Contents

Authentication Using LDAP

8-20

 

 

Multiple LDAP Instances

8-20

 

 

Failover 8-21

 

 

 

 

LDAP Connection Management 8-21

 

 

Authenticating a User Using a Bind Connection

8-21

Group Membership Information Retrieval

8-22

 

Attributes Retrieval

8-23

 

 

 

Certificate Retrieval

8-23

 

 

 

Creating External LDAP Identity Stores

8-23

 

Configuring an External LDAP Server Connection

8-24

Configuring External LDAP Directory Organization

8-26

Deleting External LDAP Identity Stores

8-30

 

Configuring LDAP Groups

8-30

 

 

Viewing LDAP Attributes

8-31

 

 

Leveraging Cisco NAC Profiler as an External MAB Database 8-31

Enabling the LDAP Interface on Cisco NAC Profiler to Communicate with ACS 8-32

Configuring NAC Profile LDAP Definition in ACS for Use in Identity Policy 8-34

Troubleshooting MAB Authentication with Profiler Integration 8-38

 

 

 

 

 

Microsoft AD

8-38

 

 

 

 

 

 

 

 

 

 

 

 

Machine Authentication

8-40

 

 

 

 

 

 

 

 

 

 

Attribute Retrieval for Authorization 8-41

 

 

 

 

 

 

 

Group Retrieval for Authorization

8-41

 

 

 

 

 

 

 

 

Certificate Retrieval for EAP-TLS Authentication

8-41

 

 

 

 

 

 

Concurrent Connection Management

8-41

 

 

 

 

 

 

 

User and Machine Account Restrictions

8-41

 

 

 

 

 

 

 

Machine Access Restrictions

8-42

 

 

 

 

 

 

 

 

Dial-in Permissions

8-43

 

 

 

 

 

 

 

 

 

 

Callback Options for Dial-in users

8-43

 

 

 

 

 

 

 

Joining ACS to an AD Domain

8-45

 

 

 

 

 

 

 

 

Configuring an AD Identity Store

8-45

 

 

 

 

 

 

 

 

Selecting an AD Group

8-47

 

 

 

 

 

 

 

 

 

 

Configuring AD Attributes

8-48

 

 

 

 

 

 

 

 

 

RSA SecurID Server 8-51

 

 

 

 

 

 

 

 

 

 

 

Configuring RSA SecurID Agents

8-51

 

 

 

 

 

 

 

 

Creating and Editing RSA SecurID Token Servers

8-52

 

 

 

 

 

 

RADIUS Identity Stores

8-57

 

 

 

 

 

 

 

 

 

 

 

Supported Authentication Protocols

8-57

 

 

 

 

 

 

 

Failover

8-58

 

 

 

 

 

 

 

 

 

 

 

 

Password Prompt

8-58

 

 

 

 

 

 

 

 

 

 

 

User Group Mapping 8-58

 

 

 

 

 

 

 

 

 

 

User Guide for Cisco Secure Access Control System 5.3

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

viii

 

 

 

 

 

 

 

 

 

 

OL-24201-01

 

 

 

 

 

 

 

 

 

 

 

 

 

Page 8
Image 8
Cisco Systems OL-24201-01 manual Failover, Viii