<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.2 using radius proxy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652096#M310802</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Uggh.&amp;nbsp; I just saw more docs and I realized that access policies drive everything, one doesn't put&lt;/P&gt;&lt;P&gt;the methods where they were previously, like in 4.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay, let me read this to see if I can get it to work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Feb 2011 22:51:03 GMT</pubDate>
    <dc:creator>eugene.tsuno</dc:creator>
    <dc:date>2011-02-01T22:51:03Z</dc:date>
    <item>
      <title>ACS 5.2 using radius proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652092#M310787</link>
      <description>&lt;P&gt;I am new to ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I want to do is talk to another radius server (safeword) and authenticate users against it on a linux host using pam_radius.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the minimum steps to do this?&amp;nbsp; (setup groups/policy/users)&amp;nbsp; Using radtest, I can authenticate a local user but&lt;/P&gt;&lt;P&gt;I haven't got it to autthenticate anything using radius proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does not seem as easy as I think it should be.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652092#M310787</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2019-03-11T00:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 using radius proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652093#M310790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG style="color: #800000; "&gt;Implementing Proxy Radius server:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;ACS 5.1 can act as&amp;nbsp; radius proxy server, it accepts the authentication, accounting, authorization request from the NAS and forwards it to external radius server. It accepts the failure or success results of the requests and sends back to NAS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;ACS can simultaneously act as a proxy server to multiple external RADIUS servers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Steps to create proxy server:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Go to Network Resources &amp;gt; External RADIUS Servers&amp;gt; create &amp;gt; click the external radius server name and edit&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Name----external radius server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Ip address: x.x.x.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Shared secret key: cisco123&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Advance options:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Authentication port:1812&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Acct port:1813&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Server timeout: default is 5 sec (can vary from 1 to 120 sec)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Connection attempts: default is 3 (can vary from 1 to 10) &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Go to access policy&amp;gt; create a new service&amp;nbsp; using (User Selected Service Type—RADIUS Proxy) (don’t user predefined template) &amp;gt;&amp;nbsp; Select the external RADIUS servers to be used for proxy and move them to the Selected External RADIUS Servers list.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Before you do above mentioned steps, please do verify that you can ping the external radius server through ACS 5.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Go to launch monitoring and reports &amp;gt; connectivity &amp;gt; type in ip address of radius server and ping.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Regds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts~&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Jan 2011 01:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652093#M310790</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-01-29T01:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 using radius proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652094#M310796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I've done that before.&amp;nbsp; What is missing is how do you&lt;/P&gt;&lt;P&gt;link a user to actually authenticate to that service?&amp;nbsp; When&lt;/P&gt;&lt;P&gt;I define a "internal user" in the identiy store, it does not have an option to link to the&lt;/P&gt;&lt;P&gt;external radius service, it simply has a settings of a a password. I have access&lt;/P&gt;&lt;P&gt;to a 4.2 ACS, and you can plainly see that once the external store is defined you&lt;/P&gt;&lt;P&gt;can setup an individual user to use it.&amp;nbsp; But on mine, it doesn't have any way to link it in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I running a broken copy of the software?&amp;nbsp; I can probably revert to 5.1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Feb 2011 18:02:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652094#M310796</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2011-02-01T18:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 using radius proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652095#M310798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I attach screen shot.&amp;nbsp; I thought here it would select which auth method to use.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Feb 2011 21:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652095#M310798</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2011-02-01T21:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 using radius proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652096#M310802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Uggh.&amp;nbsp; I just saw more docs and I realized that access policies drive everything, one doesn't put&lt;/P&gt;&lt;P&gt;the methods where they were previously, like in 4.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay, let me read this to see if I can get it to work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Feb 2011 22:51:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652096#M310802</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2011-02-01T22:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 using radius proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652097#M310808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Finally got this to work.&amp;nbsp; I did not have the Access Policies defined to use the Radius Proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd wish examples were written to go start to finish from one type of authentication, through all&lt;/P&gt;&lt;P&gt;the changes that need to be made, start to finish. Like AD, proxy radius, secureid, etc.&amp;nbsp; Or even&lt;/P&gt;&lt;P&gt;a summary report that states for host X and user Y, what policies and restrictions are in play.&amp;nbsp; Like&lt;/P&gt;&lt;P&gt;for Host X, proxy radius and local auth are on and you have acess between hours A-B on day Z.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 17:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-using-radius-proxy/m-p/1652097#M310808</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2011-02-03T17:18:15Z</dc:date>
    </item>
  </channel>
</rss>

