cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1505
Views
10
Helpful
5
Replies

realm on ACS ?

pt_wang
Level 1
Level 1

I am searching the solution  "realm" concept of Linus Radius  on Cisco ACS.

The customer hope their authentications such as account aaa@bbb.ccc send to a specific Radius server while other accounts aaa(such as no realm) to their window database(unknown user policy).

5 Replies 5

Tarik Admani
VIP Alumni
VIP Alumni

Which version of ACS are you trying to accomplish this on, if you are trying this on our older ACS software (pre 5.x) you will go to Network Configuration -> Proxy Distribution Table -> Add Entry

You will enter @bbb.ccc select suffix for the positoin field then select the radius server you would like to forward this to. (keep in mind the radius server will have to be added under the network configuration page)

If you need directions for ACS 5.x let me know. I can try to put together some screen captures and post them up.

Thanks,

Tarik Admani

pt_wang
Level 1
Level 1

I add another Radius server on ACS.  But in ACS ,I can not select ports  (It use 1645/1646)

How I add another Radius Server on ACS using ports 1812/1813?

When Adding new AAA server entry with server Type CiscoSecure ACS , even if you select 1645,1646 the 1812,18,13 port set still valid and ACS can handle Radius auth and acct packets received on those ports as well.

So if the other Radius server that you are willing to proxy part of the RADIUS AAA traffic is Cisco Secure ACS it should be fine.

Mohammad Aldehnee

-----------------------------------

Don't forget to rate answers that you find useful

My ACS version is 3.3.

I add another Radius server is Unix type so I select Radius and no port I can define here.

I was sniff the packets out to radius server ( I defined in proxy distribution table), the ports used is 1645/1646.

Does your Unix RADIUS server supports the two sets of ports or only 1812 and the 1813

If it supports only one set you can edit the port numbers at least on the new releases.

But specifying two sets of ports upon the addition of a new RADIUS server is not possible.

Mohammad Aldehnee

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: