08-09-2011 06:09 AM - edited 03-09-2019 11:38 PM
Has anyone used RSA Securid token to log into Cisco Routers, Switches and Firewalls to manage them. Is it even supported on Cisco devices? I am NOT talking about VPN access.
Any help will be greatly appreciated.
Thanks,
Lake
Solved! Go to Solution.
08-09-2011 06:28 AM
Yes, I have.On the router & switches you don't authenticate directly to the RSA server, it goes through an intermediate, like Cisco ACS.
08-09-2011 11:41 AM
Your theory is correct. The only difference is that on the ACS server you setup VSA's so it communicates with the RSA server using it's "language". It's actually pretty easy to setup. It's more of a hassel using the tokens all the time than it is setting up the servers.
08-09-2011 11:50 AM
It's not required but a good idea for when you are troubleshooting
08-09-2011 11:55 AM
08-10-2011 07:14 AM
Then that should work. If you set it up that way, let us know for sure.
08-09-2011 06:28 AM
Yes, I have.On the router & switches you don't authenticate directly to the RSA server, it goes through an intermediate, like Cisco ACS.
08-09-2011 06:39 AM
Thank you very much.
Regards,
Lake
08-09-2011 09:54 AM
Hi Colin,
Can you please give me an overview of the setup or confirm my theory?
I assume i install the Cisco ACS server software on a Windows server and configure all the cisco devices to connect to the ACS server.
Then i setup my RSA appliance and configure the RSA appliance for communication with the Windows ACS server. Can i add the Windows ACS server as a host or a Radius client or?
I would really appreciate an answer for my question?
Thanks,
Lake
08-09-2011 11:41 AM
Your theory is correct. The only difference is that on the ACS server you setup VSA's so it communicates with the RSA server using it's "language". It's actually pretty easy to setup. It's more of a hassel using the tokens all the time than it is setting up the servers.
08-09-2011 11:48 AM
Do i have to install the RSA agent on the Windows ACS server?
08-09-2011 11:50 AM
It's not required but a good idea for when you are troubleshooting
08-09-2011 11:53 AM
I am a little confused. Then how will the two communicate? Do i just add the IP Address of the ACS server in RSA Appliance?
Thanks,
Lake
08-09-2011 11:55 AM
Maybe this will help.
http://www.rsa.com/rsasecured/guides/imp_pdfs/Cisco_ACS_42_AuthMan7.1.pdf
08-10-2011 06:50 AM
Can this be done with Cisco ACS?
Thanks,
Lake
08-10-2011 06:56 AM
Can what be done? The link above describes RSA with ACS.
08-10-2011 07:08 AM
I mean if the Cisco routers, switches and firewalls can be setup so i can login using an RSA token without an ACS server.
Thanks,
Lake
08-10-2011 07:09 AM
Hmm, not sure if the RSA software has a built-in RADIUS server. The RSA site may be able to help there.
08-10-2011 07:12 AM
RSA Securid does have a built in Radius server
Thanks,
Lake
08-10-2011 07:14 AM
Then that should work. If you set it up that way, let us know for sure.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide