11-3
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 11 Working with User Databases
CiscoSecure User Database
User Import and Creation
There are five ways to create user accounts in the CiscoSecure user database in
Cisco Secure ACS for Windows 2000 Servers. Of these, RDBMS
Synchronization and CSUtil.exe support importing user accounts from external
sources.
•
Cisco Secure ACS HTML interface—The HTML interface provides the
ability to create user accounts manually, one user at a time. Regardless of how
a user account was created, you can edit a user account by using the HTML
interface. For detailed steps, see
Adding a Basic User Account, page 7-5
.
•
Unknown User Policy—The Unknown User Policy enables
Cisco Secure ACS to add users automatically when a user without an account
in the CiscoSecure user database is found in an external user database. The
creation of a user account in the CiscoSecure user database occurs only when
the user attempts to access the network and is successfully authenticated by
an external user database. For more information, see
Chapter 12,
“Administering External User Databases.”
If you use Unknown User Policy, you can also configure group mappings so
that each time a user added to the CiscoSecure user database by Unknown
User Policy is authenticated, the user group assignment is made dynamically.
For some external user database types, user group assignment is based on
group membership in the external user database. For other database types, all
users authenticated by a given database are assigned to a single
Cisco Secure ACS user group. For more information about group mapping,
see
Database Group Mappings, page 12-11
.
•
RDBMS Synchronization—RDBMS Synchronization enables you to create
large numbers of user accounts and to configure many settings for user
accounts. We recommend using this feature whenever you need to import
users by bulk; however, setting up RDBMS Synchronization for the first time
requires several important decisions and time to implement them. For more
information, see
RDBMS Synchronization, page 8-29
.
•
CSUtil.exe—The CSUtil.exe command-line utility provides a simple means
of creating basic user accounts. When compared to RDBMS Synchronization,
its functionality is limited; however, it is simple to prepare for importing
basic user accounts and assigning users to groups. For more information, see
Appendix D, “Cisco Secure ACS Command-Line Database Utility.”