Parser Views/Superviews w/ RADIUS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-05-2020 06:34 AM
I've been trying to find if there are vendor-specific RADIUS attributes for linking our Windows NPS server to views/superviews on our 2900 series routers and haven't been having any luck. I've been using privilege levels but find managing those tedious. Is there a way to use views or are the privilege levels the only things supported?
Thanks!
- Labels:
-
Other Network Security Topics
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-05-2020 09:54 AM
Hi,
Microsoft NPS supports Vendor Specific Attributes; look for Cisco and include the following attribute as authorization in your NPS policy: "shell:cli-view-name=VIEWNAME". You would assign the users privilege level 15, as the view will control what commands they have access to.
Ideally you would do command authorization via TACACS, and there are free TACACS servers running perfectly.
Regards,
Cristian Matei.
