Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Overview RADIUS, TACACS+, LDAP

Want to summarize with AI?

Log in

Describes step-by-step instructions for enabling RADIUS, TACACS+, LDAP, RSA, DUO, SAML, and OAuth 2 users to access the APIC.


APIC user access authentication is a security framework that

  • enables multiple authentication protocols including RADIUS, TACACS+, LDAP, RSA, DUO, SAML, and OAuth 2 for APIC access

  • provides centralized user authentication and authorization management through the Application Centric Infrastructure

  • requires thorough familiarity with Cisco Application Centric Infrastructure Fundamentals, especially the User Access, Authentication, and Accounting chapter.

GUI path changes and security considerations

Beginning with Cisco APIC Release 6.0(1), the APIC GUI has changed for the path, Admin > AAA. For detailed information, see Cisco APIC GUI enhancements.

Note

In the case of a disaster scenario such as the loss of all but one APIC in the cluster, APIC disables remote authentication. In this scenario, only a local administrator account can log into the fabric devices.

Note

Remote users for AAA Authentication with shell:domains=all/read-all/ will not be able to access Leaf switches and Spine switches in the fabric for security purposes. This pertains to all version up to 4.0(1h).