Cisco 2509 - Router - EN User Manual page 403

User guide
Hide thumbs Also See for 2509 - Router - EN:
Table of Contents

Advertisement

Chapter 10
Setting Up and Managing Administrators and Policy
78-14696-01, Version 3.1
Cisco Secure ACS uses port 2002 to start all administrative sessions. You
do not need to include port 2002 in the port range. Also,
Cisco Secure ACS does not allow you to define an HTTP port range that
consists only of port 2002. Your port range must consist of at least one
port other than port 2002.
A firewall configured to permit HTTP traffic over the Cisco Secure ACS
administrative port range must also permit HTTP traffic through port
2002, because this is the port a web browser must access to initiate an
administrative session.
We do not recommend allowing administration of Cisco Secure ACS
Note
from outside a firewall. If you do choose to allow access to the HTML
interface from outside a firewall, keep the HTTP port range as narrow
as possible. This can help prevent accidental discovery of an active
administrative port by unauthorized users. An unauthorized user
would have to impersonate, or "spoof," the IP address of a legitimate
host to make use of the active administrative session HTTP port.
Secure Socket Layer Setup—The Use HTTPS Transport for
Administration Access check box defines whether Cisco Secure ACS
uses secure socket layer protocol to encrypt HTTP traffic between the
CSAdmin service and a web browser used to access the HTML interface.
When this option is enabled, HTTP traffic sending the Cisco Secure ACS
logon page is not encrypted. After the administrator logs in, all
subsequent communication is encrypted with SSL, as reflected by the
URLs, which begin with HTTPS. Additionally, most browsers include an
indicator for when a connection is SSL-encrypted.
Note
Administrator credentials are always encrypted at login.
Cisco Secure ACS never sends administrator login credentials in
clear text.
To enable SSL, you must have completed the steps in
Cisco Secure ACS Server Certificate, page
Certificate Authority Certificate, page
User Guide for Cisco Secure ACS for Windows Server
Access Policy
Installing a
8-74, and
Adding a
8-76.
10-13

Advertisement

Table of Contents
loading

This manual is also suitable for:

Secure acs

Table of Contents