Cisco AAA/Identity/Nac :: How To Enable ACS 5.2.0.26 Configuration Audit

Oct 12, 2011

ACS and i would like to know how to enable the "Configuration Audit" for someone login to my network devices using their ACS login and i can monitor what they did on it.
  
ACS Version : 5.2.0.26

View 6 Replies


ADVERTISEMENT

Cisco WAN :: WS-C6509-E - How To Enable Audit Log To Server

Apr 10, 2013

In our network we use cisco WS-C6509-E (R7000) Backbobe switch. We want to route syslog to log server.But I couldn't do it. How can solve this problem?

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS5.2 - Allow Show Running Configuration Without Enable

May 24, 2012

I am using ACS5.2 I want user to access the device with all necessary command like show run/ver/int/log… I try to set user privilege using Shell from 1 to 10 but show run doesn't work.

View 15 Replies View Related

Cisco AAA/Identity/Nac :: 3845 - Enable Secret Password Missing In Configuration

Jun 23, 2011

Recently I came across a router (Cisco 3845,  IOS 12.4) configured for TACACS, one local username and an enable  password. Going through the configuration I noticed the router didn't  have an enable secret password which I thought was strange. The TACACS  config is below, comments regarding the  TACACS config and the consequences of not having an enable secret or if  there is a need for one.
 
aaa authentication login default group tacacs+                                  aaa authentication login no_tacacs enable                                       aaa authorization exec default group tacacs+                                    aaa authorization commands 1 default group tacacs+                              aaa authorization commands 15 default group tacacs+                             aaa accounting exec default start-stop group tacacs+                            aaa accounting commands 1 default start-stop group tacacs+                      aaa accounting commands 15 default start-stop group tacacs+                     aaa accounting network default start-stop group tacacs+

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.4 - Audit Logs Operated By Secondary Instance?

Mar 28, 2013

I'm using ACS 5.4p2 within distributed systems: one primary and one secondary instance.For now, primary instance is acting as Log Collector server and I can see any AAA audit logs.

When the primary instance fails I can authenticate successfully using the secondary instance.However, when primary instance comes back, I'm not able to see any audit logs operated by secondary.

View 9 Replies View Related

Cisco :: Ciscoworks LMS3.2 Not Showing Latest Configuration / Change Audit Report

Dec 19, 2012

My cisco works LMS3.2 is  not showing recent configuration of my Cisco devices. also it dont show any change report on last 24 hours or even if i select x number of day, looks like its not saving any changes made on devices.
 
today i logged in and cisco ASA was showing this in status as well Configuration Last Archived Time    May 03 2012 11:27:46 EDT  on checking i could see it is same date when cisco ASA was added in cisco works. do i need to click some where for auto update configuration changes and latest confoguration in cisco works setting?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Enable Privilege On ACS 5.1.0.44

Jun 4, 2011

I have created internal user on internal identiy store --> users with password  & enable password  , Similarly i have enabled max privilige level 15 under policy elements , authorisation & permission ,Device administration , shell profile .But i am unable to login into device using enable password , I am finding following error on my logg report
 
Failuire reason : 13029 Requested privilige level is too high .

View 3 Replies View Related

AAA/Identity/Nac :: Enable Password In ACS 5.3?

Jan 28, 2013

How to configure authentication of enable password using acs 5.3. I have installed acs 5.3 and created user and gave relevant passwords. Following config is done on router
 
aaa new-model
aaa authentication login default group tacacs+ local
aaa authen enable default group tacacs+ enable
tacacs-server host x.x.x.x key xxxxx
 
Now when I telnet router, i can authenticate username/pass with acs5.3 but when i try to enter enable command and give password, it gives me error in authentication. What is the process of configuring enable passwords?

View 6 Replies View Related

Cisco WAN :: 891 - Configuration To Enable The FE8 Port

Jun 23, 2011

I am switching out our old WRVS4400 router to the Cisco 891. Having a problem configuring the Cisco 891 router. I changed the V LAN port on the 891 from 10.10.10.1 to 192.168.2.1 and the ip address saves but when I try to rediscover it through the CCP to the new Ip address 192.168.2.1 I get the message discovery failed.

The sub net mask I used is 255.255.255.0  The only thing connected to the 891 router is our linksys 48 port switch which is SL248G and my laptop is connected to the switch. The port its connected to is FE LAN 0 . How do discover the 891 so I can do further configuration and to enable the FE8 port for using it for our internet connection?

View 8 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 How To Enable Log On Secondary Server

Feb 28, 2013

We are using ACS 5.3 with two servers in a distributed solution.All logs are collected on primary server so when this server fails all logs are lost.How can I enable log on secondary server also?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Is Refusing To Use Enable Password

Dec 21, 2012

I have migrated my ACS data from 4.1 to 5.1 and everything is working fine to test the connection I have configured a switch to get the authentication from the new Tacacs server, using my old username and password..i got in perfectly but when the switch asked my for enable which is the same password, it refused the password.(I have unchecked the <use a different password for enable> option) I deleted my switch from the Tacacs to enter locally, I went in with no problems..i thought that the problem may be from the old configuration.so I created a new username and password to check, and the problem still exist.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Enable Authentication Mode On ACS 4.2

Feb 8, 2012

how to Config the ACS 4.2 server runs in TACACS + mode (users accounts configured the ACS) mode  to authenticate enable mode  password on the asa using the same AD account?

View 10 Replies View Related

Cisco WAN :: 6509 - How To Enable Netflow / Configuration

Jan 21, 2013

Below is the show ver of 6509 switch , how to enable netflow
 
sh ver
Cisco IOS Software, s72033_rp Software (s72033_rp-IPSERVICESK9_WAN-M), Version 12.2(33)SXI7, RELEASE SOFTWARE (fc1)
Technical Support: [URL]
Copyright (c) 1986-2011 by Cisco Systems, Inc.
Compiled Mon 18-Jul-11 05:50 by prod_rel_team 

[code]....

View 2 Replies View Related

Cisco WAN :: Enable GUI For Configuration Of 1921 Router?

Dec 15, 2011

I have a Cisco 1921 in place with the security IOS so it is also acting as a firewall.
 
I am wondering if I can enable the GUI so I can configure it remotely.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: 8.4 (2) / ASA System Context Authentication Enable?

Jan 12, 2012

We have ASA configured in multi context mode, with software 8.4(2) configured for AAA Configuration is admin context as follows:

aaa-server TAC protocol tacacs+
aaa-server TAC (management) host 10.162.2.201
key *****
aaa authentication enable console TAC LOCAL
aaa authentication http console TAC LOCAL
aaa authentication serial console TAC LOCAL
aaa authentication ssh console TAC LOCAL
 
Because of multiple context, after logging in we enter System context. Console port authentication is working fine except access to privileged mode while connecting over console port. After issuing "enable" command ASA accepts only configured enable secret in system context and changes user ID to enable_15, so we are unable to do user-level command authorization and accounting.It seems that ASA in system context is not aware of any AAA configuration, and there isn't any command to configure AAA in system context.Is there any way to configure enable authentication over AAA in system context?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Enable Parser View Command On ACS 5.X

Mar 11, 2013

Would like to check out is it possible  binding Cisco secure ACS 5.x to support router/switch ios feature view -  superview and parser command
 
Busines objective is assigning administrative roles, with different role based CLI access, using ACS5.X as backend server.  a. Admin (allow all) b. network monitor (privlege # 7, enable view that can doing various show command and configure) c. support (privlege #1, read only)

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS V4.2 Changed AD Password Now Can't Get Into Enable Side

Dec 29, 2011

Changed my AD password and now i cannot get into the enable side of the cisco switches on our network (we have no routers).Looking on the logs for the ACS v4.2 I can see the following -
 
On TACACS+ Accounting you can see the connections which have worked - it the initial tty connections -
 
When i look in the failed attempts i see the following Auth failed -  External  DB user invalid or bad password  or on another occasion internal error or EAP-TLS or PEAP authentication failed due to unknown CAcertificate during SSL handshake.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.4 Drop Users Into Enable Mode?

Apr 11, 2013

I am trying to get users in the external identity store (AD) to be dropped directly into enable mode after being authenticated, since I don't know of a way to set an enable password for users in an external identity store. I think it has something to do with shell attributes but I'm not realy sure.
 
So here's what I tried.Linking identity group to external group and provide full command priviliges - enable still didn't work Creating duplicate users in the internal identity store and setting the password type field to AD1 - That gives me the ability to get to the enable password prompt hit enter on the blank promt then prompts for Old and new passwords but fails everytime with an Error in Authentication.

View 8 Replies View Related

Cisco AAA/Identity/Nac :: 5510 - How To Enable Password When Using Tacacs+

Jul 10, 2012

I have been experimenting with acs 4.2 and  a cisco asa 5510. I have managed to authenticate the ASA users with my tacacs server. The user "test" is authenticated with the tacacs server, and can log in. But the enable password is wrong, because i dont know where to place it in the tacacs server.
 
Now my question is, where do i set my enable password when authenticatig with tacacs+. And for this i mean in the acs 4.2, i know how to do it on the asa.

View 4 Replies View Related

Cisco AAA/Identity/Nac :: Enable Unconditional Machine Authentication In ACS 5.3?

Jul 4, 2012

It´s possible to enable unconditional machine authentication in ACS 5.3.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Interactive Viewer Grayed Out / How To Enable

Apr 7, 2011

When I launch Monitoring & Report Viewer and select one of the report (TACACS authorization for example) I want to filter the search with Interactive Viewer, but I can't cause all options are grayed. I've heared that some flash is needed but I've got plugins installed and nothing changed.
 
Can I run in in demo version? cause I've read that there is an add-on license which "Add-on licenses are available to support deployments that are larger than 500 devices (AAA clients) and to support advanced monitoring, reporting and troubleshooting functionality"

View 5 Replies View Related

Cisco :: WLC 5508 Max-Login Ignore Identity Response Is Set To Enable

Sep 20, 2012

We`re using a WLC 5508 with SW 7.2.103.0.The most things are working fine, but i have a problem with the web auth.
 
Setup:

- Max Concurrent Logins for a user name is set to 1
- Max-Login Ignore Identity Response is set to enable
- Web Authentication Type is set to customized
 
The Problem:

- the user "test" is logged in at device1 (working), the same user "test" try to login at device 2 (is not working, fine!) -> login is not accepted, WLC redirects to the INTERNAL Web Login Page.The problem is the redirect to the internal web login page after failed login. If i try to login with a not existing user, the redirect is working perfect to the customized web login.

View 4 Replies View Related

AAA/Identity/Nac :: Use Cisco Secure ACS 4.2 To Enable Command Authorization Using TACACS?

Nov 5, 2011

provide a sample configuration to use Cisco Secure ACS 4.2 to enable command authorization using TACACS.

View 8 Replies View Related

Cisco AAA/Identity/Nac :: Can't Seem To Enable In ASA With Non-15 Privilege Level User Configured In ACS 4.2

Apr 29, 2011

I can't seem to enable in ASA with a non-15 privilege level user configured in ACS 4.2 (tacacs).When I enable in IOS device, it enables and "show privilege" shows level 10 as expected. ACS should be configured correctly as it works fine with IOS. User is not set with explicit settings. Group is set with "max enable level" 15 and "shell exec priv level" 15. The enable password is set to the internal ACS PAP password. Works fine in IOS.When I enable in ASA, it fails to enable, and ACS log says "Tacacs+ enable privilege too low". I suspect that ASA tries to enable into level 15 explicitely. If I try to issue "enable 10" command in ASA it says: Enabling to privilege levels is not allowed when configured for AAA authentication. Use 'enable' only. [code]

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Ws-c3750-48ps Enable Dot1x On Stack I

May 31, 2013

I have 3 ws-c3750-48ps in a stack and i'd like to enable dot1x on the stack I entered the commands: [code] I also have dot1x enabled on several interface on the 2nd and 3rd switches in the stack with these commands [code] dot1x successfully works on these ports and I see the logs in acs, heres where the problem comes in when i try to enable dot1x using the above commands on any interface on the first switch in the stack it doesn't work its like the switch doesn't support dot1x. I'm assuming that there is a bug in version 3 but after googling I didn't come up with much.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: 2960 - Unable To Login To Enable Mode

Dec 30, 2012

I configured the below config in Routers it is working good , but when i do the same in SWITCH-2960 , i am getting a problem not able to login to enable mode ... i am getting the basic login only ....
 
Error msg :   % Error in Authentication.
  
Need to be configured at TAFE Network Devices: Code...

View 4 Replies View Related

Cisco AAA/Identity/Nac :: How To Setup Enable Mode Password On ASA 5510

Jan 24, 2013

how do I setup an enable password for an ASA 5510?  At the moment its setup to authenticate using RADIUS (which I'd like to keep doing) but I need to setup an enable mode password.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Migration Utility TACACS+ Enable Password

Jul 26, 2012

I am trying to migrate an ACS 4.1.1(24) using the migraton tool to ACS 5.2. The tool is working OK. It migrates the users, groups, NDG, etc. and the reports are showing no errors.
 
The problem is with the Enable password of the users. The users in the ACS 4 have the TACACS+ Enable Password configured, but after the migration it appears empty in the ACS 5.

View 3 Replies View Related

AAA/Identity/Nac :: ACS 5.4 - TACACS Authentication - Drop Straight Into Enable Mode?

Dec 5, 2012

I successfully authenticate through ACS to my Identity Store, but only get dropped into a non-enable prompt: ciscoasa> How can I get an Authenticated user directly into enable mode?

View 3 Replies View Related

Network Audit Tools?

Oct 10, 2012

me what are the best Free tools to do a Network Audit (Thoughput, speed linksswitchs usage, analyse network topology.. etc)

View 7 Replies View Related

Cisco :: LMS 4.0.1 / Understanding Change Audit Report?

Jun 27, 2011

I need to understand why change audit report reports an unused username Name of the user who performed the change. This is the name  entered when the user logged in. It can be the name under which the LMS  application is running, or the name using which the change was performed on the  device. #The User Name field may not always reflect the user name. The  User Name is reflected only when: A config change was performed using LMS. #A config change was performed outside of LMS, but the  network has username-based AAA security model, wherein authentication is  performed by an AAA server, which could be TACACS/RADIUS or local.

View 2 Replies View Related

Cisco Security :: PIX 515E Logging For Audit

Oct 17, 2011

We have a PIX 515E running ver 6.3 and we want to implemente some sort of logging to keep track of who/when logs in to the PIX and if they make any config changes or to the file system. All of this is for forensic purposes in the future. I have already looked at some PIX docs but I don´t seem to find what I am lokking for.

View 1 Replies View Related

Cisco VPN :: Audit Users On Old 3060 Concentrators?

Sep 13, 2012

We are trying to finally get rid of a couple old 3060 concentrators and would like to see how many active connections are still on.  Is there any reporting that can be seen from the concentrators? 

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved