cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
523
Views
0
Helpful
2
Replies

TACACS=admin RADIUS=802.1x same ACS?

sbrooke
Level 1
Level 1

I have an ACS appliance set up for TACACS auth for administrative users. I need to configure 802.1x with RADIUS as I'm sending the VLAN ID back down when the user authenticates. Is this possible? Doesn't seem to be working for me. Also, I am doing this on both CatOS and IOS so IOS only solutions won't help.

Thanks!

2 Replies 2

darpotter
Level 5
Level 5

Hi

Yes you can do both T+ device admin and 802.1x from the same ACS server.

Luckily T+ and RADIUS config happily co-exist even in the same groups because they are pretty much orthogonal.

Darran

jafrazie
Cisco Employee
Cisco Employee

Yes, it's possible. You need to set the following stndard RADIUS attributes via a per-group or per-user basis:

[64] Tunnel-Type ? ?VLAN?

[65] Tunnel-Medium-Type ? ?802?

[81] Tunnel-Private-Group-ID - ""

Hope this helps.