco ISE?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS Migration From 4.0 To 5.3 With High Availability?

Oct 1, 2012

One of my customer wants to upgrade their Cisco ACS version from 4.0 to 5.3. The client has existing ACS version 4.0 windows on VM with two instance and need to upgrade to 5.3 Linux.As per my understanding following version are supporter to upgrade ACS to version 5.3 ACS 4.1.1.24ACS 4.1.4ACS 4.2.0.124ACS 4.2.1 but unfortunatlly there is running 4.0.I suggested to my client the upgradation for ACS and proposed this Upgrade lisence L-CSACS-53VMUP-K9 and CON-SAS-CSACS3V? how I can do the smooth deployment / Migration from 4.0 to 5.3 with (A/P)high availability.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Migration VPN From ACServer 4.2 To ACSystem 5.3?

Jul 18, 2012

I'm using Cisco Secure ACS 4.2 for Windows to configure and authenticate VPNs external groups and users on VPN 3K concentrator.Now I'm migrating to AC System 5.3.I'm trying to configure the new system to do the same work.

I have configured a new access profile with all RADIUS attributes, than an access policy.IPSec Phase 1 completed successfully but VPN client doesn't procede with XAUTH.ACS View reports the correct rule and access service.

View 7 Replies View Related

Cisco AAA/Identity/Nac :: Migration Of Shared DACLs From ACS 4 To 5?

Mar 7, 2012

Is there a simple way to migrate shared dACL to group/user mappings from ACS 4 to ACS 5? After migration using the Migration tool provided by Cisco I get shared dACLs and also I get all my users/groups transfered but these shared dACLs are not mapped to groups or users as previously. I understand that in new ACS we do not apply authorization directly to users/groups, but then if I had in ACS 4.x a hundreds of groups and each of these groups had a dedicated dACL (shared) applied as authorization attribute now after migration to ACS 5 I have to create separate authorization profile for each of these groups which is a lot of manual work. So I'm asking for an easy automated way to migrate authorozation rules  to new ACS version.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Cannot Access WLSE After Migration

Nov 30, 2011

I cannot access WLSE, after migration from ACS 4.2 to ACS 5.2. WLSE was configured with tacacs+ management. In ACS 5.2 I've configured the optional custom attributes: groups = "System Admin"

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Migration ACS 5 Appliance To ACS 5.1 Vmware

Jun 7, 2011

I'm with problems to migrate the ACS 5.1 hardware to  ACS 5.1 vmware. In my infraestructure I have a appliance with ACS 5.1 and I need to migrate to vmware to do HA. I installed vmware as the Cisco ACS recommendations. I made ​​a backup of the ACS hardware and copied the local disk vmware ACS.
 
When I start the restore process after a few minutes an error occurs:
 
UMA/admin# dir
Directory of disk:/
    33293306 Jun 08 2011 16:51:38  bkp-production-110608-1433.tar.gpg
       5862 Nov 07 2009 01:06:32  favicon.ico.1
      16384 Jun 06 2011 17:54:34  lost+found/
[Code]....

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Migration Utility Fails On ACS 4.x Server ID?

Dec 21, 2010

I am working through the migration from ACS 4.1.4 on Windows Server 2003 to ACS 5.2 on the appliance.  I have created the 4.1.4 migration server, installed the software and imported the data from our production ACS 4.1.4 box.  I downloaded the migration utility from the 5.2 ACS server and am attempting to run on the 4.1.4 migration server.  The question that fails is:
 
Enter ACS 4.x Server ID:
 
I do not know what this means and do not see anything on the 4.1.4 server that identifies the Server ID.  I try localhost and it does not work and the 4.1.4 server is not registered in DNS or I would try that  (and . are not valid characters in the ID so the IP does not work).
 
How have other people handled this question?  Is there something that can identify the local server ID?

View 9 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Migration Utility TACACS+ Enable Password

Jul 26, 2012

I am trying to migrate an ACS 4.1.1(24) using the migraton tool to ACS 5.2. The tool is working OK. It migrates the users, groups, NDG, etc. and the reports are showing no errors.
 
The problem is with the Enable password of the users. The users in the ACS 4 have the TACACS+ Enable Password configured, but after the migration it appears empty in the ACS 5.

View 3 Replies View Related

Cisco :: Migration From Windows LMS 4.0.1 To Appliance 4.1?

Oct 4, 2011

Can't see this in the documentation, as only Solaris to soft appliance is mentioned, so does anyone know if you can migrate data from LMS 4.0.1 on Windows 2008 to the soft appliance on LMS 4.1?

View 1 Replies View Related

Cisco :: LMS 4.1 Data Migration From Windows To UNIX OS

Dec 13, 2011

I was using CiscoWorks LMS4.0 on a Windows server 2008 R2. Now I wanted to do an upgrade to the newest LMS 4.1 version and in the same time switch to the new Linux soft appliance. After that I copied all the backup data to the appliance, I launched the "restorebackup.pl" script and unfortunately got the error "The Backup archive is from WINDOWS . But the current OS is UNIX. Restore is not supported across OS." Is there eventually any possibility to however migrate the data to the appliance?? As Cisco is offering the 2 platforms, there should be a possible migration path.

View 1 Replies View Related

Cisco :: Encryption Method On ISAKMP

Feb 3, 2012

Is 3DES on ISAKMP considered to be secured for your average site (other options are AES/DES)? I'd imagine AES should be much stronger but what about DES, is that considered adequate or broken? Is there any proof of concept attack against 3DES on ISAKMP (or ISAKMP in general)?

View 2 Replies View Related

Cisco VPN :: AES256 VPN Encryption Method

Dec 21, 2012

I've some VPN encryption method questions.Is it recommended to use different encryption algorithms for both VPN phases (phase 1 and phase 2)?I’ve read once that it is much secure to use different encryption algorithms for each phase.In my opinion, I would go for the AES256 algorithm in both phases. But maybe it is a better idea to use AES128 or AES192 in the first phase and AES-256 in the second phase… I don't know.After saying this, I’m also wondering about the best VPN encryption setup for a site-to-site VPN (IKEv2) when using a Cisco ASA like the 5510, 5520 or the 5515.Which encryption method is recommended for phase 1 and phase 2Which PFS / DH-group should be used (considering CPU load and security) 

View 2 Replies View Related

Cisco WAN :: BGP Filtering Best Method For 2921

Nov 3, 2012

I have recently upgraded my company's network significantly, and in the process removed our Cisco edge routers and firewalls (gasp!), and replaced them with another vendor who gave a better price point for the router.However, i was only able to get ONE edge router, whereas before I had two, so I want to recycle one of my old 2921's as a cold standby (in case the brown sticky stuff hits the rotating air distribution blades, and $other-vendor router dies).Trouble is, the 2921 does not, I believe, have sufficient system resources to take the full routing table we're getting from our two ISP's.What I would like to ask is people's thoughts on the best method for me to configure the BGP setup on the 2921 to do the following:

-Accept the default route from each ISP and discard *everything* else in the route table
-Modify our advertisement (ad prepend) out the "secondary" ISP to reduce the priority of traffic coming in over this link.
-Configure the OUTBOUND priorities so that the "primary" link is used by preference for outgoing traffic (which will effectively shut down the secondary link for outbound traffic

View 6 Replies View Related

Practical Method To Measure SNR?

Oct 14, 2012

As we know SNR (signal to noise ratio) is very important in communication special in wireless. So I wondering : How is SNR measured (by using practical method)?

View 2 Replies View Related

Common Method For Ups Requirements And Max PoE Switches

Apr 25, 2012

We have a scheduled office move where we are consolidating 2 remote offices into one. I’ve been asked to spec out the correct size UPS to support all of the network equipment for this new office.I went to the Cisco website and I see on the datasheet for the switches and router where they talk about the wattages and BTU’s but how can I go about deciphering from that information what my total wattage and BTU will be for each switch and router?What numbers should I be looking at? For instance, we have 3 3750 48 port PoE switches. So if I look at the datasheet for that switch they have 4 different columns, one for 100% throughput power consumption, one for 5% throughput, another one for 100% throughput for max PoE load and one for 5% throughput with 50% PoE loads?Is there a common method for deremining UPS requipments? For the switches I pretty sure I need to assume max PoE load in the event every port has a phone plugged into each port.

View 3 Replies View Related

Renew Method Using Google's DNS Server

Apr 13, 2013

I am having some issues with my internet connection. release and renew method and using Google's DNS server.

View 1 Replies View Related

Cisco VPN :: 5505 Certificate Only Authentication Method With AnyConnect

Jul 7, 2011

Any instructions to configure an ASA to allow authentication by certificate only on an AnyConnect vpn?I'm running an ASA 5505 with 8.4(1) and AnyConnect 2.4.7030 on an Android phone.I currently have the AnyConnect client connecting ok using username / password for authentication.
 
I have loaded the company root certificate (internally generated) into the ASA "CA Certificates" and generated an Identity Certificate for the ASA.

View 1 Replies View Related

Cisco LAN :: 6500 / 3550 - Method For Detecting Loops

Sep 23, 2012

I am a network tech at a local school district (easily enterprise network).  I am just a worker bee, so have no say in the design of the networks.  Our topo at a site goes WAN rtr---LAN rtr (6500 of 3550)----distro switches----access switches.
 
Now at most of our sites we use Extreme, which has a handy feature called ELRP Extreme Loop Recovery Protocol, despite the name, this mechanism just detects loops, in the logs we can see, ok...off the LAN rtr, port 2, then on port 2 we see whats hanging off it...ok, loop off port 5 of that switch.....and work your way down the room.
 
We do not have STP on our network (dont ask) and yes, logging is not set to standards also......what is the best way to detect loops?  Commonly these loops come from classrooms that have mini-sw's that are looped onto themselves or a wall jack connected to mini sw and that mini sw then connected to another wall drop going back to same sw.  Sometimes I disable all ports minus the WAN uplink on the LAN router, then enabled ports one by one while having a LR hooked up to a user facing rj45 port on the 6500 and when the LR (link runner) shows 100% util, I know that port is now suspect.

View 5 Replies View Related

Method Of Remote Database Share / Access

Feb 21, 2011

what is the easiest method permitting a local and a remote pc to access the same database ? They both have internet access.

View 3 Replies View Related

Cisco :: Enable Password Fails In AAA Authentication Method List?

Jul 15, 2011

I've got a weird problem that I can't figure out. I've de-authorized the switch in the RADIUS server to force an ERROR status to test the backup entries in the AAA authentication method list. However, after I do that and try to log in (through ssh), it just prompts me for my username's password and not the enable password. Here's the debug output:

1d02h: RADIUS: Marking server xxx.xxx.xxx.xxx:1812,1813 dead
1d02h: RADIUS: Tried all servers.
1d02h: RADIUS: No valid server found. Trying any viable server
1d02h: RADIUS: Tried all servers.
1d02h: RADIUS: No response for id 10

[code]...

View 14 Replies View Related

Cisco VPN :: 5520 AnyConnect Authentication With RADIUS Secure Method

Nov 6, 2012

I have been successfully able to setup Cisco AnyConnect VPN on ASA 5520 with 8.4 code.  I have set it to authenticate against the RADIUS Server (Microsoft Windows 2008 NPS server).  I have noticed one thing, on the server under "Constraints and Authentication Method".  I picked MS-CHAP-v2, but it is considered Less secure authentication methods.  I can click on Add and choose other Authentication methods like Smart Card or other Certificate, PEAP, EAP-MSCHAP v2.  I picked PEAP but then the VPN does not work.
 
So first of all does it really matter if I just leave it to MS-CHAP-v2?  Because from my understanding is that AnyConnect will authenticate to ASA and then ASA in the backend talks to the RADIUS server so from a security stand point this scenario shouldn't it be sufficient as no un encrypted or less secure information is available to the outside world? Secondly is there any documentation on using PEAP with Cisco AnyConnect?

View 4 Replies View Related

Cisco :: 5508 / Easiest Method To Block Employees From Guest Network?

Jun 3, 2013

We have WCS and several WLCs (WISMv1, 5508, 4402) all running the 7.0.240.0 code.  The "Guest" SSID is "garden-walled" from the corp LANs.  We used to have web-auth page that required ID / PW.   This became unreasonable as IT Dept was getting requests at all hours for immediate access from guest / resident family memebrs.  So we changed the web-auth to remove the the ID / PW and just display corp policy and have to hit a "continue" button to gain access to Guest SSID.  Healthcare staff on the floor are not tech-savvy enough to want to use or perform Hotel Ambassador functions.The issue now is that we have employees with smartphones, tablets and even personal laptops conecting the Guest SSID. Sr. Mgt wants to find a way to stop the abuse.I do not believe there is any perfect solution to prevent employees from gaining access, but have been asked to find a manageable method to deter most employees from connecting to the Guest network.   Looked at seing up MAC filtering in WCS, it seems that you have to enter MACs that you *allow* on to the network - by default, other MACs are blocked.  I would rather have the template block the MACs listed in the csv file and allow access as the default.. We have several SSIDs.  Our corporate SSID uses 802.1x and we use Microsoft Server 2012 Network Policy Server (RADIUS) to pass user ID / PW to our AD for authentication.  We do not have Cisco ACS.  I am not sure if integrating RADIUS is the answer here either.   I have had some webex sessions on ISE, NCS, and Prime infrastructure.  We are only interested at the moment to monitor  / control access to Guest.  I have been told that ISE will have "sponsorship" functionality added in soon -- where user fills out info and ID / PW is sent via text or email to a cell phone or other device.

View 2 Replies View Related

Cisco Wireless :: 4402 Any Method To Limit Roaming Between Different Floors In Building

Jun 19, 2012

We have cisco wireless network throught the whole 8-floor building on Cisco WLC 4402 and Cisco LAP-1242 AP. There are no coverage holes, but sometimes clients are flapping between two access points at different floors with serious loss in throughput. Is there any method to limit roaming between different floors in the building?

View 7 Replies View Related

Cisco Switching/Routing :: How To Connect Two Switches 4505 Using Trunking Method

Dec 26, 2011

How Can i Connect two switches 4505 using the trunking method,…

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved