Databases; Trust Relationships - Cisco 2509 - Router - EN User Manual

User guide
Hide thumbs Also See for 2509 - Router - EN:
Table of Contents

Advertisement

Chapter 11
Working with User Databases
The Cisco Secure ACS Authentication Process with Windows
NT/2000 User Databases

Trust Relationships

Note
78-14696-01, Version 3.1
Cisco Secure ACS forwards user credentials to a Windows NT/2000 database by
passing the user credentials to the Windows operating system of the server that
Cisco Secure ACS runs on. The Windows NT/2000 database either passes or fails
the authentication request from Cisco Secure ACS. Upon receiving the response
from the Windows NT/2000 database, Cisco Secure ACS instructs the requesting
AAA client to grant or deny the user access, depending upon the response from
the Windows NT/2000 database.
Cisco Secure ACS grants authorization based on the Cisco Secure ACS group to
which the user is assigned. While the group to which a user is assigned can be
determined by information from the Windows NT/2000 database, it is
Cisco Secure ACS that grants authorization privileges.
To further control access by a user from within the Windows NT User Manager or
the Windows 2000 Active Directory Users and Computers, you can configure
Cisco Secure ACS to also check the setting for granting dialin permission to the
user. This setting is labeled "Grant dialin permission to user" in Windows NT and
"Allow access" in the Remote Access Permission area in Windows 2000. If this
feature is disabled for the user, access is not permitted, even if the username and
password are typed correctly.
Cisco Secure ACS can take advantage of trust relationships that have been
established between Windows NT/2000 domains. If the domain that contains
Cisco Secure ACS trusts another domain, Cisco Secure ACS can authenticate
users whose accounts reside in the other domain. Cisco Secure ACS can also
reference the Grant dialin permission to user setting across trusted domains.
If Cisco Secure ACS is running on a member server rather than a domain
controller, taking advantage of trust relationships depends upon proper
configuration of Cisco Secure ACS at installation. For more information, see
"Windows Authentication from a Member Server" in Installing Cisco Secure ACS
for Windows 2000/NT Servers.
User Guide for Cisco Secure ACS for Windows Server
Windows NT/2000 User Database
11-9

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Secure acs

Table of Contents