7-20
User Guide for Cisco Secure Access Control System 5.4
OL-26225-01
Chapter7 Managing Network Reso urces
Working with External Proxy Servers
Step2 Do one of the following:
Click Create.
Check the check box next to the external proxy server that you want to duplicate, then click
Duplicate.
Click the external proxy server name that you want to edit, or check the check box next to the name
and click Edit.
The External Proxy Servers page appears.
Step3 Edit fields in the External Proxy Servers page as shown in Tabl e 7-7.
Step4 Click Submit to save the changes.
The external Proxy Server configuration is saved. The External Proxy Server page appears with the new
configuration.
Table7-7 External Policy Servers Page
Option Description
General
Name Name of the external RADIUS or TACACS+ server.
Description (Optional) The description of the external RADIUS or TACACS+ server.
Server Connection
Server IP Address IP address of the external RADIUS or TACACS+ server. It can be either an IPv4 or IPv6 address. ACS
5.4 validates the IP address, if the address is entered in the supported format. It displays an error
message if the entered format is not correct.
Shared Secret Shared secret between ACS and the exte rnal RADIUS or TACACS+ server that is used for
authenticating the external RADIUS or TACACS+ server.
A shared secret is an expected string of text that a user mu st provide to enable the network device to
authenticate a username and password. The connection is rejected until the user supplies the shared
secret.
Show/Hide button is available to view the Shared secret in plain text or hidden fo rmat.
Advanced Options
RADIUS Choose to create a RADIUS proxy server. RADIUS supports only IPv4 addresses.
TACACS+ Choose to create a TACACS+ proxy server. TACACS+ supports IPv4 and IPv6 addresses.
Cisco Secure ACS Default choice. Supports both RADIUS and TACACS+. You can choose Cisco Secure ACS if you use
an IPv4 address.
Authentication Port RADIUS authentication port number. The default is 1812.
Accounting Port RADIUS accounting port number. The default is 1813.
Server Timeout Number of seconds ACS waits for a response from the external RADIUS server. The default is 5
seconds. Valid values are from 1 to 999.
Connection
Attempts
Number of times ACS attempts to connect to the external RADIUS server. The default is 3 attempts.
Valid values are from 1 to 99.
Connection Port TACACS+ connection port. The default is 49.
Network Timeout Number of seconds ACS waits for a response fr om the external TACACS+ server. The default is 20
seconds.