User Guide for Cisco Secure ACS for Windows Server 3.2

Table Of Contents






Related Documentation

Obtaining Documentation

Ordering Documentation

Documentation Feedback

Obtaining Technical Assistance

Cisco TAC Website

Opening a TAC Case

TAC Case Priority Definitions

Obtaining Additional Publications and Information


This section discusses the objectives, audience, and organization of the CiscoSecureAccessControlServer (CiscoSecureACS) for WindowsServer version3.2 user guide.


This document will help you configure and use CiscoSecureACS and its features and utilities.


This guide is for system administrators who use CiscoSecureACS and who set up and maintain accounts and dial-in network security.


The CiscoSecureACS User Guide is organized into the following chapters:

"Overview" An overview of CiscoSecureACS and its features, network diagrams, and system requirements.

"Deployment Considerations" A guide to deploying CiscoSecureACS that includes requirements, options, trade-offs, and suggested sequences.

"Interface Configuration" Concepts and procedures regarding how to use the Interface Configuration section of CiscoSecureACS to configure the HTML interface.

"Network Configuration" Concepts and procedures for establishing CiscoSecureACS network configuration and building a distributed system.

"Shared Profile Components" Concepts and procedures regarding CiscoSecureACS shared profile components: network access restrictions and device command sets.

"User Group Management" Concepts and procedures for establishing and maintaining CiscoSecureACS user groups.

"User Management" Concepts and procedures for establishing and maintaining CiscoSecureACS user accounts.

"System Configuration: Basic" Concepts and procedures regarding the basic features found in the System Configuration section of CiscoSecureACS.

"System Configuration: Advanced" Concepts and procedures regarding RDBMS Synchronization and CiscoSecure Database Replication, found in the System Configuration section of CiscoSecureACS.

"System Configuration: Authentication and Certificates" Concepts and procedures regarding the Global Authentication and ACS Certificate Setup pages, found in the System Configuration section of CiscoSecureACS.

"Logs and Reports" Concepts and procedures regarding CiscoSecureACS logging and reports.

"Administrators and Administrative Policy" Concepts and procedures for establishing and maintaining CiscoSecureACS administrators.

"User Databases" Concepts and procedures for establishing user databases.

"Unknown User Policy" Concepts and procedures about the Unknown User Policy.

"User Group Mapping and Specification" Concepts and procedures regarding the assignment of groups for users authenticated by an external user database.

This guide also comprises the following appendixes:

"Troubleshooting." How to identify and solve certain problems you might have with CiscoSecureACS.

"TACACS+ Attribute-Value Pairs." A list of supported TACACS+ AV pairs and accounting AV pairs.

"RADIUS Attributes." A list of supported RADIUS AV pairs and accounting AV pairs.

"CSUtil Database Utility." Instructions for using the database import utility, CSUtil, to import an ODBC database, and back up, maintain, or restore the CiscoSecureACS database.

"VPDN Processing." An introduction to Virtual Private Dial-up Networks (VPDN), including stripping and tunneling, with instructions for enabling VPDN on CiscoSecureACS.

"RDBMS Synchronization Import Definitions." A list of import definitions, for use with the RDBMS Synchronization feature.

"Internal Architecture." A description of CiscoSecureACS architectural components.


This guide uses the following typographical conventions:

Table 1 Typographic Conventions 



Introduces new or important terminology and variable input for commands.


Denotes paths, file names, and example screen output. Also denotes Secure Script translations of security policy decision trees.


Identifies special terminology and options that should be selected during procedures.

Tip Means the following information will help you solve a problem. The tip information might not be troubleshooting or even an action, but could be useful information.

Note Means reader take note. Notes contain helpful suggestions or references to materials not covered in the manual.

Caution Means reader be careful. In this situation, you might do something that could result in equipment damage, loss of data, or a breach in your network security.

Warning Means danger. You are in a situation that could cause bodily injury. Before you work on any equipment, you must be aware of the hazards involved with electrical circuitry and be familiar with standard practices for preventing accidents. To see translated versions of the warning, refer to the Regulatory Compliance and Safety document that accompanied the device.

Related Documentation

Note Although every effort has been made to validate the accuracy of the information in the printed and electronic documentation, you should also review CiscoSecureACS documentation on for any updates.

The following documentation is available on and in PDF format on the CD-ROM for the applicable CiscoSecureACS platform:

For CiscoSecureACS for Windows Server, the following documents are available:

Release Notes for CiscoSecureACS for Windows Server

User Guide for CiscoSecureACS for Windows Server

Installation Guide for CiscoSecureACS for Windows Server

For CiscoSecureACS Appliance, the following documents are available:

Release Notes for CiscoSecureACS Appliance

User Guide for CiscoSecureACS Appliance

Installation and Setup Guide for CiscoSecureACS Appliance

Installation and Configuration Guide for CiscoSecureACS Remote Agents

Regulatory Compliance and Safety Information for the CiscoSecureACS Appliance

For all CiscoSecureACS platforms, Installation and User Guide for CiscoSecureACS User-Changeable Passwords is available.

Included in the CiscoSecureACS HTML interface are two sources of information:

Online Help contains information for each associated page in the CiscoSecureACS HTML interface.

Online Documentation is a complete copy of the user guide for the applicable release of CiscoSecureACS.

You can find other product literature, including white papers, data sheets, and product bulletins, at

You should refer to the documentation that came with your AAA clients for more information about those products. You might also want to consult the Cisco Systems publication CiscoSystems' Internetworking Terms and Acronyms.

Obtaining Documentation

Cisco documentation and additional literature are available on Cisco also provides several ways to obtain technical assistance and other technical resources. These sections explain how to obtain technical information from Cisco Systems.

You can access the most current Cisco documentation on the World Wide Web at this URL:

You can access the Cisco website at this URL:

International Cisco websites can be accessed from this URL:

Ordering Documentation

You can find instructions for ordering documentation at this URL:

You can order Cisco documentation in these ways:

Registered users (Cisco direct customers) can order Cisco product documentation from the Ordering tool:

Nonregistered users can order documentation through a local account representative by calling Cisco Systems Corporate Headquarters (California, USA) at 408526-7208 or, elsewhere in North America, by calling 800553-NETS (6387).

Documentation Feedback

You can submit e-mail comments about technical documentation to

You can submit comments by using the response card (if present) behind the front cover of your document or by writing to the following address:

Cisco Systems
Attn: Customer Document Ordering
170 West Tasman Drive
San Jose, CA 95134-9883

We appreciate your comments.

Obtaining Technical Assistance

For all customers, partners, resellers, and distributors who hold valid Cisco service contracts, the Cisco Technical Assistance Center (TAC) provides 24-hour-a-day, award-winning technical support services, online and over the phone. features the Cisco TAC website as an online starting point for technical assistance. If you do not hold a valid Cisco service contract, please contact your reseller.

Cisco TAC Website

The Cisco TAC website provides online documents and tools for troubleshooting and resolving technical issues with Cisco products and technologies. The Cisco TAC website is available 24 hours a day, 365 days a year. The Cisco TAC website is located at this URL:

Accessing all the tools on the Cisco TAC website requires a user ID and password. If you have a valid service contract but do not have a login ID or password, register at this URL:

Opening a TAC Case

Using the online TAC Case Open Tool is the fastest way to open P3 and P4 cases. (P3 and P4 cases are those in which your network is minimally impaired or for which you require product information.) After you describe your situation, the TAC Case Open Tool automatically recommends resources for an immediate solution. If your issue is not resolved using the recommended resources, your case will be assigned to a Cisco TAC engineer. The online TAC Case Open Tool is located at this URL:

For P1 or P2 cases (P1 and P2 cases are those in which your production network is down or severely degraded) or if you do not have Internet access, contact Cisco TAC by telephone. Cisco TAC engineers are assigned immediately to P1 and P2 cases to help keep your business operations running smoothly.

To open a case by telephone, use one of the following numbers:

Asia-Pacific: +61 2 8446 7411 (Australia: 1 800 805 227)
EMEA: +32 2 704 55 55
USA: 1 800 553-2447

For a complete listing of Cisco TAC contacts, go to this URL:

TAC Case Priority Definitions

To ensure that all cases are reported in a standard format, Cisco has established case priority definitions.

Priority 1 (P1)—Your network is "down" or there is a critical impact to your business operations. You and Cisco will commit all necessary resources around the clock to resolve the situation.

Priority 2 (P2)—Operation of an existing network is severely degraded, or significant aspects of your business operation are negatively affected by inadequate performance of Cisco products. You and Cisco will commit full-time resources during normal business hours to resolve the situation.

Priority 3 (P3)—Operational performance of your network is impaired, but most business operations remain functional. You and Cisco will commit resources during normal business hours to restore service to satisfactory levels.

Priority 4 (P4)—You require information or assistance with Cisco product capabilities, installation, or configuration. There is little or no effect on your business operations.

Obtaining Additional Publications and Information

Information about Cisco products, technologies, and network solutions is available from various online and printed sources.

Cisco Marketplace provides a variety of Cisco books, reference guides, and logo merchandise. Go to this URL to visit the company store:

The Cisco Product Catalog describes the networking products offered by CiscoSystems, as well as ordering and customer support services. Access the Cisco Product Catalog at this URL:

Cisco Press publishes a wide range of general networking, training and certification titles. Both new and experienced users will benefit from these publications. For current Cisco Press titles and other information, go to Cisco Press online at this URL:

Packet magazine is the Cisco quarterly publication that provides the latest networking trends, technology breakthroughs, and Cisco products and solutions to help industry professionals get the most from their networking investment. Included are networking deployment and troubleshooting tips, configuration examples, customer case studies, tutorials and training, certification information, and links to numerous in-depth online resources. You can access Packet magazine at this URL:

iQ Magazine is the Cisco bimonthly publication that delivers the latest information about Internet business strategies for executives. You can access iQ Magazine at this URL:

Internet Protocol Journal is a quarterly journal published by Cisco Systems for engineering professionals involved in designing, developing, and operating public and private internets and intranets. You can access the Internet Protocol Journal at this URL:

Training—Cisco offers world-class networking training. Current offerings in network training are listed at this URL: