Aaa Configuration - Cisco CRS-1 - Carrier Routing System Router Configuration Manual

Ios xr system security configuration guide
Hide thumbs Also See for CRS-1 - Carrier Routing System Router:
Table of Contents

Advertisement

Information About Configuring AAA Services
Remote Database
AAA data can be stored in an external security server, such as CiscoSecure ACS. Security data stored in
the server can be used by any client (such as a network access server [NAS]) provided that the client
knows the server IP address and shared secret.
Remote AAA Configuration
Products such as CiscoSecure ACS can be used to administer the shared or external AAA database. The
router communicates with the remote AAA server using a standard IP-based security protocol (such as
TACACS+ or RADIUS).
Client Configuration
The security server should be configured with the secret key shared with the router and the IP addresses
of the clients.
User Groups
User groups that are created in an external server are not related to the user group concept that is used
in the context of local AAA database configuration on the router. The management of external
TACACS+ server or RADIUS server user groups is independent, and the router does not recognize the
user group structure. The remote user or group profiles may contain attributes that specify the groups
(defined on the router) to which a user or users belong, as well as individual task IDs. For more
information, see the
Configuration of user groups in external servers comes under the design of individual server products.
See the appropriate server product documentation.
Task Groups
Task groups are defined by lists of permitted task IDs for each type of action (such as read, write, and
so on). The task IDs are basically defined in the router system. Task ID definitions may have to be
supported before task groups in external software can be configured.
Task IDs can also be configured in external TACACS+ or RADIUS servers.

AAA Configuration

This section provides information about AAA configuration.
Method Lists
AAA data may be stored in a variety of data sources. AAA configuration uses method lists to define an
order of preference for the source of AAA data. AAA may define more than one method list and
applications (such as login) can choose one of them. For example, console and auxiliary ports may use
one method list and the vty ports may use another. If a method list is not specified, the application tries
to use a default method list. If a default method list does not exist, AAA uses the local database as the
source.
Cisco IOS XR System Security Configuration Guide for the Cisco CRS-1 Router
SC-8
Task IDs for TACACS+ and RADIUS Authenticated Users
Configuring AAA Services on Cisco IOS XR Software
section.
OL-20382-01

Advertisement

Table of Contents
loading

Table of Contents