C H A P T E R
14-1
User Guide for Cisco Security MARS Local Controller
78-17020-01
14
Configuring AAA Devices
Revised: February 23, 2007
Authentication, authorization, and accounting (AAA) devices provide accountability throughout your
network, ensuring that valid users are authorized to use the network services they request and providing
detailed event logs regarding failures and successes in such requests.
The AAA server is a key component in the Network Access Control (NAC) initiative (see
Configuring
Network Admission Control Features, page 2-52
and
Enable NAC-specific Messages, page 3-4
). Cisco
Secure Access Control Server (ACS), which is the AAA server for NAC, returns access control decisions
to the network access device on the basis of the antivirus credentials of the hosts that are requesting
network services.
MARS supports the Cisco Secure ACS software and the Cisco Secure ACS Solution Engine, version 3.3
and later. In the case of Cisco Secure ACS software, support is provided by an agent that resides on the
Cisco Secure ACS server. For the Cisco Secure ACS Solution Engine, this agent must reside on a remote
logging host. This agent provides MARS with three event logs in syslog format. The logs are as follows:
•
Passed authentication log (requires Cisco Secure ACS, 3.3 or later)
•
Failed attempts log
•
RADIUS accounting log
To support NAC and the 802.1x features, Cisco Secure ACS uses the RADIUS authentication protocol
and the cisco-av-pair attributes. For more information on configuring Cisco Secure ACS as a posture
validation server for NAC, see the following URLs:
•
“Network Admission Control” chapter in
User Guide for Cisco Secure ACS for Windows Server,
Version 3.3
http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a00
802335f1.html
•
“Posture Validation” chapter in
User Guide for Cisco Secure ACS for Windows, Version 4.0
http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a00
8052e956.html
•
“Using Profile Templates” section in the “Network Access Profiles” chapter in
User Guide for Cisco
Secure ACS for Windows, Version 4.0
http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a00
8052e984.html#wp1075429
For more information on the cisco-av-pair attributes, see the following URL:
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...