<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius to Radius server communication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-to-radius-server-communication/m-p/755613#M420487</link>
    <description>&lt;P&gt;folks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a vpn connection coming into my network which i'm passing onto a third party network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we use radius to authenticate our own users but the new connection uses the third party's authentication server(SecureID - i think) and they now want to our radius server and theirs to use proxy radius authentication so our radius server will authenticate their users&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my concern is that as i know nothing about this i could be introducing a hole in my security model by inadvertently passing on or allowing them to pull our user details to their radius server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has anyone any ideas, thoughts or relevant documents on this please&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks to anyone taking the time to reply&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:11:54 GMT</pubDate>
    <dc:creator>mulhollandm</dc:creator>
    <dc:date>2019-03-10T22:11:54Z</dc:date>
    <item>
      <title>Radius to Radius server communication</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-to-radius-server-communication/m-p/755613#M420487</link>
      <description>&lt;P&gt;folks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a vpn connection coming into my network which i'm passing onto a third party network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we use radius to authenticate our own users but the new connection uses the third party's authentication server(SecureID - i think) and they now want to our radius server and theirs to use proxy radius authentication so our radius server will authenticate their users&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my concern is that as i know nothing about this i could be introducing a hole in my security model by inadvertently passing on or allowing them to pull our user details to their radius server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has anyone any ideas, thoughts or relevant documents on this please&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks to anyone taking the time to reply&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:11:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-to-radius-server-communication/m-p/755613#M420487</guid>
      <dc:creator>mulhollandm</dc:creator>
      <dc:date>2019-03-10T22:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Radius to Radius server communication</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-to-radius-server-communication/m-p/755614#M420489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though there wont be any security hole in such a setup. As you just have to see on which parameters you'll decide that a request need to be proxied to their Radius server for authentication. In general all radius servers have this proxy feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have ACS server, then you can accomplish this by configuring SecureID as an external Database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's something that will help you with ACS-SecureID,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://rsasecurity.agora.com/rsasecured/guides/imp_pdfs/Cisco_ACS_401_AuthMan61.pdf" target="_blank"&gt;http://rsasecurity.agora.com/rsasecured/guides/imp_pdfs/Cisco_ACS_401_AuthMan61.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://rsasecurity.agora.com/rsasecured/guides/imp_pdfs/Cisco_ACS_333_11_AuthMan6.1.pdf" target="_blank"&gt;http://rsasecurity.agora.com/rsasecured/guides/imp_pdfs/Cisco_ACS_333_11_AuthMan6.1.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apart from this if you want to really proxy the request, I can help you with ACS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/netcfg.htm#wp341876" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/netcfg.htm#wp341876&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m sure pure proxy feature is there in most of the radius servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2007 11:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-to-radius-server-communication/m-p/755614#M420489</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-06T11:02:57Z</dc:date>
    </item>
  </channel>
</rss>

