<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring Radius Authentication/Authorization on a 6509 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337308#M429515</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We configure our Catalyst 6500 switches with these commands:&lt;/P&gt;&lt;P&gt;set authentication enable tacacs enable console primary&lt;/P&gt;&lt;P&gt;set authentication enable tacacs enable telnet primary&lt;/P&gt;&lt;P&gt;and it works fine for us. When a user enters the enable command the switch sends an authentication request to the tacacs server and if the user is not configured for enable access in the server then the attmept is denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this works for us with tacacs. I do not believe that there is any significant difference between tacacs and radius though I am not able to verify the function on radius. I did test this on a switch running 7.6(6) and believe that the functionality should be the same on your switch running 7.5(1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Mar 2005 14:56:07 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2005-03-23T14:56:07Z</dc:date>
    <item>
      <title>Configuring Radius Authentication/Authorization on a 6509</title>
      <link>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337303#M429504</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't seem to find the commands to do what I need.  I have a 6509 running 7.5.1 Cat OS.  I want the Radius server to authenticate and authorize privilege based on the user database in Radius.  Could someone point me to the set commands to do this?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way it is now, no matter what attributes are given to the user in the Radius db, they are can execute 'enable' and type the password and they are in enable mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kim&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:03:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337303#M429504</guid>
      <dc:creator>kimlong</dc:creator>
      <dc:date>2019-03-10T21:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Radius Authentication/Authorization on a 6509</title>
      <link>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337304#M429507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would you post the configuration you have for authentication? It sounds to me like you have configured user login to use radius but have not configured enable access to use radius. It would be easier to find your answer if we can see the config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Mar 2005 16:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337304#M429507</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2005-03-18T16:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Radius Authentication/Authorization on a 6509</title>
      <link>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337305#M429511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, I am unable to post the config.  However, it sems like it would only be a one line command to do what you suggest.  Can you provide the command line to enter?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Mar 2005 14:07:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337305#M429511</guid>
      <dc:creator>kimlong</dc:creator>
      <dc:date>2005-03-19T14:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Radius Authentication/Authorization on a 6509</title>
      <link>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337306#M429513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont think this can be done with Cat OS. I know if your running IOS and the RADIUS servers sends a Cisco AV Pair of  shell:priv-lvl=15   the the IOS box will set you up with Enable Access. However this does not work when it is sent to any of my CatOS boxes.  I looked a few months back and wasnt able to find a way to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Timo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Mar 2005 01:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337306#M429513</guid>
      <dc:creator>Tim Glen</dc:creator>
      <dc:date>2005-03-21T01:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Radius Authentication/Authorization on a 6509</title>
      <link>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337307#M429514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2005 13:04:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337307#M429514</guid>
      <dc:creator>kimlong</dc:creator>
      <dc:date>2005-03-23T13:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Radius Authentication/Authorization on a 6509</title>
      <link>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337308#M429515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We configure our Catalyst 6500 switches with these commands:&lt;/P&gt;&lt;P&gt;set authentication enable tacacs enable console primary&lt;/P&gt;&lt;P&gt;set authentication enable tacacs enable telnet primary&lt;/P&gt;&lt;P&gt;and it works fine for us. When a user enters the enable command the switch sends an authentication request to the tacacs server and if the user is not configured for enable access in the server then the attmept is denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this works for us with tacacs. I do not believe that there is any significant difference between tacacs and radius though I am not able to verify the function on radius. I did test this on a switch running 7.6(6) and believe that the functionality should be the same on your switch running 7.5(1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2005 14:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337308#M429515</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2005-03-23T14:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Radius Authentication/Authorization on a 6509</title>
      <link>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337309#M429517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The big difference between RADIUS and TACACS is&lt;/P&gt;&lt;P&gt;that RADIUS is 'open source' and TACACS is Cisco&lt;/P&gt;&lt;P&gt;Proprietary &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  So, implementing TACACS on Cisco&lt;/P&gt;&lt;P&gt;products is really sweet.  Not so much on the RADIUS&lt;/P&gt;&lt;P&gt;side, though.  Cat OS is the fly in the ointment.&lt;/P&gt;&lt;P&gt;With IOS commands I found the 'attribute' command which would allow RADIUS to utilize TACACS attributes.  At least, that's what it looks like at&lt;/P&gt;&lt;P&gt;first glance.  I haven't been able to read through the doc at this time.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to everyone for your suggestions.  I appreciate your time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Mar 2005 13:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configuring-radius-authentication-authorization-on-a-6509/m-p/337309#M429517</guid>
      <dc:creator>kimlong</dc:creator>
      <dc:date>2005-03-30T13:01:18Z</dc:date>
    </item>
  </channel>
</rss>

