Cisco AAA / Identity / Nac :: Nexus 7009 - Integration Of ACS With RSA

May 29, 2012

We have Nexus7009 at client network but due to limitation of Nexus switches that they can not be directly integrate Nexus with RSA so client has purchased cisco ACS for the AAA. We are able to do the authentication and authorization via ACS.However clients wants to further integrate the ACS with RSA so that authentication should happen via RSA and authorization should happen ACS. Is that possible ? if yes, how can i configure the ACS ?

View 5 Replies


Cisco AAA/Identity/Nac :: Nexus 7009 Using Radius Authentication?

Mar 13, 2012

I have setup my radius server access on the Nexus but am unable to authenticate through putty. If I do a radius-server test on the Nexus it says I authenticate. Here is the log I am getting.
 2012 Mar 14 16:03:21 switch-a %AUTHPRIV-4-SYSTEM_MSG: pam_unix(aaa:auth): check
pass; user unknown - aaad


View 1 Replies View Related

Cisco :: Nexus 7009 / Cannot Connect To It Via SSH

Feb 21, 2013

I have a nexus 7009 that used to work connecting via SSH. However now I cannot connect to it via ssh. It appears the SSH is connects but doing a show users from the console shows nothing connected other than the console connection.

View 4 Replies View Related

Cisco Switching/Routing :: Upgrade Nexus 7009 6.0.1 To 6.1.2?

Feb 3, 2013

I need to upgrade my core switches at one of our locations (two 7009s with dual sups) from 6.0.1 to 6.1.2.  After looking through the release notes it appears that this will be a disruptive upgrade?how long should I expect for the disruption?  Are we talking a 7009 boot cycle (10 - 15 minutes) or something longer?How many disruptions can I expect?  I suspect 1 per chassis during the failover to the standby but I'd like to validate.Is there any compelling reason to upgrade the EPDL?  From what I can see, again from the release notes, this is only necessary with F2 cards if I were to upgrade to Sup2s . I'm in a healthcare environment and this upgrade will be affecting one of our major campuses so the more info I can get to the managers the more accepting they will be for the disruptions.

View 3 Replies View Related

Cisco Switching/Routing :: Nexus 7009 Error Message

May 27, 2013

I have in logs following error message:


Has failed test SpineControlBus 20 times on device Power Mgmt Bus on slot 10 due to error Spine control test failed error number 0x00000002.

View 3 Replies View Related

Cisco Switching/Routing :: Max Power Consumption Of Nexus 7009?

Mar 3, 2013

I need to figure out the max power consumption of 7009. The issue is, at this point i am not sure what modules will be used, so just to give an estimate, how we calculate the max power consumption of nexus 7009 ?

View 2 Replies View Related

Cisco Switching/Routing :: Upload Large ACLs To NX-OS Nexus 7009?

Feb 3, 2013

We are migrating from Catalyst 6509 IOS platforms to Nexus 7009. There's the normal differences in commands which is well doucumented. We do have some quite large files containing ACLs varying from 10's of lines to several 1000's of lines. Our normal upload would be done using tftp and then issuing the command 'conf net' on the the 6509. This is no longer the way to do this on NX-OS. I've tried copy ftp: running-config which works fine for small files but for big ones it takes a long time, in some cases I've see it takes 20-30 minutes. The initilal tftp uplaod to the 7009 seems OK but the copy into the running-config is the bit that takes time and initially I thought I'd killed the 7009!! It did finally come back to the prompt. Are the 7009's simply not designed for large ACLs? I did try the configure session (Session Manager) but I couldn't see a way of uploading a file. I tried creating a new session and then exiting it, copying in a file of the same format and then commiting it but it didn't seem to acknowledge the file (checksum?).

View 10 Replies View Related

Cisco Switching/Routing :: Nexus 7009 Line Cards Compatibility?

Apr 14, 2013

I wanted to know that in nexus 7009, can i use mix of F2/M1/M2 series line cards ? will they work with each other ? Lets say i have F2 line card and M2 line card, will servers attached to them will communicate with each other ?

View 4 Replies View Related

Cisco Switching/Routing :: RSPAN Configuration In Nexus 7009 Switches

Jan 19, 2013

We have Nexus 7009 switch and want to configure the span session
We are using F2 and M2 card both are in seperate differeent VDC.And out server is connected to M2 card on eth 4/6 and want to monitor the traffic from vlan 161Which is made on F2 card.
Connectivity is like this.
Nexus 1                                Nexus2
Slot 3: F2 card                     Slot 3 : F2 card
Slot 3: M2 card                    Slot 3 : M2 card


View 1 Replies View Related

Cisco Switching/Routing :: Nexus 7009 / Maximum Distance For FCOE?

Apr 3, 2012

We are looking to deploy two Nexus 7009 cores at our two datacenters. They are approximately 2 miles apart. We are hoping to have 10G Dark Fiber between the buildings and therefore dedicate a pair for FCOE between the cores using 10G Long Range SFP's. I read that the Nexus 5000 series had a limit of ~3 km for FCOE. Does the same hold true for the 7000 series? I thought I read somehwere that the buffers were larger on the 7000 series and therefore would be able to do ~30 km.

View 2 Replies View Related

Cisco Switching/Routing :: 6509 - Nexus 7009 Rack Concerns

Mar 5, 2013

I wanted to know if any has the Nexus 7009 chassis installed into a 600 wide rack with the sides fitted and if they are experiencing heat issues? 
My client will be replacing their aging 6509 chassis with 7009 devices, but the physicals dont tally with the install guidelines for the 7009 series chassis.  The current install of the 6509s does not tally with the recommended install guidelines for those either, but they have not expereienced any heat issues...
The 7009 will be fitted with 2xSUP2E, 3x48portSFP-F2E cards and 2x10GSFP-M2 cards with 2x6K PSUs.  I am genuinely concerned they may cook these devices, but space restrictions look like vetoing the upgrade to 800 wide racks.  Likewise moving to 7010 chassis may prove tricky due to existing other installs within the racks limiting vertical space.

View 2 Replies View Related

Cisco Switching/Routing :: Nexus 7009 Need To Configure DCNM Server To Get License

Jun 18, 2012

We've gotten two Nexus 7009's in and I'm starting to configure them when I found I couldn't add VDCs.  I found there was no license installed but the only licenses I found that came with them are "Cisco DCNM for LAN Enterprise Lic for one Nexus 7000 Chassis".  So my question is this - do I need to configure a DCNM server to get the license pushed to these two 7009s or should there be another PAK for each chassis that I can register and get my enterprise services?

View 1 Replies View Related

Cisco Switching/Routing :: Nexus 7009 - Syslog Configuration Doesn't Seem To Work For NX-OS

Sep 10, 2012

we've been using IOS for a long time, but are relatively new to NX-OS. We've got a central syslog server that all our devices log to. No matter what we do, we can't get our Nexus switches to log there. Here's my current attempt:
Nexus 7009, NX-OS 6.0(1)
# sh logging server
Logging server:                 enabled
server severity:        debugging
server facility:        local7
server VRF:             default

The default VRF is working. I see log entries in the logfile, but nothing arrives at the syslog server. It's not a config issue on the server, because tcpdump shows that no packets arrive from the IP for loopback 0.

View 3 Replies View Related

Cisco Switching/Routing :: Any Challenge To Upgrade Core Switch 6500 Series From Nexus 7009 Which Runs NxOS

Jan 28, 2013

Is there any challenge to upgrade core switch 6500 series from Nexus 7009 which runs NxOS, because i have 3750X series switches connected at distribution and access layer in my network topology??
Is there any challenge if we place NxOS in core and IOS in distribution and Access layer??? how we are able to match sh run config in existing 6500 switch to Nexus 7009 NXOS?

View 9 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 With AD Integration

Mar 14, 2011

first i configure the ACS to Synchronize time from AD as NTP server second when i configure the integration between the ACS and AD and test the connection there is no output from this test but i see that the domain is connected and the end of the page the problem is when i try to navigate the groups by go to directory group and use select there is no output.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: WLC Integration With NAC 4.9(1) L3 OOB

Apr 15, 2013

Is it possible to integrate a WLC with a NAC 4.9(1) L3 OOB? I can't find any documentation that says that it is possible or not.

View 9 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Integration With RSA?

Dec 24, 2012

I have Integrated the ACS 5.3 with AD.Now my next goal is to Integrate ACS with RSA in such a way that all my Cisco devices should use the username and password from the AD.The enable privilege level should come from the RSA Token OTP.Is it possible to do such a thing with ACS 5.3?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Integration Of WLC (7.0.235) With ISE?

Nov 20, 2011

We have a customer who wants to configure his guest wireless network in such way that the guest should fill in a self registration form and generate the username and password themselves. For this purpose we are using cisco ISE but we don't know how to integrate it with cisco WLC.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Integration Of ACS 4.2 With AD

Jun 24, 2012

We have an ACS running 4.2. I am sure that this ACS is talking to our AD database because our wireless users (using ACS as RADIUS servers) are able to log in using their Windows AD account.
However, I am not sure how ACS is integrated with AD. Our ACS is installed on a windows 2003 R2 server. I am not sure where the AD database is?  ie,if AD is on the same server as ACS OR on a different server [ADs managed by different group altogether :-(  ].

How is the integration done between ACS and AD when both are on the same windows server? And How is the integration done between ACS and AD when they are on different windows servers?

ACS is software installed on windows 2003 R2 server.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 Integration With AD 2008 R1?

Jul 13, 2011

I have configured my WLC 4402 for Radius authentication using Cisco ACS server version 4.2 Patch 4. When using Local Database of ACS my Wireless Users are able to authenticate but users are not able to authenticate from External Database of Windows AD 2008 R1.
In ACS logs I am getting the this error- Authentication session timed out. Challenge not provided by client.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Prime NCS Integration With ACS 5.1?

Jan 29, 2013

We've an issue with authorization on NCS system. NCS successfully integrated witch ACS, but there is a problem with one user. All users have equivalent rights under root. There is shell profile with all possible tasks (exported from NCS server) configured on ACS. All users exept this one (unlucky one:)) authorizes successfully.  In  ACS logs, authentification and authorization status for this user is passed and all attributes (policy, profile, AV-pairs e.t.c.) is the same as for another users. This 'unlucky' user gets a following message: There is surely no browser or network issue. Tried from different PCs with same result. There is no any local info related to this username on the NCS server. When i change one charecter in the username on his ACS account, everything works well.

Our ACS v
Version : 1.1.2.X

View 1 Replies View Related

AAA/Identity/Nac :: Cisco ACS 1121 Integration With AD?

May 15, 2011

integrated the Cisco ACS 1121 with 5.1 and AD and been able to use multiple policies to permit or deny access to different NDG?  I am able to authenticate agains AD but I am having an issue with getting the policies to use the user memberOf attribute to set access levels. 

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Integration With LDAP?

Jun 22, 2011

provide me  Step by Step procedure for integrating LDAP with ACS 5.2 .

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ISE 1.1.1 With Domino LDAP Integration?

Oct 23, 2012

know about Domino LDAP ? I would like to integrate this LDAP with Cisco ISE.I try to bind this LDAP but it does not show me anything in "Naming Context". So I cannot choose group to map into ISE.I test this on WLC. It is success to do but cannot make the same thing with Cisco ISE.Is this LDAP supports with Cisco ISE 1.1.1 ?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Active Directory Integration Acs 5.1?

Aug 24, 2011

I'm attempting to integrate an acs 5v into the domain through the gui. The connection will establish, and the status will read 'connected', just as it lists the domain I've submitted. However, I can't seem to find anything listed under the directory groups, and when I run a connection test, I simply get 'Global Catalogue port status error.' Eventually, I'd like to configure this as a radius server.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Integration With RSA Allow Only One Login Every Minute?

Nov 1, 2011

I have an ACS 5,2.0.26-8 running on VM intergrated with RSA. Users are able to login using their RSA passcode for network management utilizing TACACS. The problem seam to be related with RSA token caching. Once a user login sucessful on device A using current token he can not login with the same token on another device. User must wait for a new token and then he can login again.  Before moving to ACS 5.2 we were using ACS 4.2 (intergrated with the same RSA) and back then ACS 4.2 cache passcode so user where able to login on devices using the same passcode. When the token change user have to use the new one. providing the same functionality like the "Token Card Settings" Durantion option under group properties, to cache token for a specific period. The global option for caching under RSA definition on 5.2 does not solve the problem.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Integration With NGenius Server

Mar 8, 2011

I'm currently working on ACS 5.1 to use it as AAA server for Netscout NGenius.I followed a guide for ACS 4.2 and tried to replicate the configuration settings in ACS 5.1.
- created a host profile on network devices and AAA clients having the same shared key with NGenius
- added three (3) NGenius required attributes in system administration > configuration > identity > internal users
- added attribute values to Internal User database
- created an access policy:
* identity pointing to Internal Users
- edit in NGenius server to match the requirements
I would like to have NGenius authenticate via ACS 5.1, but as of the moment there is an error message that I receive:

Unicentified error, Code=16510, Details: AV pairs do not match NGenius format ::<insert tacacs username here>, Severity 1, Code: 16510.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Active Directory Integration

Apr 24, 2012

A customer uses Active Directory where some group names contain special characters (ç ~ '^). The Cisco ACS 5.2 is presenting the warnings: "Not all Active Directory user groups are retrieved successfully. One or more of thegroup's canonical name was not retrieved "(Category CSC Oacs_ Identity_ Stores_Diagnostics; code 24457).

What are the results of these warnings to the customer's network? Slow? Loss of access?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Integration Of ACS 4.2 And MS Active Directory

Oct 21, 2010

configure the Cisco ACS to authenticate the users from MS Active Directory. Cisco Acs = 4.2.1(15)Currently, i have multiple users configured as local databse. but now i want to authenticate with the domain users.

View 11 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Multi Forest AD Integration?

Aug 24, 2011

Domain A (Forest 1) <--Two Way Trust--> Domain B (Forest 2)
ACS is joined to domain A.
My question is AD integration (Not LDAP) supported between 2 domains in different forests?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Integration ACS 5.2 With Other Device (sandvine)

Sep 18, 2012

I have a ACS version 5.2 (TACACS) where I require equipment integrated with Sandvine, I currently looking information and very little to manage the integration of ACS with these teams Sandvine.
I have an information on the provider Sandvine with a guide to the case where only states:

TACACS + server
On a TACACS + server, each user entry must allow the service "Sandvine". Within this
service, the attribute-value pairs Following can exist:
• An attribute named "Sandvine-Group" of type string.


View 4 Replies View Related

AAA/Identity/Nac :: ACS 5.2 Integration With Safe Connect?

Jan 26, 2012

I am having an issue upgrading from 4.1 to 5.2 in regards to interoperability with our SafeConnect appliance.  When I bring 5.2 online, Safe Connect reacts and causes network outages. 

View 0 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Integration With AD Windows 2000 Advanced SP4?

Dec 13, 2012

I'm having a issue when configuring Cisco ACS 5.2 appliance 1121 to integrate windows 2000 Active Directory as an External Users Database.I'm using an account with administrator privileges on AD (can create computer objects).The ACS register itself successfully to the domain but it doesn't retrieve the AD Groups, even when i change the seach base and filter.At this link says that ACS supports AD over Windows 2003, 2008 and 2008R2 but it doesnt say that not supports Windows 2000.[URL]

View 2 Replies View Related

Copyrights 2005-15, All rights reserved