<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is AAA possible for IPS? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826879#M84816</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That jives with my understanding.  The sensors don't support AAA and the addition of CSM doesn't change that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best you can probably do is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) configure AAA in CSM&lt;/P&gt;&lt;P&gt;2) configure CSM to use a "process account" for logging into the sensors (i.e. "security manager device creds")&lt;/P&gt;&lt;P&gt;3) configure the sensors to ONLY allow connections from specifiic IP addresses (like CSM and MARS).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The last step is big...if you can do it.  You might want to add a trusted server that only the IDS team has access to in the event that CSM dies for some reason and you need to reach a sensor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Jan 2008 20:15:27 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2008-01-28T20:15:27Z</dc:date>
    <item>
      <title>Is AAA possible for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826876#M84813</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Is it possible to configure AAA with Cisco IPS and CSACS?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:57:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826876#M84813</guid>
      <dc:creator>dehghan</dc:creator>
      <dc:date>2019-03-10T10:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is AAA possible for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826877#M84814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;not directly no.  The best you can do today is to use Cisco Security Mananager (CSM) to manage your sensors and configure AAA in CSM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2008 14:44:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826877#M84814</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2008-01-28T14:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is AAA possible for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826878#M84815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just got bitten by this.  CSM has the option (Tools-&amp;gt; Security Manager Administration -&amp;gt; Device Communication) to use "Security Manager Device Credentials" or "Security Manager User Login Credentials".  The former will use whatever account info you configured when you added the device, and the latter will use whatever username is currently doing the config changes via CSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The latter option is preferable when you're in an ACS / AAA environment, because then TACACS+/RADIUS account logs will show the user that actually made the modifications.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to switch to that option, but since the IPS devices don't support AAA, CSM choked and couldn't complete the update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I can tell the change affects all CSM-managed devices; you can't change it on a per-device basis.  So to get this to work I'd have to have every user that manages IPS devices log in to each IPS sensor (two dozen+) and create a local username/pass that matches their current login creds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSM doesn't support configuring AAA on IPS sensors, since the sensors themselves don't support it.  Everything is local.  Other posts here seem to claim "well, your IPS sensors are -supposed- to be secure" but I don't buy it.  Having multiple, independent local accounts spread out over dozens of sensors seems LESS secure.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2008 18:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826878#M84815</guid>
      <dc:creator>clausonna</dc:creator>
      <dc:date>2008-01-28T18:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Is AAA possible for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826879#M84816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That jives with my understanding.  The sensors don't support AAA and the addition of CSM doesn't change that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The best you can probably do is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) configure AAA in CSM&lt;/P&gt;&lt;P&gt;2) configure CSM to use a "process account" for logging into the sensors (i.e. "security manager device creds")&lt;/P&gt;&lt;P&gt;3) configure the sensors to ONLY allow connections from specifiic IP addresses (like CSM and MARS).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The last step is big...if you can do it.  You might want to add a trusted server that only the IDS team has access to in the event that CSM dies for some reason and you need to reach a sensor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2008 20:15:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826879#M84816</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2008-01-28T20:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is AAA possible for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826880#M84817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So do you create a 'dummy' entry for the IPS in ACS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 13:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826880#M84817</guid>
      <dc:creator>jpazahanick</dc:creator>
      <dc:date>2008-06-03T13:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is AAA possible for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826881#M84818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You configure CSM to use AAA/ACS for access by users.  You add sensors into CSM using the normal process (this won't have anything to do with AAA or Cisco ACS).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 15:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826881#M84818</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2008-06-03T15:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is AAA possible for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826882#M84819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm getting a 'Device Not Authorized' 'The device is not in the Cisco Secure ACS error, but this could be because the device is running 6.1, and I just read CSM 3.2 doesn't support 6.1 yet..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 15:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-aaa-possible-for-ips/m-p/826882#M84819</guid>
      <dc:creator>jpazahanick</dc:creator>
      <dc:date>2008-06-03T15:36:02Z</dc:date>
    </item>
  </channel>
</rss>

