cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
647
Views
0
Helpful
1
Replies

Configuring multiple authentication sources in router TACACS config / radius

PETER NEGUS
Level 1
Level 1

I have the requirement to allow the customer to login to the router, and to use their own AD for authentication, whilst maintaining our own TACACS access for management. Obviously, I could do an integration between our TACACS server and the customer's AD, but this involves blowing lots of holes in our firewalls and much grief all round.

So what I would like to do is:

For default login (say SMITHJ) authenticate via our TACACS+

For customer login (say john.doe@contoso.com) authenticate via customer owned RADIUS onto the customer's AD.

At a push, I could install a TACACS+ server in the customer domain to proxy onto their AD if it is not possible to do this with RADIUS.

Is this possible? If so a config would be much appreciated.

1 Reply 1

Abzal
Level 7
Level 7

Hi,

I'm not sure about TACACS+ integration with AD. But for such task you can use Windows server 2000/2003 with integrated RADIUS server in box. Or you can use Cisco Access Secure Server which can be integrated with AD.
Refer this link
http://briandesmond.com/blog/how-to-authenticate-against-active-directory-from-cisco-ios/

Hope it will help.

Sent from Cisco Technical Support iPhone App

Best regards,
Abzal
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card