Chapter 18 Managing System Administration Configurations

Configuring RSA SecurID Prompts

Generating EAP-FAST PAC

 

 

Use the EAP-FAST Generate PAC page to generate a user or machine PAC.

 

 

 

 

 

Step 1

Select System Administration > Configuration > Global System Options > EAP-FAST > Generate

 

 

PAC.

 

 

The Generate PAC page appears as described in Table 18-5:

Table 18-5

Generate PAC

 

 

 

 

Option

 

 

Description

 

 

 

 

Tunnel PAC

 

 

Select to generate a tunnel PAC.

 

 

 

Machine PAC

 

Select to generate a machine PAC.

 

 

 

 

Identity

 

 

Specifies the username or machine name presented as the “inner username” by the EAP-FAST

 

 

 

protocol. If the Identity string does not match that username, authentication will fail.

 

 

 

PAC Time To Live

 

Enter the equivalent maximum value in days, weeks, months and years, and enter a positive

 

 

 

integer.

 

 

 

 

Password

 

 

Enter the password.

 

 

 

 

 

Step 2

Click Generate PAC.

 

 

 

 

Configuring RSA SecurID Prompts

You can configure RSA prompts for an ACS deployment. The set of RSA prompts that you configure is used for all RSA realms and ACS instances in a deployment. To configure RSA SecurID Prompts:

Step 1 Choose System Administration > Configuration > Global System Options > RSA SecurID Prompts. The RSA SecurID Prompts page appears.

Step 2 Modify the fields described in Table 18-6.

Table 18-6

RSA SecurID Prompts Page

 

 

 

 

Option

 

Description

 

 

Next Token Prompt

Text string to request for the next token. The default value is “Enter Next

 

 

TOKENCODE:”.

 

 

Choose PIN Type Prompt

Text string to request the PIN type. The default value is “Do you want to

 

 

enter your own pin?”.

 

 

 

 

User Guide for Cisco Secure Access Control System 5.3

18-4

OL-24201-01

Page 518
Image 518
Cisco Systems OL-24201-01 Configuring RSA SecurID Prompts, Generating EAP-FAST PAC, Click Generate PAC, Tokencode, 18-4