Discussion:
MS IAS and Cisco IOS
(too old to reply)
lozza
2008-11-21 00:43:01 UTC
Permalink
Hi Guys,

Looking for some help here so appreciate any time you can give.

I have successfully setup a couple of cisco devices to authenticate using MS
IAS and Active Directory. I have even got it to the point where IOS Privilege
Levels are associated with the Windows group the User belongs and drops that
user in at that level when logging into the Cisco Device.

What I wanted to know is how to leverage the other 2 A's in a AAA
implementation using IAS. I am looking for how you guys do it and how it is
setup. Any help on the cisco side would also be much appreciated. For
instance

- what kind of authorisation can I leverage?
- what kind of accounting can get out of this solution?
- where are the accounting logs?
- and if I can authorise can I authorise certain IOS commands for certain
windows groups when logging into cisco devices?

Thanks for your time
Loz
FenderAxe
2008-12-06 19:23:59 UTC
Permalink
Post by lozza
Hi Guys,
Looking for some help here so appreciate any time you can give.
I have successfully setup a couple of cisco devices to authenticate
using MS IAS and Active Directory. I have even got it to the point
where IOS Privilege Levels are associated with the Windows group the
User belongs and drops that user in at that level when logging into
the Cisco Device.
What I wanted to know is how to leverage the other 2 A's in a AAA
implementation using IAS. I am looking for how you guys do it and how
it is setup. Any help on the cisco side would also be much
appreciated. For instance
- what kind of authorisation can I leverage?
- what kind of accounting can get out of this solution?
- where are the accounting logs?
- and if I can authorise can I authorise certain IOS commands for
certain windows groups when logging into cisco devices?
Thanks for your time
Loz
IAS has authorization by user or by group. Authz by user is not a good idea
unless you have a small network, but if you want to do it, you basically
use the AD user account dial-in properties to grant or deny access. Authz
by group is easier -- you set AD dial-in properties to "Control access
through remote access policy," and then you create remote access policies
based on AD groups of users or computers.

Accounting in WS03 and WS08 is either text file or SQL Server. The location
of the accounting logs is in the IAS Help. In fact, the Help contains all
the information you need about authorization and accounting.

I don't know anything about IOS commands, so I can't help you there. :-)

FA

Loading...