<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help£¡ in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/help/m-p/128325#M436232</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Here's the link for the command details;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip radius source&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_r/fssprocr/srfrad.htm#1039140" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_r/fssprocr/srfrad.htm#1039140&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip tacacs source&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_r/fssprocr/srftacs.htm#1017796" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_r/fssprocr/srftacs.htm#1017796&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For any command lookup, please use the Command Lookup Tool at&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/Support/Cmdlookup/home.pl" target="_blank"&gt;http://www.cisco.com/cgi-bin/Support/Cmdlookup/home.pl&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have be logged into CCO to be able to use this tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the users for ISDN, the above config is correct for authentication i.e. these users will use the service ppp.&lt;/P&gt;&lt;P&gt;If the users are also going to use enable or telnet to the router, then you will need to have " aaa authentication login ......." command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to the url below for more info;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS Configuration Examples&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt2/scdrad.htm#1001308" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt2/scdrad.htm#1001308&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/cs_unx/csu23ug/nasconra.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/cs_unx/csu23ug/nasconra.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt2/scdtplus.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt2/scdtplus.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/cs_unx/csu23ug/nasconfg.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/cs_unx/csu23ug/nasconfg.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yatin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Jul 2003 00:49:18 GMT</pubDate>
    <dc:creator>ywadhavk</dc:creator>
    <dc:date>2003-07-08T00:49:18Z</dc:date>
    <item>
      <title>help£¡</title>
      <link>https://community.cisco.com/t5/network-access-control/help/m-p/128322#M436229</link>
      <description>&lt;P&gt;i need add some branch routers as clients to the acs server.  so when choosing the ip addresses of these routers,  which interface's ip address should i choose?&lt;/P&gt;&lt;P&gt;if i use these routers' loopback interface ip address,  should i add any other command beside the basic aaa configurations?  I mean to specify the loop back address as the source to send related aaa info to the acs server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance! &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:23:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help/m-p/128322#M436229</guid>
      <dc:creator>zhang-hao</dc:creator>
      <dc:date>2019-03-10T14:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: help£¡</title>
      <link>https://community.cisco.com/t5/network-access-control/help/m-p/128323#M436230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You should try using that interface address that is closest to the ACS server's segment. But you could source the Radius/Tacacs from other interfaces such as the loopback as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command to use is&lt;/P&gt;&lt;P&gt;ip radius source-interface  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or in case of tacacs,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip tacacs source-interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;yatin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2003 14:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help/m-p/128323#M436230</guid>
      <dc:creator>ywadhavk</dc:creator>
      <dc:date>2003-07-07T14:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: help£¡</title>
      <link>https://community.cisco.com/t5/network-access-control/help/m-p/128324#M436231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!  Thanks a lot for your help!  And could you tell me any links to learn these commands?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And more help is needed,  if  each branch router has a isdn backup for the main ddn circuit to the center router,  in order to authenticate the user of isdn in case the failure of main circuit,  how can i add users in the acs server?  I mean if it is same as i do when i add users for telnet and enable authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following command for isdn authentication I configured on the center router:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aa authentication ppp default  group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host x.x.x.x key xxxxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And users for isdn have been defined in the branch routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So will the above configuration enough for the isdn authentication to take effect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jul 2003 00:33:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help/m-p/128324#M436231</guid>
      <dc:creator>zhang-hao</dc:creator>
      <dc:date>2003-07-08T00:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: help£¡</title>
      <link>https://community.cisco.com/t5/network-access-control/help/m-p/128325#M436232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Here's the link for the command details;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip radius source&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_r/fssprocr/srfrad.htm#1039140" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_r/fssprocr/srfrad.htm#1039140&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip tacacs source&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_r/fssprocr/srftacs.htm#1017796" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_r/fssprocr/srftacs.htm#1017796&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For any command lookup, please use the Command Lookup Tool at&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/Support/Cmdlookup/home.pl" target="_blank"&gt;http://www.cisco.com/cgi-bin/Support/Cmdlookup/home.pl&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have be logged into CCO to be able to use this tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the users for ISDN, the above config is correct for authentication i.e. these users will use the service ppp.&lt;/P&gt;&lt;P&gt;If the users are also going to use enable or telnet to the router, then you will need to have " aaa authentication login ......." command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to the url below for more info;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS Configuration Examples&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt2/scdrad.htm#1001308" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt2/scdrad.htm#1001308&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/cs_unx/csu23ug/nasconra.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/cs_unx/csu23ug/nasconra.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt2/scdtplus.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt2/scdtplus.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/cs_unx/csu23ug/nasconfg.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/cs_unx/csu23ug/nasconfg.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yatin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jul 2003 00:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help/m-p/128325#M436232</guid>
      <dc:creator>ywadhavk</dc:creator>
      <dc:date>2003-07-08T00:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: help£¡</title>
      <link>https://community.cisco.com/t5/network-access-control/help/m-p/128326#M436233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,  thanks for the quick response.   It's of much help. Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jul 2003 01:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help/m-p/128326#M436233</guid>
      <dc:creator>zhang-hao</dc:creator>
      <dc:date>2003-07-08T01:57:15Z</dc:date>
    </item>
  </channel>
</rss>

