Cisco 4700M Configuration Manual page 88

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Configuring the AAA Server
The user profile attribute serves an important configuration function for a
Note
RADIUS server group. If the user profile attribute is not obtained from the server
during authentication, or if the profile is obtained from the server but the context
name(s) in the profile do not match the context in which the user is trying to log
in, a default role (Network-Monitor) and a default domain (default-domain) are
assigned to the user if the authentication is successful.
To configure the RADIUS role and domain settings on Cisco Secure ACS,
perform the following steps:
Go to the User Setup section of the Cisco Secure ACS HTML interface and
Step 1
double-click the name of an existing user that you want to define a user profile
attribute for virtualization. The User Setup page appears.
Under the Cisco IOS/PIX RADIUS Attributes section of the page, configure the
Step 2
following settings:
Click Submit when you finish configuring the RADIUS role and domain settings.
Step 3
For example, if USER1 is assigned the role ADMIN and the domain
MYDOMAIN1 (where shell:Admin=ADMIN MYDOMAIN1), then one of the
following can occur:
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
2-18
Check the [009\001] cisco-av-pair check box.
In the text box below the [009\001] cisco-av-pair check box, enter the user
role and associated domain for a specific context in the following format:
shell:<contextname>=<role> <domain1> <domain2>...<domainN>
For example, to assign the selected user to the C1 context with the role
ROLE1 and the domain DOMAIN1, enter shell:C1=ROLE1 DOMAIN1.
If USER1 logs in through the Admin context, that user is automatically
assigned the Admin role and the MyDomain1 domain.
If USER1 logs in through a different context, that user is automatically
assigned the default role (Network-Monitor) and the default domain
(default-domain). In this case, the user profile attribute is not obtained from
the RADIUS server during authentication.
Chapter 2
Configuring Authentication and Accounting Services
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents