Cisco Switching/Routing :: 2960 Radius Server Users Different Privileges

Jul 26, 2012

I have Cisco 2960 switches deployed in my environment along with radius server authentication. Now i need to assign some roles to particular users (shutdown port, description) so what i need to do for this task so not all users have same privileges.

View 1 Replies


ADVERTISEMENT

Cisco Switching/Routing :: Configure Radius On 2960 And 2955

Apr 3, 2012

I'm about to configure radius on a 2960 and 2955 switch as I have been testing this on a 1841 router and to my dismay I can't see the options to configure radius, do these L2 switches not supoprt radius?
 
edit - apoligies I forgot the "aaa new-model" all ok now
 
Although when I added:
 
radius-server host 10.1.1.1 auth-port 1645 acct-port 1646 key 123456789
radius-server host 10.1.1.2 auth-port 1645 acct-port 1646 key 123456789
radius-server vsa send accountingradius-server vsa send authentication
 
I got this:
 
Warning: This CLI will be deprecated soon. Please move to radius server <name> CLI.
  
And what woudl the above look like if I configured it that way?

View 6 Replies View Related

Cisco Switching/Routing :: Catalyst 2960 After IP Change Via Web-Surface No Users Work Anymore

Sep 16, 2012

A customer contacted us that he can't connect his devices via web since he changed the IP address. Ok, big laugh "type the correct IP" but no. Even if you use the correct IP, no user can't connect anymore to the device. Also via CLI!The only thing that worked was the password recovery procedure. After that everything worked fine.The customer and me tried it again with another 2960, maybe there went something wrong when he did it last time and it was an accident. Nice thought but no: another device same error, no login possible.

View 1 Replies View Related

Cisco Switching/Routing :: To Manage LAN Users And Database Servers Traffic On Single 2960

Sep 6, 2012

For my Lan, I have created two Vlan; Vlan 10 = for Users   and    Vlan 20 = For Database Servers,There are 15 Lan computer/laptop and 5 SQL database server (Dell Server) connected through same 24 port cisco 2960 switch. Means, 15 + 5 port occupied.
 
I have applied access list on cisco switch to restrict communication between vlan 10 and vlan 20.But My main purpose to create two Vlan is not for any kind of communication or restriction. My main Purpose is that Users traffic do not distrub or choke or affect the Database servers. then what will i need to do for that is VLAN Concept is sufficient for my concern  OR  I will need to buy seperate Cisco Switch to connect 5 database servers   OR  Else ?

View 9 Replies View Related

Cisco Switching/Routing :: Catalyst 2960-48 - Capable Of Being Backbone Switch For 1000+ Users Network

Feb 6, 2013

Wondering if this switch is capable of being a backbone switch for a network of about 1000+ users and if the switch can handle a sustained 30Meg of data going across it?

View 3 Replies View Related

Cisco Switching/Routing :: 1841 - Set Up Different Privileges On Router

Mar 7, 2012

We have a Cisco 1841 router that requires 2 levels of access, at the moment we have network admins logging in with a single username via SSH and with privilege 15 but we also need our helpdesk to login to run certain commands but not chaneg anything

View 4 Replies View Related

Cisco Switching/Routing :: Catalyst 3560 Can't Access Radius-server In Vrf

Aug 23, 2012

My configuration:          
    
radius-server host 10.138.44.57 auth-port 1645 acct-port 1646 key 7 ******
!
aaa new-model
!
aaa authentication dot1x default group radius local

[code]....

View 2 Replies View Related

Cisco Switching/Routing :: Radius-server Attribute 61 Extended On ASR1004

Nov 9, 2011

We faced with problem after upgrade ASR from 12(2) 33 XNE2. I know that this is an old XE release but our Radius deny authization from ASR with more new XE version. Here is our radius attribute configuretion:
 
!
radius-server attribute 44 include-in-access-req
radius-server attribute nas-port format d
radius-server host x.x.x.x auth-port 1812 acct-port 1813 non-standard

[Code]....

How can I add in my configuration that ASR send necesserry NAS-Port-Type - VPDN

I couldn't found out any info ((( for radius-server attribute 61 extended

View 1 Replies View Related

Cisco Switching/Routing :: Radius Server Command Missing From Global Configuration Mode 4510R

Feb 22, 2013

I came across an interesting issue and thought I would see if anyone else has encountered it before contacting TAC.I have two Cisco Catalyst WS-4510R-E switches with a single Supervisor V module in each chassis.  Both Sup cards are now running 12.2(54) SG1; ipbasek9 firmware; yes, I plan to move both switches to 15 code but that's another story.  Anyways, prior to the upgrade the one switch was running 12.2 (33) code; I suspect the code was never upgraded; running ipbase non - K9 code.  The other switch was running 12.2(44) with K9 prior to upgrade to 12.2(54). 

View 2 Replies View Related

Cisco Switching/Routing :: Radius Server Command Missing From Global Configuration Mode 4510R-E

Apr 23, 2012

I have two Cisco Catalyst WS-4510R-E switches with a single Supervisor V module in each chassis.  Both Sup cards are now running 12.2(54) SG1; ipbasek9 firmware; yes, I plan to move both switches to 15 code but that's another story.  Anyways, prior to the upgrade the one switch was running 12.2 (33) code; I suspect the code was never upgraded; running ipbase non - K9 code.  The other switch was running 12.2(44) with K9 prior to upgrade to 12.2(54).  With the background set, one switch reports the following:SwitchA (config)#r?radius-server  redundancy regexp represourc rmon route-map router.

View 4 Replies View Related

Cisco Switching/Routing :: Nexus 7010 New Users Were Not Getting Ip Address From Dhcp Server

Jun 8, 2013

We  have 2 nexus 7010 switches configured with HSRP in the network. For all  the vlans core1 is Master and Core2 is standby. In the current setup we  have external dhcp server and dhcp relay is configured for all the  vlans on Master and standby switch. The setup is running the IOS 5.2
 
Activity Done: During  the Maintainacne activity, we isolated core1 switch in the network by  disabling the vpc/keepalive and all the uplinks from access switch. The  core2 switch was master for all the vlans.
 
Issue observed: It  has been observed that new users were not getting ip address from the  dhcp server. The ethereal capture showed that dhcp server was not  getting the dhcp requests from the core2 switch. We disabled the dhcp  feature in core2 and enabled again with dhcp relay again configured on  vlan interfaces .even after doing this no change was observed in  behaviour. Finally we got core1 back in network by enabling all the  links.
 
Observation: The  moment VPC link came up between the core switches, users started  getting ip's from dhcp. Then we started enabling all the uplinks on  core1.Core1 again become master for all the vlans and users continued  getting ip’s. Network running fine.
 
Further Testing

1. For  one of the vlan, core 2 switch has been made primary and for new users  checked the dhcp functionality and it was working fine. The aim was to  identify if anything wrong on core 2 related to dhcp relay

2.Again  we changed the priority for this vlan and made core1 master for the  same. This time we disabled this vlan on core1 and tried new user with  core 2 became master and dhcp functionality worked fine for new user.  Actually in this case we have simulated the same behaviour when we  observed the issue with only difference of VPC was not available during  the issue time as core 1 was isolated form network 
Inputs needed.

Is  there any known behaviour for dhcp functionality when VPC is  unavailable? If we see the test scenario2 (wherein core1 was master for  the vlan and we disable this vlan on core 1 and core 2 was able to relay  dhcp requests for new users in this vlan.) it was actually same as  scenario we observed during issue time..

View 7 Replies View Related

Cisco Switching/Routing :: 10GE On 2960 Switch Connect To Server?

Sep 11, 2011

just want to confirm if I could use the 2x 10GE uplink ports of a cisco 2960 to connect to my Server directly?

View 17 Replies View Related

Cisco Switching/Routing :: 2960 NTP Server / Client Configuration In Switches

Feb 28, 2012

We had core(4503), distribution(3750), and access switches(2960) in our environment. Currently we configured the clock manually in each switch, but a reboot of the switch resets the clock also. We are planning to make a single switch as a NTP servers and others are clients to synchronise  the correct time even after a reboot of the access switches.

View 6 Replies View Related

Cisco Switching/Routing :: 2960 With LAN Lite Software Be DHCP Server?

Feb 10, 2013

I need to  buy a cheap Cisco switch with DHCP server.Can you confirm that 2960-24-S, 2960-24TC-S and 2960-48TC-S be a DHCP server?

View 3 Replies View Related

Cisco Switching/Routing :: DHCP Server Will Work On 2950 / 2960 Switch

Feb 11, 2012

With out using any server, will DHCP be configured in cisco 2950/2960 switch?I man cisco it self should work as a dhcp server also.

View 10 Replies View Related

Cisco Switching/Routing :: Unable To Login To 2960 Via Console Through Terminal Server

Oct 23, 2012

I have a set-up with multiple C2960 and C3750 switches. All these devices are being managed remotely. So basically I login to C2901, which is used as a Terminal Server,  and reverse SSH to the console of each device. That's - I have assigned an IP to each port of the terminal server so that I can SSH directly to the desired device through via the mapped IP.
 
Now, recently I had to restart couple of switches - one C2960 and C3750. I initiated the reboot via console connection remotely. I could see the device logs for some time and then the logs stopped and there was no reaction from the console irrespective of any command I tried to enter.
 
I tried resetting the line on the terminal server, but that didn't work.
 
Now when I try to SSH the IP mapped to console of that particular device - i dont get any login prompt and there is no effect on device after giving any command. Although i can see the logs on the console session - but cant do anything.
 
I have a second way of connecting the device via inband- management, and checked the device config found it correct. It is same as other devices which are working correctly.
 
Both C3750 and C2960 are behaving exactly same - can see logs on console but see effect of even pressing enter - not getting login prompt as well.

View 4 Replies View Related

Cisco Switching/Routing :: Error While Upgrading IOS On 2960 Switch Using Tftp Server

Apr 29, 2013

I am trying to copy IOS from my TFTP server which is on my laptop to cisco 2960 switch
 
I am able to ping to switch from my laptop, connectivity is fine, tftp server is running
 
Current Image on Switch --> C2960-LANBASE-MZ.122-25.SEE3.bin -->  trying to upgrade to --> c2960-lanbasek9-mz.122-53.SE2
 
I am getting below error when trying to upgarde IOS:
 
2960-SW#copy tftp: flash:           
Address or name of remote host []? 10.1.x.x
Source filename []? c2960-lanbasek9-mz.122-53.SE2

[Code].....

View 6 Replies View Related

Cisco Switching/Routing :: Configure 2960 8 Port Switch With DHCP Server?

Jun 24, 2012

I need to configure a Cisco 2960 switch as a DHCP server.    The current IP address will be on a different seed than the DHCP addresses.  i.e.
 
Switch IP = 10.1.2.3, GW = 10.1.2.1, Subnet = 255.255.255.0
DHCP addresses would be 192.168.1.1 - 200, GW=???? (10.1.2.3?) and subnet would be 255.255.255.0

View 1 Replies View Related

Cisco Switching/Routing :: Catalyst 2960 / VLAN Configuration Using MS DHCP Server

Jan 28, 2013

I am going to creat VLANs very 1st time therefore for test purpose I have following simple scnerio.I have created 2 VLANs , VLAN2 and VLAN3 on Cisco Catalyst 2960 series switch. Ports 1-12 is assigned to VLAN2 and Ports 13-24 are assiged to VLAN3. Now I have configured DHCP on Microsoft Server 2003 defining 2 scopes with following configurations.
 
Scope 1 for VLAN 2--- Range is 172.16.0.17 to 172.16.0.30   with subnet mask=255.255.255.240 . Server IP address 172.16.0.17
( Note: Address 172.16.0.17 is excluded from dhcp server Scope 1 and give to the MS server itself)
 Scope 2 for VLAN 3----Range is  172.16.0.33 to 172.16.0.46 with subnet mask=255.255.255.240 .
 
Now in Cisco 2960 series switches, under Vlan 2 and Vlan 3, I have following configurations...
 
interface Vlan2
ip address 172.16.0.30 255.255.255.240
ip helper-address 172.16.0.17
 interface Vlan3
ip address 172.16.0.46 255.255.255.240
ip helper-address 172.16.0.17
 
Now the problem is when i connect a client computer to any port from 1-12, It gets correct IP address from Scope 1 but when I connect a computer to any port from 13-24, it does not get the ip address.
 
Further I want to do inter VLAN comunication as well for that purpose i Have an  ISR 2900 series router. What further configuration i will have to do on router for inter vlan communication.

View 3 Replies View Related

Cisco Switching/Routing :: 2960 - DHCP Server Port-Based Address Allocation

Nov 15, 2012

Does the 2960 switches with LAN-Lite support DHCP Server Port-Based Address Allocation?

View 1 Replies View Related

Cisco Switching/Routing :: Add 2960 To Stack Of 4 X 2960 Switches

Feb 7, 2012

I have an existing stack of 4 x 2960-S switches connected by stack cables.I would like to add another 2960-S switch to the stack but am unable to as the 2960-S will only allow 4 x 2960-S switches per stack.how I would add the 5th 2960-S switch to the existing stack of 4 x 2960-S switches.

View 12 Replies View Related

Cisco Switching/Routing :: 2960-S To 2960-LST Configuration Over Fiber?

Feb 11, 2013

I have a 24 port 2960-S that is not communicating with a 2960-LST that it is directly connected to over fiber.  The link is up on the LST but will not come up on the -S.  What command should I use to bring up this link?  I have tried no shut from the (Config-if)# prompt.         

View 3 Replies View Related

AAA/Identity/Nac :: ACS 4.2 Radius Authentication For SSL VPN Users

Dec 22, 2012

Using Cisco ASA I want the  ssl clientless vpn users to be authenticated through a local Radius-Server. but it does not work, and on asa while i want to see (Debug Radius) output, there is no debuging msgs displayed.    When i try to test the user which i have created on the ACS-Server 4.2,  the test gets successful.  where i have made a mistake in my configuration ?

View 2 Replies View Related

Cisco :: Aeronet 1250 - Radius Authentication For Wi-Fi Users?

May 20, 2013

I have a aeronet 1250 access point and i have a windows 2003  radius server configured to authenticate users. I need to configure the access point for radius authentication .

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.x TACACS / Radius Password Policy Profile For Different Users

Sep 4, 2012

I just came across a requirement, of implementing different password policies for different group users.
 
I can see in >>>>SYSTEM CONFIGURATION>>>>User>>AUTHENTICATION SETTINGS has only global option to implement the password complexity/no of days for active user. But i need this feature to be based for per user/group

View 3 Replies View Related

Cisco WAN :: Radius Authentication On Catalyst 2960?

Feb 25, 2013

I have a problem with radius authentication on catalyst 2960 with freeradius as radius-server. The Catalyst is behind a HP5412zl layer3-switch. The rest of the network are hp-layer2 switches, which do radius authentication to the same radius server. The ios on the catalyst is c2960-lanbasek9-mz.150-1.SE3. Apparently there are no requests made to the radius-server, since I dont see any requests coming in. Port 0/7 is voice port with laptop behind , /port 0/8 access-port with laptop directly connected.
 
config :
 
aaa new-model
aaa authentication dot1x default group radius
 dot1x system-auth-control
!
!
!
interface FastEthernet0/1

[code]....

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Http Radius Authentication Fail In 12.2.58 And 15.0.1 For 2960

Aug 18, 2011

Find here the extraction of the configuration and the debug sysout. The radius servers works fine with all the other accesss like ssh, telnet...
 
Just the http access fail. This configuration work fine with the version 12.2.55 installed before.
  
Aaa new-model
aaa authentication login default group radius local
aaa authentication login physique local

[Code].....

View 2 Replies View Related

Cisco Switching/Routing :: ASA 5510 / Routing Mobile Users Via VPN To Different Gateways

Oct 6, 2012

I have mobile users using air cards that connect to the network with a VPN product called Net Motion. Our  firewall is a ASA 5510. Once connected to the Net Motion VPN server the user will get a DHCP address from our network. In the past we could not get the VPN tunnel to complete since our layer 3 switch (3750G IP services) has 3 egress points and the egress point that we needed the VPN traffic to go out of is not the default gateway. To solve this we had the air card carrier set switch our air cards to static IP addresses and using route statements for the public IP addresses and access lists we got it to work.
 
The problem with this is that every new air card we provision needs a static IP address. My question is would policy based routing work in this scenario? The problem has been that the VPN tunnel was not able to complete the negotitaion phase as the traffic came into the switch and was trying to go out the default gateway. The VPN client wont get an internal IP address until the VPN tunnel is created.
 
I would like to get away from using static IP addresses.

View 1 Replies View Related

Cisco Switching/Routing :: 3560 V2 24 PS-S - RADIUS Not Working

Aug 15, 2012

We are using mac authentication, it is working fine on all of the other 3560's except this new one.
 
Mac address shows up completely different (very long hex, doesnt even look like a mac address) on ACS compared to what its showing on the switch in the mac address table.
 
Im stumped, config matches every other 3560 in the building, has something changed in the v2 software compared to the older 3560's ?

View 5 Replies View Related

Cisco Switching/Routing :: 3560V2 Switch Radius

Feb 13, 2012

A Cisco 3560V2 was bought to complete a project at my company. I noticed the IPBase IOS Image was installed. I was unable to configure RADIUS. I upgraded the IOS to the Latest Release of the IPServices IOS Image. I still dont have the capabilities of configuring RADIUS.

View 4 Replies View Related

Cisco Switching/Routing :: Configuring Radius On 2950G Switch With IOS 12.1?

Jul 20, 2011

getting radius to work on a 2950G switch with an older IOS of 12.1(22)EA1. I have radius setup on a windows 2k8 box and all of my other switches 2960's and above have no issues. I am unable to input the nas-identifier of 32 into the config using - radius-server 32 attribute 32 include-in-access-req format %h as well as the aaa session-id common commands. Doing a debug radius says that the radius server is not defined.

View 5 Replies View Related

Cisco Switching/Routing :: Configure RADIUS In IOS15 On 3750X?

Mar 21, 2013

I went to configure RADIUS on my 3750X with IOS 15, and lo and behold it is not where it used to be. Did it get moved somewhere else that I can't seem to find very easily? 

View 2 Replies View Related

Cisco Switching/Routing :: AP1142N Radius To Access Web Interface

Dec 13, 2012

I currenly have a cisco AP1142N configured to work with our radius server (It was already configured when I took over the network). I order two additional access points for building coverage on multiple floors. Currently, I uploaded the config of the orginal access point to the new device and I can access the device via web and the ssid is being broadcasted. I then added in the access point into IAS with the radius secret key to our Radius server. When I go to connec to the new access point w/ domain credentials I am not able to establish a connection. I am not very familiar with CISCO products. I followed a video to get the access point up and running w/ an IP from CLI so I could access the web interface and upload the edited config.txt file. Are there any issues with setting up multiple access points w/ a single windows radius (IAS) server?

View 7 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved