Cisco 4700M Configuration Manual page 87

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 2
Configuring Authentication and Accounting Services
Step 4
Step 5
Defining Private Attributes for Virtualization Support in a RADIUS Server
OL-16202-01
(Optional) If you are using Cisco Secure ACS for Windows Server, you can
specify log file management, which determines how large the RADIUS account
files can be, how many are retained, how long they are retained, and where they
are stored.
You can use Cisco Secure ACS to send accounting data to other AAA
Note
servers by configuring the AAA server entry in the Network
Configuration section of the HTML interface. For details, see the
applicable Cisco Secure ACS user guide.
Click Submit when you finish moving the attributes into the Logged Attributes.
Cisco Secure ACS saves and implements the changes that you made to its
RADIUS accounting configuration.
You can create the same username across contexts and associate it with a unique
role in a context and multiple domains. Contexts can share a RADIUS server, but
the user must be authenticated for each context and must use the same password.
When a user attempts to log in to the ACE, the RADIUS client on the ACE sends
the username and password to the remote RADIUS server for authentication. The
RADIUS server retrieves a user's profile as part of the authentication request.
Once the user is successfully authenticated, the RADIUS server returns a user
profile to the RADIUS client on the ACE with the authentication status. If the
associated context of the user attempting to log in matches the contexts of the user
profile obtained through the RADIUS server, the RADIUS client updates the user
profile with the remote server user profile. If the contexts do not match, the user
profile is updated with the default role (Network-Monitor) and the default domain
(default-domain).
Configure the user profile on the RADIUS server as a Vendor Specific Attribute
with vendor Id Cisco (09) and subattribute type CiscoAVPair (type 01) with a
value string in the following format:
shell:<contextname>=<role> <domain1> <domain2>...<domainN>
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
Configuring the AAA Server
2-17

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents