Proxy In An Enterprise; Remote Use Of Accounting Packets - Cisco 2509 - Router - EN User Manual

User guide
Hide thumbs Also See for 2509 - Router - EN:
Table of Contents

Advertisement

Chapter 4
Setting Up and Managing Network Configuration

Proxy in an Enterprise

Remote Use of Accounting Packets

78-14696-01, Version 3.1
"@corporate.com", leaving a username of just "mary" which may be the
username format that the destination AAA server requires to identify the correct
entry in its database.
This section presents a scenario of proxy used in an enterprise system. Mary is an
employee with an office in the corporate headquarters in Los Angeles. Her
username is mary@la.corporate.com. When Mary needs access to the network,
she accesses the network locally and authenticates her username and password.
Because Mary works in the Los Angeles office, her user profile, which defines her
authentication and authorization privileges, resides on the local Los Angeles
AAA server. However, Mary occasionally travels to a division within the
corporation in New York, where she still needs to access the corporate network to
get her e-mail and other files. When Mary is in New York, she dials in to the New
York office and logs in as mary@la.corporate.com. Her username is not
recognized by the New York Cisco Secure ACS, but the Proxy Distribution Table
contains an entry, "@la.corporate.com", to forward the authentication request to
the Los Angeles Cisco Secure ACS. Because the username and password
information for Mary reside on that AAA server, when she authenticates correctly,
the authorization parameters assigned to her are applied by the AAA client in the
New York office.
When proxy is employed, Cisco Secure ACS can dispatch AAA accounting
packets in one of three ways:
Log them locally
Forward them to the destination AAA server
Log them locally and forward copies to the destination AAA server
Sending accounting packets to the remote Cisco Secure ACS offers several
benefits. When Cisco Secure ACS is configured to send accounting packets to the
remote AAA server, the remote AAA server logs an entry in the accounting report
for that session on the destination server. Cisco Secure ACS also caches the user
connection information and adds an entry in the List Logged on Users report. You
can then view the information for users that are currently connected. Because the
User Guide for Cisco Secure ACS for Windows Server
Proxy in Distributed Systems
4-7

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Secure acs

Table of Contents