4-7
User Guide for Cisco Secure Access Control System 5.4
OL-26225-01
Chapter4 Common Scenarios Using ACS
Password-Based Network Access
Password-Based Network Access Configuration Flow
This topic describes the end-to-end flow for password-based network ac cess and lists the tasks that you
must perform. The information about how to configure the tasks is located in the relevant task chapters.
To configure password-based network access:
Step1 Configure network devices and AAA clients.
a. In the Network Devices and AAA Clients, page7-5, configure the Authentication Setting as
RADIUS.
b. Enter the Shared Secret.
See Network Devices and AAA Clients, page7-5, for more information.
Step2 Configure the users and identity stores. For more information, see Chapter 8, “Managing Users and
Identity Stores.”
Step3 Define policy conditions and authorization profiles. For more information, se e Chapter 9, “Managing
Policy Elements.”
Step4 Define an access service. For more information, see Creating, Duplicating, and Editing Access Services,
page 10-12.
a. Set the Access Service Type to Network Access.
b. Select one of the ACS-supported protocols in the Allowed Protocols Page and follow the steps in
the Action column in Table 4 -1.
Step5 Add the access service to your service selection policy. For more information, see Creating, Duplicating,
and Editing Service Selection Rules, page10-8.
Step6 Return to the service that you created and in the Authorization Policy Page, define authorization rules.
For more information, see Configuring Access Service Policies, page 10-22.
Table4-1 Network Access Authentication Protocols
Protocol Action
Process Host Lookup
(MAB)
In the Allowed Protocols Page, choose Process Host Lookup.
RADIUS PAP In the Allowed Protocols Page, choose Allow PAP/ASCII.
RADIUS CHAP In the Allowed Protocols Page, choose Allow CHAP.
RADIUS MSCHAPv1 In the Allowed Protocols Page, choose Allow MS-CHAPv1.
RADIUS MSCHAPv2 In the Allowed Protocols Page, choose Allow MS-CHAPv2.
EAP-MD5 In the Allowed Protocols Page, choose Allow EAP-MD5.
LEAP In the Allowed Protocols Page, choose Allow LEAP.