08-25-2006 03:55 AM - edited 03-10-2019 02:43 PM
I use the ACS box mainly for AAA on the switches and routers using tacacs. Now we're looking at the possibility of using 802.1x, my early reading tell me I have to use RADIUS, but I'm using TACACS, can I have ttow different methods of authentication on the same switch/router?
Any help would be greatly appreciated.
Thanks.
08-25-2006 04:21 AM
Yes you can. You specify which interfaces use which protocol in what order.
08-25-2006 04:39 AM
Yes, you have to run RADIUS for 1X, but you can enable both just fine.
08-25-2006 05:07 AM
Is there an example config where both are shown? Each time I add a radius command it erases a radius command, but then I am doing the defaults and nothing specific.
Thanks.
08-25-2006 07:07 AM
Not sure what you mean, but here's an example with 2 servers:
aaa group server tacacs+ mgmt_access
server 10.10.10.2
server 10.10.10.3
aaa group server radius dot1x_access
server 10.10.10.2
server 10.10.10.3
aaa authentication login VTY group mgmt_access enable
aaa authentication dot1x DOT1X group dot1x_access
09-28-2006 03:57 AM
Hi ,
Yes you can have different authentication methods on the same router/switch .
In case if you need to configure 802.1x you can simply add the 802.1x commands as they will not interfare in the working of your tacacs authentication .
If you want to configure radius for login authentication along with exsisting Tacacs then you need to configure method list .
Regards,
Puneet
01-24-2007 07:54 AM
Hi Puneet,
I'm also stuck with the same problem. I understand that a Router/Switch could be configured to use both the protocols get authenticated, however I don't see if the same is possible with any of the ACS Servers?
Or in other words, if I have to use the dot1x and the TACACS for enable purposes, I have to use 2 differnt ACS Servers, one with RADIUS and second with the TACACS+ protocol.
Plesae correct me if I'm wrong.
Regards,
Wilson Samuel
01-24-2007 08:51 AM
You do have to have two entries in the ACS box. So here's how I did it, I named one entry switch1 and the other entry switch1-radius. On the switch1 I selected tacacs on the switch1-radius I selected RADIUS (CISCO IOS PIX).
Restarted the service and it didn't complain a bit and it works fine.
01-24-2007 09:59 AM
Wow.. such a simple thing never clicked in my brain.. Thanks a lot!!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide