Cisco AS5800 Specifications Page 158

  • Download
  • Add to my manuals
  • Print
  • Page
    / 334
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 157
4-20
Cisco AS5800 Operations, Administration, Maintenance, and Provisioning Guide
DOC-7810814=
Chapter 4 Administration
Access Service Security
The standard NAS-Port attribute (RADIUS IETF Attribute 5) will continue to be sent. If you do not want
this information to be sent, you can suppress it by using the no radius-server attribute nas-port
command. When this command is configured, the standard NAS-Port attribute will no longer be sent.
Specify RADIUS Authentication
After you have identified the RADIUS server and defined the RADIUS authentication key, you need to
define method lists for RADIUS authentication. Because RADIUS authentication is facilitated through
AAA, you need to enter the aaa authentication command, and specify RADIUS as the authentication
method. For more information, refer to information on configuring authentication in the security
configuration guide for your Cisco IOS release.
Specify RADIUS Authorization
AAA authorization lets you set parameters that restrict users network access. Authorization using
RADIUS provides one method for remote access control, including one-time authorization or
authorization for each service, per-user account list and profile, user group support, and support of IP,
IPX, ARA, and Telnet. Because RADIUS authorization is facilitated through AAA, you need to issue
the aaa authorization command, specifying RADIUS as the authorization method.
Specify RADIUS Accounting
The AAA accounting feature enables you to track the services users access and the amount of network
resources they consume. Because RADIUS accounting is facilitated through AAA, you need to issue the
aaa accounting command, specifying RADIUS as the accounting method.
RADIUS Attributes
The network Cisco AS5800 monitors the RADIUS authorization and accounting functions defined by
RADIUS attributes in each user-profile.
Vendor-Proprietary RADIUS Attributes
An Internet Engineering Task Force (IETF) draft standard for RADIUS specifies a method for
communicating vendor-proprietary information between the network Cisco AS5800 and the RADIUS
server. Some vendors, nevertheless, have extended the RADIUS attribute set in a unique way. Cisco IOS
software supports a subset of vendor-proprietary RADIUS attributes.
RADIUS Configuration Examples
RADIUS configuration examples in this section include the following:
RADIUS Authentication and Authorization Example, page 4-21
RADIUS Authentication, Authorization, and Accounting Example, page 4-21
Vendor-Proprietary RADIUS Configuration Example, page 4-22
Page view 157
1 2 ... 153 154 155 156 157 158 159 160 161 162 163 ... 333 334

Comments to this Manuals

No comments