Chapter7 Se tting Up and Managing User Accounts
Advanced User Authentication Settings
7-44
Cisco Secure ACS 3.0 for Windows 2000/NT Servers User Guide
78-13751-01, Version 3.0
Setting Microsoft RADIUS Parameters for a User
Microsoft RADIUS provides VSAs supporting Microsoft Point-to-Point
Encryption (MPPE), which is an encryption technology developed by Microsoft
to encrypt point-to-point (PPP) links. These PPP connections can be via a dial-in
line, or over a Virtual Private Network (VPN) tunnel. The Microsoft RADIUS
attribute configurations display only if both the following are true:
A AAA client has been configured in Network Configuration that uses a
RADIUS protocol that supports the Microsoft RADIUS VSA.
The Per-user TACACS+/RADIUS Attributes check box is selected under
Advanced Options in the Interface Configuration section.
The user-level RADIUS (Microsoft) attributes you intend to employ have
been enabled under RADIUS (Microsoft) in the Interface Configuration
section.
The following Cisco Secure ACS RADIUS protocols support the Microsoft
RADIUS VSA:
Cisco IOS
Cisco VPN 3000
Cisco VPN 5000
Ascend
Microsoft RADIUS represents only the Microsoft VSA. You must configure both
the IETF RADIUS and Microsoft RADIUS attributes.
Note To hide or display Microsoft RADIUS attributes, see the Setting Protocol
Configuration Options for RADIUS (Microsoft) section on page 3-17.
To configure and enable Microsoft RADIUS attributes to be applied as an
authorization for the current user, follow these steps:
Step 1 Perform Steps 1 through 3 of the Adding a Basic User Account section on
page 7-5.
Result: The User Setup Edit page opens. The username being added or edited
appears at the top of the page.