8-67
User Guide for Cisco Secure Access Control System 5.4
OL-26225-01
Chapter8 Managing Users and I dentity Stores
Managing External Identity Stores
Check the check box next to the identity store you want to duplicate, then click Duplicate.
Click the identity store name that you want to modify, or check the box next to the name and click
Edit.
Step3 Complete the fields in the General tab. See Configuring General Settings, page8-67 for a description of
the fields in the General tab.
Step4 You can:
Click Submit to save the RADIUS Identity Server.
Click the Shell Prompts tab. See Configuring Shell Prompts, page 8-69 for a description of the fields
in the Shell Prompts tab.
Click the Directory Attributes tab. See Configuring Directory Attributes, page8-69 for a descripti on
of the fields in the Directory Attributes tab.
Click the Advanced tab. See Configuring Advanced Options, page 8-70 for a description of the
fields in the Advanced tab.
Step5 Click Submit to save the changes.
Related Topics
RADIUS Identity Stores, page8-63
Creating, Duplicating, and Editing RADIUS Identity Servers, page8-66
Configuring General Settings
Table 8 -19 describes the fields in the General tab of the RADIUS Identity Servers page.
Table8-19 RADIUS Identity Server - General Tab
Option Description
Name Name of the external RADIUS identity server.
Description (Optional) A brief description of the RADIUS identity server.
SafeWord Server Check this check box to enable a two-factor authentication using a
SafeWord server.
Server Connection
Enable Secondary Server Check this check box to use a secondary RADIUS identity server as a
backup server in case the primary RADIUS identity server fails.
If you enable the secondary server, you must configure the parameters for
the secondary RADIUS identity server and must choose one of the
following options:
Always Access Primary Server First—Select this option to ensure that
ACS always accesses the primary RADIUS identity server first before
the secondary server is accessed.
Failback To Primary Server After n Minutes—Select this option to set
the number of minutes ACS can use the secondary server for
authentication.
After this time expires, ACS should again attempt to authenticate
using the primary server. The default value is 5 minutes.