cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
387
Views
15
Helpful
7
Replies

aaa new-model

alsayed
Level 1
Level 1

Howdy Experts!

i have an ACS 3.2 RUNNING ON THE Win2003 Server(10.10.10.1);i need to configure My access Switches to be Aunthenticated by This Acs Beofor the loging to the Switchs.

1)what could be the Proper Configuration on each access switch?

2)in wich we use Tacacs-server 10.10.10.1 .

& in wich case we use Radius-server 10.10.10.1

3)also what could be the configuration on the Acs to accomplish the Setup.

10xs for ur help!

7 Replies 7

mahmoodmkl
Level 7
Level 7

Hi Sayeed

U need to configure the appropriate clients in the ACS.Then u need to configure the swithces or routers to forward any access request to the aaa server i.e u r tacacs server.

Hope the below link will help u .

http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7a7.html

Thanks

Mahmood

Ok;So the Config on all access Switchs it will be as the following:

aaa new-model

aaa authentication group tacacs+ local

tacacs-server host 10.10.10.1

tacacs-server key cisco.

is it a proprer config?

2) in regards to ht Acs Config,what shoud i configure?

10xs

HI

It should be like this

aaa new-model

aaa authentication login default group tacacs+ enable local

aaa authentication enable default group tacacs+ enable

tacacs-server host 10.10.10.1

tacacs-server key {password}

Thanks

Mahmood

Hi Mahmoud 10xs for ur reply!what about the configuration at Acs Side?what about if we use Radius?in which case we use Radius Instead of Tacacs+..

10xs for ur time

Hi

In ACS when u log in u will find a option called network configuration click on it u will get the options to add the clients i.e u r network deivces.if u r using radius then replace the tacacs+ with radius option.

Thanks

Mahmood

Hi Mahmoud;10xs for ur reply!

Mahmoud in wich Branch r u?in Jedah or Khobar?

plz can u mail me to the Following Contact:

aldoctors@hotmail.com

10xs

Hi

Ali u can contact me on mahmood_mkl@yahoo.com

I m in jubail

Thanks

Mahmood

Review Cisco Networking products for a $25 gift card