Chapter 4 Setting Up and Managing Network Configuration
Proxy in Distributed Systems
4-4
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Note
If the fields mentioned in this section do not appear in the Cisco Secure ACS
HTML interface, enable them by clicking Interface Configuration, clicking
Advanced Options, and then selecting the Distributed System Settings check box.
Default Distributed System Settings
You use both the AAA Servers table and the Proxy Distribution Table to establish
distributed system settings. The parameters configured within these tables create
the foundation to enable multiple Cisco Secure ACS servers to be configured to
work with one another. Each table contains a Cisco Secure ACS entry for itself.
In the AAA Servers table, the only AAA server initially listed is itself; the Proxy
Distribution Table lists an initial entry of
(Default)
, which displays how the local
Cisco Secure ACS is configured to handle each authentication request locally.
You can configure additional AAA servers in the AAA Servers table. This enables
these devices to become available in the HTML interface so that they can be
configured for other distributed features such as proxy, CiscoSecure user database
replication, remote logging, and RDBMS synchronization. For information about
configuring additional AAA servers, see
Adding a AAA Server, page 4-23
.
Proxy in Distributed Systems
Proxy is a powerful feature that enables you to use Cisco Secure ACS for
authentication in a network that uses more than one AAA server. Using proxy,
Cisco Secure ACS automatically forwards an authentication request from a AAA
client to another AAA server. After the request has been successfully
authenticated, the authorization privileges that have been configured for the user
on the remote AAA server are passed back to the original Cisco Secure ACS,
where the AAA client applies the user profile information for that session.
Proxy provides a useful service to users, such as business travelers, who dial in to
a network device other than the one they normally use and would otherwise be
authenticated by a “foreign” AAA server. To use proxy, you must first click
Interface Configuration, click Advanced Options, and then select the
Distributed System Settings check box.