Configure Cisco Switch or Router to Use ACS for AAA Services

Hi All

I'm back again. I was figuring out how to use the ACS for managing access to switches and routers within GNS3 but I suppose a similar experience would occur in the physical real world!

Before attempting any of this, ensure you are able to ping your ACS's and Routers/Switches.


These are the settings which are required on the Router / Switch. 



Basic Default Line VTY Settings



Login to ACS

Add Device Locations & Types




Add Device



Create User Groups

 
 Add Users

Create Shell Profiles (linked to Access Policies) - Priviledges for Users




Command Sets


Service Selection Rules - should be there by default


 Default Device Admin
 Default Device Admin - Authorization


Test Router / Switch using Priviledge Level 0 


Notice the command failure? It was not authorized in the Command Set.


Test Router / Switch using Priviledge Level 15
Notice, this user has gone straight into Priviledge mode 15 without requiring Enable Password.



Hope this helps someone out there. It might not be perfect but it gives you a starting point and helps me remember.










Comments

Popular posts from this blog

Create bootable CUC CUCM CUP Image / ISO

Configuring Oracle 12c backups on Veritas Backup Exec 16.

CUCM 11.5 - Esxi 6.5 - unable to create VM