cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
860
Views
0
Helpful
5
Replies

where the AAA cache is stored??

david de sousa
Level 1
Level 1

                   Hi,

I'd like to know where the DB for the AAA caching is stored. because i made a caching for my users and it works well. but at reboot, the cache is empty and we need to reauthenticate to populate the DB.

Is it possible to store that DB in NVRAM or another location ? where can i see this DB file?

Thanks for reply

5 Replies 5

Amjad Abdullah
VIP Alumni
VIP Alumni

Hi David:

What is your auth method? what are you using authentication for? what are the AAA devices? what is the AAA server?

What type of users are authenticating?

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"

Hi Amjad,

we use authentication via a RADIUS server hosted on a windows server 2008, we autenticate users to grant access to the network devices like switchs and routers Cisco. we match on an active directory user and give differents level privileges.

everythings is good, works fine, we use this as a fail-over for access to the devices. but we have some mobiles equipments, and we like to grant an access even if the mobile device is not connected to our network. but the problem is, when we shut down the devices, the cache is cleaned, and after reboot, the cache is empty.

I'd like to know if it's possible to store the AAA cache in a location who can stay populated like in NVram for example. is it possible? where can i see the cache file? can i see it?

thanks

David:

Where you configure the cache? can you please describe briefly how it is being cnofigured on the NPS? That will allow us to understand how it works. Just a brief description how those devices authenticate and how they are getting cached.

Thank you.

Amjad

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"

hi,

well the cache is configured on the cisco's device, after a logon, the username/password (authentication) and the privilege (authorization) is cached in the switch or router. not on the NPS. So the cache is local to the device. that's why, when i power off the device, the cache is cleaned. and i'd like to keep it in the device.

thank you

David:
Thank you for your explanation. So you authenticate wired devices to the switch.

I would suggest that you use a mechanism called MAB (MAC Authenticaion Bypass). This will authenticate your devices based on a mac address.

This is usually intended for devices that do not support 802.1x and connected to a switch so they get allowed on the network based on their MAC address which is added to a whitelist on the RADIUS.

If you search a little about how to configure that on your radius I think you'll find something useful.

HTH

Amjad

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"