cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
644
Views
0
Helpful
1
Replies

Cisco Prime Infrastructure with AAA server

Mohamed Sayed
Beginner
Beginner

Hi all,

I have installed cisco PI and I have AAA server in my network and I added this server (AAA) to the PI.

I want to know what are the benefits of this synch between AAA server and PI ???

thanks alots.

1 Reply 1

Marvin Rhoads
VIP Community Legend VIP Community Legend
VIP Community Legend

Not a whole lot.

You can set your PI to use an external AAA server for authentication to PI itself (reference). Authorization (i.e what the authenticated user may do on the server) requires settings local to the PI server. PI itself doesnt really "manage" any AAA servers other than the most basic up/down ping test. You might be able to load the server MIBs and get a little more out of it but that's really not what PI is designed to do.

You can setup ISE (if you use it) as a data source in PI to show you what users have authenticated to ISE-managed devices.

Prime LMS (before it was Prime and just plain LMS back to the CiscoWorks days) used to be able to rely on a TACACS server for authorization but the integration was a bit complicated and Cisco moved away from that as LMS moved to v4 and their TACACS server product (ACS) moved to v5.

Of coure the crredentials PI uses to log into devices can be on the AAA server but that's a device - AAA integration, not really a PI integration.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: