<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA authentication on different Cisco Devices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-on-different-cisco-devices/m-p/716695#M419953</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will be possible through Network Access Profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following link can give you more information on NAP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs40/user/sp.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs40/user/sp.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a pointer&lt;/P&gt;&lt;P&gt;You need to create 2 NAP's &lt;/P&gt;&lt;P&gt;One for ACE Module&lt;/P&gt;&lt;P&gt;Other for MDS 9000 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In these you have to define Network Access Filters having ACE for ACE-NAP &lt;/P&gt;&lt;P&gt;and MDS for MDS-NAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And for the NAP's you have to define the Radius Authorization components (attributes) to be send when the authentication happens from the devices referred in NAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Both NAF and RAC can be defined in Shared Profile Components, if you cannot see them there enable them from Interface Configuration)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So now whenever the authentication will happen, ACS will look at the required NAP and for specific device send the required RAC attributes, So for ACE devices you will get only ACE attributes and for MDS you will only get MDS attributes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rohit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Jul 2007 16:26:34 GMT</pubDate>
    <dc:creator>rochopra</dc:creator>
    <dc:date>2007-07-19T16:26:34Z</dc:date>
    <item>
      <title>AAA authentication on different Cisco Devices</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-on-different-cisco-devices/m-p/716694#M419951</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;we use a tacacs Server ACS4.0 and have different networkdevices in our network, just like MDS 9000 ACE-Module and normal CatO and IOS devices. &lt;/P&gt;&lt;P&gt;Now I wanted to creat a group with users with are allowed to connect to all devices as admin. &lt;/P&gt;&lt;P&gt;But to connect to the ACE Module i need to insert the following lines to the ACE Custom attributes: shell:ANLOS*Admin,&lt;/P&gt;&lt;P&gt;and for the MDS 9000 pair*shell:roles="network-admin".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I insert the commands allone the authentication on the devices works, but when I inser both commands, the authentication on the ACE Module failed.&lt;/P&gt;&lt;P&gt;Is it possible to insert both commands so that it works on all devices ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks very mutch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-on-different-cisco-devices/m-p/716694#M419951</guid>
      <dc:creator>pprade</dc:creator>
      <dc:date>2019-03-10T22:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication on different Cisco Devices</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-on-different-cisco-devices/m-p/716695#M419953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will be possible through Network Access Profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following link can give you more information on NAP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs40/user/sp.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs40/user/sp.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a pointer&lt;/P&gt;&lt;P&gt;You need to create 2 NAP's &lt;/P&gt;&lt;P&gt;One for ACE Module&lt;/P&gt;&lt;P&gt;Other for MDS 9000 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In these you have to define Network Access Filters having ACE for ACE-NAP &lt;/P&gt;&lt;P&gt;and MDS for MDS-NAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And for the NAP's you have to define the Radius Authorization components (attributes) to be send when the authentication happens from the devices referred in NAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Both NAF and RAC can be defined in Shared Profile Components, if you cannot see them there enable them from Interface Configuration)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So now whenever the authentication will happen, ACS will look at the required NAP and for specific device send the required RAC attributes, So for ACE devices you will get only ACE attributes and for MDS you will only get MDS attributes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rohit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2007 16:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-on-different-cisco-devices/m-p/716695#M419953</guid>
      <dc:creator>rochopra</dc:creator>
      <dc:date>2007-07-19T16:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication on different Cisco Devices</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-on-different-cisco-devices/m-p/716696#M419955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure that will work... NAP is for RADIUS only and device admin uses TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, the way to do it is create an admins group plus a number of Shared Device Command sets (one for each device type).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the command authorisation section of the group setup add mapping from the AAA Clients (either at device level or NDG) to the appropriate SPC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way an admin user is always in the admin group, but the command authorisation change depending on the device being managed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;et voila!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device Command Sets are explained in this excellent White Paper: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a0080088893.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a0080088893.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2007 06:01:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-on-different-cisco-devices/m-p/716696#M419955</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-07-23T06:01:51Z</dc:date>
    </item>
  </channel>
</rss>

