SBR Radius Config

SBR Radius Config

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
SBR Radius Config JohnD 07-16-2007
Posted by JohnD on July 16, 2007, 3:18 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks to Dave and Doug for replying to my earlier post. I now have my
2600s authenticating to a Radius server.

However, I have run into another issue I hope someone can help me with.

On my Juniper SBR radius server, I have set up two active directory groups
for domain authentication against the radius server. I have a Cisco VPN
Client group, and a Cisco Router Admin group.

Practically everyone in the company is in the Cisco VPN Client group.
Conversely, only 5 of us are in the Cisco Router Admins group.

When I remove Joe from the Cisco Router Admins group, he is still able to
log on to our Cisco routers. I have confirmed that this is because he is
still a member of the Cisco VPN Client group.

More alarming, it appear that everyone in the Cisco VPN Client group is
authorized to login to our routers.

Is there a way to configure the radius server so that it knows which
resources a group should have access to? I suppose my main concern is that
anyone who is a member of any group on the radius server will have access to
any of our devices that are authenticating against that server, regardless
of type of device, job function, etc.



Posted by on July 25, 2007, 5:29 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Thanks to Dave and Doug for replying to my earlier post. I now have my
> 2600s authenticating to a Radius server.
>
> However, I have run into another issue I hope someone can help me with.
>
> On my Juniper SBR radius server, I have set up two active directory groups
> for domain authentication against the radius server. I have a Cisco VPN
> Client group, and a Cisco Router Admin group.
>
> Practically everyone in the company is in the Cisco VPN Client group.
> Conversely, only 5 of us are in the Cisco Router Admins group.
>
> When I remove Joe from the Cisco Router Admins group, he is still able to
> log on to our Cisco routers. I have confirmed that this is because he is
> still a member of the Cisco VPN Client group.
>
> More alarming, it appear that everyone in the Cisco VPN Client group is
> authorized to login to our routers.
>
> Is there a way to configure the radius server so that it knows which
> resources a group should have access to? I suppose my main concern is that
> anyone who is a member of any group on the radius server will have access to
> any of our devices that are authenticating against that server, regardless
> of type of device, job function, etc.

John

you have 3 choices:
1. use diff. radius servers/instances for vpn users and for admins
2. use single radius with configured Filter-Id, configure ACLs on the
2600
3. continue to use radius for vpn users and use tacacs for admins

regards
Roman Nakhmanson


Similar ThreadsPosted
Help w/pix 501 config & vpn client setup w/radius September 9, 2006, 2:09 am
Cisco 802 config and MS IAS / Radius Server November 8, 2006, 9:07 am
initial config of 3560, set config, cant ping~~nv_done: unable to open "flash:/C:\new\config.new February 5, 2008, 11:39 pm
"copy running-config startup-config" simultaneously March 8, 2005, 6:00 am
copy startup-config running-config ??? Why is this command not used. April 1, 2007, 12:01 am
2924 Switch: VLAN config not in config.text May 22, 2007, 5:23 am
can not save running-config to startup-config. November 10, 2005, 5:56 pm
Help - 2610/Radius/PIX/NAT November 11, 2004, 2:12 pm
Radius Problems December 11, 2004, 6:50 pm
RADIUS authentication February 28, 2005, 1:29 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map