<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RSA SecurID and Cisco ACS integration for user(s) with enabl in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964335#M390461</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately this option is not available at group level&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other way is using RDBMS, see this link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/A_RDBMS.html#wp92082" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/A_RDBMS.html#wp92082&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action Code 105&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Jun 2008 13:25:20 GMT</pubDate>
    <dc:creator>Jagdeep Gambhir</dc:creator>
    <dc:date>2008-06-02T13:25:20Z</dc:date>
    <item>
      <title>RSA SecurID and Cisco ACS integration for user(s) with enable mode</title>
      <link>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964332#M390370</link>
      <description>&lt;P&gt;I thought I had this problem figured out but I guess not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Cisco 2621 router with IOS 12.2(15)T17.  Behind the&lt;/P&gt;&lt;P&gt;router is a Gentoo linux, RSA SecurID 6.1 and Cisco ACS 3.2.&lt;/P&gt;&lt;P&gt;I use tacacs+ authentication for logging into the Cisco router&lt;/P&gt;&lt;P&gt;such as telnet and ssh.  In the ACS I use "external user databases"&lt;/P&gt;&lt;P&gt;for authentication which proxy the request from the ACS over &lt;/P&gt;&lt;P&gt;to the RSA SecurID Server.  I installed RSA Agents with &lt;/P&gt;&lt;P&gt;sdconf.rec file on the Cisco ACS server.  I renamed "user group 1"&lt;/P&gt;&lt;P&gt;to be "RSA_SecurID" group.  In the "External user databases" and &lt;/P&gt;&lt;P&gt;"database configurations" I assign SecurID to this "RSA_SecurID"&lt;/P&gt;&lt;P&gt;group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything is working fine.  In the "User Setup" I can see dynamic&lt;/P&gt;&lt;P&gt;user test1, test2,...testn listed in there as "dynamic users". In&lt;/P&gt;&lt;P&gt;other words, I can telnet into the router with my two-factor &lt;/P&gt;&lt;P&gt;SecurID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that if test1 wants to go into "enable" mode with&lt;/P&gt;&lt;P&gt;SecurID login, I have to go into "test1" user setting and select &lt;/P&gt;&lt;P&gt;"TACACS+Enable Password" and choose "Use external database password".&lt;/P&gt;&lt;P&gt;After that, test1 can go into enable mode with his/her SecurID&lt;/P&gt;&lt;P&gt;credential.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, this works fine if I have a few users.  The problem is that&lt;/P&gt;&lt;P&gt;I have about 100 users that I need to do this.  The solution is&lt;/P&gt;&lt;P&gt;clearly not scalable.  Is there a setting from group level that &lt;/P&gt;&lt;P&gt;I can do this?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ACS "experts" want to help me out here?  Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964332#M390370</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2019-03-10T22:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: RSA SecurID and Cisco ACS integration for user(s) with enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964333#M390419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sure there is, in the group config, TACACS+ Settings section check Shell(exec) and Privilege level boxes, in the field next to the Privilege level type in 15.&lt;/P&gt;&lt;P&gt;Then in Shell Command Authorization either select a shared auth profile (if defined) or to allow the execution of all commands check Per Group Command Authorization and Permit.&lt;/P&gt;&lt;P&gt;This will give level 15 to all the users who are the members of this group upon entering just username / PASSCODE, no enable required. This does not work with ASAs (at least I have not figured out the authorizzation sesstings in ASA), so with ASA after entering the user /PASSCODE you have to wait for the next token code to enter enable &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jun 2008 18:33:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964333#M390419</guid>
      <dc:creator>dmitry</dc:creator>
      <dc:date>2008-06-01T18:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: RSA SecurID and Cisco ACS integration for user(s) with enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964334#M390448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is not what I want.  I want user "test1" to be able to do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C&lt;/P&gt;&lt;P&gt;*****************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: test1&lt;/P&gt;&lt;P&gt;Enter PASSCODE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C2960&amp;gt;en&lt;/P&gt;&lt;P&gt;Enter PASSCODE:&lt;/P&gt;&lt;P&gt;C2960#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words, test1 user has to type in his/her RSA token password to get&lt;/P&gt;&lt;P&gt;into exec mode.  After that, he/she has to use the RSA token password to&lt;/P&gt;&lt;P&gt;get into enable mode.  Each user can get into "enable" mode with his/her&lt;/P&gt;&lt;P&gt;RSA token mode.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way you descripbed, it seemed like anyone in this group can go directly&lt;/P&gt;&lt;P&gt;into enable mode without password.  This is not what I have in mind.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas?  Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jun 2008 21:40:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964334#M390448</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-06-01T21:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: RSA SecurID and Cisco ACS integration for user(s) with enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964335#M390461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately this option is not available at group level&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other way is using RDBMS, see this link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/A_RDBMS.html#wp92082" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/A_RDBMS.html#wp92082&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action Code 105&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2008 13:25:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964335#M390461</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-06-02T13:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: RSA SecurID and Cisco ACS integration for user(s) with enabl</title>
      <link>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964336#M390498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Excluding RDBMS, are there workarounds for&lt;/P&gt;&lt;P&gt;this?  RDBMS is too cumbersome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am suprised a complex piece of software&lt;/P&gt;&lt;P&gt;like Cisco ACS does not offer this feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 00:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rsa-securid-and-cisco-acs-integration-for-user-s-with-enable/m-p/964336#M390498</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-06-03T00:15:23Z</dc:date>
    </item>
  </channel>
</rss>

