Guest

Cisco NAC Appliance (Clean Access)

NAC (CCA): Configure Authentication on the Clean Access Manager (CAM) with ACS

Document ID: 107396



Contents

Introduction
Prerequisites
      Requirements
      Components Used
      Conventions
Configure
      Network Diagram
      Steps to Configure Authentication on CCA with ACS
      ACS Configuration
Verify
Troubleshoot
NetPro Discussion Forums - Featured Conversations
Related Information

Introduction

This document describes how to configure the authentication on the Clean Access Manager (CAM) with Cisco Secure Access Control Server (ACS).

Prerequisites

Requirements

This configuration is applicable to CAM version 3.5 and later.

Components Used

The information in this document is based on CAM version 4.1.

The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, make sure that you understand the potential impact of any command.

Conventions

Refer to the Cisco Technical Tips Conventions for more information on document conventions.

Configure

In this section, you are presented with the information to configure the features described in this document.

Note: Use the Command Lookup Tool ( registered customers only) to obtain more information on the commands used in this section.

Network Diagram

This document uses this network setup:

acs-auth-cam1.gif

Steps to Configure Authentication on CCA with ACS

Complete these steps:

  1. Add New Roles
    1. Create an Admin Role

      • In the CAM, choose User Management > User Roles > New Role.

        acs-auth-cam2.gif

      • Enter a unique name, admin, for the role in the Role Name field.

      • Enter Admin User Role as an optional Role Description.

      • Choose Normal Login Role as the Role Type.

      • Configure the Out-of-Band (OOB) user role VLAN with the appropriate VLAN. For example, choose the VLAN ID and specify the ID as 10.

      • When finished, click Create Role. In order to restore default properties on the form, click Reset.

      • The role now appears in the List of Roles tab as shown in the Tag VLANs for OOB Role-based mappings section.

    2. Create a User Role

      • In the CAM, choose User Management > User Roles > New Role.

        acs-auth-cam3.gif

      • Enter a unique name, users, for the role in the Role Name field.

      • Enter Normal User Role as an optional Role Description.

      • Configure the Out-of-Band (OOB) user role VLAN with the appropriate VLAN. For example, choose the VLAN ID and specify the ID as 20.

      • When finished, click Create Role. In order to restore default properties on the form, click Reset.

      • The role now appears in the List of Roles tab as shown in the Tag VLANs for OOB Role-based mappings section.

  2. Tag VLANs for OOB Role-based mappings

    In the CAM, choose User Management > User Roles > List of Roles in order to see the list of roles so far.

    acs-auth-cam4.gif

  3. Add RADIUS Auth Server (ACS)

    1. Choose User Management > Auth Servers > New.

      acs-auth-cam5.gif

    2. From the Authentication Type drop-down menu, choose Radius.

    3. Enter the Provider Name as ACS.

    4. Enter the Server Name as auth.cisco.com.

    5. Server Port—The port number 1812 on which the RADIUS server is listening.

    6. Radius Type—The RADIUS authentication method. Supported methods include EAPMD5, PAP, CHAP, MSCHAP and MSCHAP2.

    7. Default Role is used if mapping to ACS is not defined or set correctly, or if the RADIUS attribute is not defined or set correctly on the ACS.

    8. Shared Secret—The RADIUS shared secret bound to the specified client's IP address.

    9. NAS-IP-Address—This value to be sent with all RADIUS authentication packets.

    10. Click Add Server.

      acs-auth-cam6.gif

  4. Map ACS Users to CCA User Roles

    1. Choose User Management > Auth Servers > Mapping Rules > Add Mapping Link in order to map admin user in ACS to the CCA admin user role.

      acs-auth-cam7.gif

    2. Choose User Management > Auth Servers > Mapping Rules > Add Mapping Link in order to map normal user in ACS to the CCA user role.

      acs-auth-cam8.gif

    3. Here is the user role mapping summary:

      acs-auth-cam9.gif

  5. Enable Alternate Providers on User Page

    Choose Administration > User Pages > Login Page > Add > Content in order to enable alternate providers on the user login page.

    acs-auth-cam10.gif

ACS Configuration

  1. Choose Interface Configuration in order to make sure that the RADIUS (IETF) Class attribute [025] is enabled.

    acs-auth-cam11.gif

  2. Add RADIUS Client to ACS Server

    1. Choose Network Configuration in order to add the AAA client CAM as shown:

      acs-auth-cam12.gif

      Click Submit + Restart.

      Note: Make sure that the RADIUS key matches with the AAA client and uses RADIUS (IETF).

    2. Choose Network Configuration in order to add the AAA client CAS as shown:

      acs-auth-cam13.gif

      Click Submit + Restart.

      Note: For VPN gateway RADIUS accounting, CCA policy must allow RADIUS accounting packets (UDP 1646/1813) from the CAS IP address to pass unauthenticated to the ACS server IP address.

    3. Choose Network Configuration in order to add the AAA client ASA as shown:

      acs-auth-cam14.gif

      • User near-side PIX/ASA interface address (typically inside interface)

      • Set type to RADIUS (Cisco IOS/PIX).

  3. Add /Configure Groups on ACS Server

    1. Create Admin group

      acs-auth-cam15.gif

      • Set the IETF RADIUS Class attribute [025] to appropriate group value.

      • The value must match that configured on CAS mapping.

    2. Create User group

      acs-auth-cam16.gif

      Add/configure group for each Clean Access User Role to be mapped.

    3. Add/Configure Users on ACS Server

      acs-auth-cam17.gif

      • Add/configure ACS user for each Clean Access user to be authenticated by ACS.

      • Set ACS Group membership.

      • ACS also supports proxy authentication to other external servers.

Verify

Use this section to confirm that your configuration works properly.

In the ACS monitoring section, you can see the information on the passed authentications as shown:

acs-auth-cam18.gif

Similarly, you can see the screenshot for RADIUS accounting:

acs-auth-cam19.gif

Troubleshoot

There is currently no specific troubleshooting information available for this configuration.

NetPro Discussion Forums - Featured Conversations

Networking Professionals Connection is a forum for networking professionals to share questions, suggestions, and information about networking solutions, products, and technologies. The featured links are some of the most recent conversations available in this technology.
NetPro Discussion Forums - Featured Conversations for Security
Security: Intrusion Detection [Systems]
Security: AAA
Security: General
Security: Firewalling

Related Information



Updated: Jun 24, 2008Document ID: 107396