Can Cisco Device Manager Support ACS Authentication?

Background:
My company has approximately 500+ devices all across the country (mainly 2801's, 2924's, 2950's, and 2960's) and approx 3 people that have a real idea of how to configure the devices, and 2 or 3 that have a general clue about how to do it. I am in the process of moving all of these devices to use ACS authentication for signing into the device. While I am doing this I am establishing a strong password for the secret password to provide as a backup.
Problem:
My supervisor would like the cisco device manager to be available to the people that don't have the in depth cli experience. However in my testing, it will only accept the strong password for its authentication, and does not try the ACS server for authentication. Is this possible?

Hi,
Actually, there is a difference as from where the authentication is picked from for HTTP authentication,
With HTTP v1 server, same method list is picked, that is used by VTY lines.
With HTTP v1.1 server, but before the integration of fix for bug CSCeb82510, the method list defined for console is checked.
After the fix of the above mentioned bug, we have some different sent of commands that we can use.
I would suggest you to give this a try,
aaa authentication login CONSOLEandHTTP tacacs+ local
aaa authorization exec CONSOLEandHTTP if-authenticated
ip http authentication aaa
line con 0
login authentication CONSOLEandHTTP
authorization exec CONSOLEandHTTP
For detail please refer,
http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a008069bdc5.shtml
Regards,
Prem

Similar Messages

  • Cisco Multicast Manager Support for NEXUS

    Hi All,
    Does Cisco Multicast manager support Nexus devices ?
    Please help.

    No at this time it does not according to the data sheets:
    http://www.cisco.com/en/US/partner/prod/collateral/netmgtsw/ps6504/ps6335/ps6337/q_a_c67-527951.html
    You can use cisco data center manager for managing Nexus devices:
    http://www.cisco.com/en/US/products/ps9369/index.html
    Download software:
    http://tools.cisco.com/support/downloads/go/Redirect.x?mdfid=281722751

  • Unable to open 2 9509 switches at the same time in Cisco Device Manager

    Dear Friends,
    There are a pair of MDS 9509 switches whose management addresses are 172.16.2.197 and 172.16.2.198.
    When we try to manage these Devices through Cisco device manager, the first device opens up without any problem, but when the second 9509 is opened in Cisco Device Manager, it fails giving the following error message:
    "Open udp transport failed: Address already in use: Cannot bind"
    To get around this issue, if we close the first interface to the 9509 switch, then we are able to open up the second 9509 in Device Manager.
    We have this problem only in Cisco device manager. If we open one switch in Cisco device manager and the other switch in Cisco Fabric Manager, it works.
    Also, we can telnet to both the devices successfully at a time.
    The device manager in use is 4.1.
    Please find enclosed the sh version outputs for your kind reference.
    Can you please help me understand the cause of this issue?
    Thanks a lot
    Gautam

    Is it always the same MDS that fails to open, or can you open either one first, and then the second one poses the problem (no matter which one is second)?
    Can you try from a second work station and see if you can open DM to both switched at the same time? I suspect the address it is complaining about is the local workstation IP, not the MDS IP.
    If you open the FM map, then you click on the MDS ICONs, can you open DM to both MDS?
    - Mike

  • Cisco devices that support Multicast traffic?

    Folks,
    I am looking for list of Cisco devices that support Multicast traffic. Does anyone know how to get this information?
    Thanks,
    Nagesh 

    Cisco Feature Navigator

  • How can integrate UCS Manager with ACS

    Somebody have guidelines to integrate UCS Manager 2.0 with ACS 5.3 using TACACs
    I have tried creating a TACACs Providers and a TACACs Providers Group, the In the Native Authentication i have changed the real from local to tacacs usin the provider group i've created.
    In the ACS i have added the device and in monitoring viewer i can view the succesful log of authentication but the UCS Manager windows close before the authentication page

    Hi Shelley,
    I was reading the document, but I have some doubts. What we need is to do the integration with Cisco Secure ACS 4.X Solution Engine 1113 Appliance. We need to identify a client for a name and not for IP Address. Can I do this with SM and ACS??.
    Regards.
    Jaime.

  • Cisco Security Manager Local RBAC Authentication Radius assign user role

    Is it possible to use Cisco Security Manager with local RBAC, authenticate the user to Radius and retrieve it's role from Radius. Getting the authentication to work isn't the problem, but is it also possible to return the role the user has (i.e. Super Admin) via Radius, without having to create all the users one-by-one in the local CSM database with the correct role.
    Can i use a certain Cisco-AV-Pair attribute to return the user role via Radius?

    I just got asked to look at the same situation by one of our security people.
    We have exactly the same problem but it reports a username of "*****" and we are running CSM 4.7 (upgraded last week)

  • Is HP Device Manager Supporting Apple Contacts (Address Book) in OS X Yosemite when computer faxing?

    Hi,
    I am trying to select best possible printer for our small office which will let us use os x's power and integritiy to do a lot with less effort. Hp Office Jet Pro X576 and 8630 look very promising to me.
    As a power user, recent mac switcher I was digging hp support forums to make clear if Apple Contacts (Yosemite 10.10, former Address Book) supported in Hp Device Device Manager when Faxing. I have found some shared screenshots but no Apple Contacts icon available near fax options dialogue boxes. 
    Imagine that I have 4000 contacts on my mac those nearly all have fax numbers along with emails. Based on legal and business purposes faxing is essential to us. Finally, I wouldn't like to enter fax number manually every time faxing.
    Thanks

    Hi,
    I am trying to select best possible printer for our small office which will let us use os x's power and integritiy to do a lot with less effort. Hp Office Jet Pro X576 and 8630 look very promising to me.
    As a power user, recent mac switcher I was digging hp support forums to make clear if Apple Contacts (Yosemite 10.10, former Address Book) supported in Hp Device Device Manager when Faxing. I have found some shared screenshots but no Apple Contacts icon available near fax options dialogue boxes. 
    Imagine that I have 4000 contacts on my mac those nearly all have fax numbers along with emails. Based on legal and business purposes faxing is essential to us. Finally, I wouldn't like to enter fax number manually every time faxing.
    Thanks

  • Need help in configuring Cisco AP to support EAP authentication

    Hello all,
    in desperation after trying for more than 3 weeks, I am trying in this way to get a solution to my following problem.
    I am trying to build up as 802.1x scenario using 802.11b infrastructure (RADIUS server, Cisco 1100 Aironet AP, Cisco PCMCIA WLAN card with Xsupplicant software, the complete OS is Linux). I am trying to use EAP-MD5 authentication. It seems that the things are funtioning in standalone mode.
    The client wants to authenticate to access WLAN. It sends EAPoL start packet and gets a request from AP for user identity. Good. Then the user sends his identity with EAP packet. The Cisco AP is forwarding the request to RDAIUS server as specified in many documents. It is also Good. RADIUS server is sending a request for challenge (Password). Upto this point things are gooing fine.
    Now the Cisco AP is not sending this challenge to the
    Xsupplicant, it is just ignoring it. Can any one help me in this point. If needed I can also send the configuration file of the AP.
    I would be very thankful, if I could solve this Problem with your support.
    Thanking you in advance,
    Felix

    As per the RFC for RADIUS, a RADIUS Server receiving an Access-Request with a Message- Authenticator Attribute present MUST calculate the correct value of the Message-Authenticator and silently discard the packet if it does not match the value sent. A RADIUS Client receiving an Access-Accept, Access-Reject or Access-Challenge with a Message-Authenticator Attribute present MUST calculate the correct value of the Message-Authenticator and silently discard the packet if it does not match the value sent.

  • How to install Cisco Device Manger on Window 7

    Hello
    Is Cisco device manager supported on windows 7 ?
    If yes how to install Cisco Device Manger on Window 7?
    Please advise
    Thanks
    Chetan R

    You can install the latest DCNM 5.x  for support, please see here:
    http://www.cisco.com/en/US/docs/switches/datacenter/sw/5_x/dcnm/release/notes/dcnm_5_1_relnotes.html#wp179665
    Support for Windows 7 and Windows 2008
    In Cisco DCNM Release 5.1(3u), the Cisco DCNM server supports Windows 2008 and the Cisco DCNM client support Windows 7.
    You can download the DCNM from the Software Download. Device Manager is bundled in DCNM.
    For DCNM-SAN installation please see here:
    http://www.cisco.com/en/US/docs/switches/datacenter/sw/5_x/dcnm/installation/guide/inst_troubleshoot.html
    I hope this helps.
    Carlos

  • Windows 7 64-bit Cisco Fabric/Device Manager Installer

    Does anyone know if there is Cisco Device Manager Installer compatible with Windows 7 (64-bit)? I'm trying to install Device Manager onto my Windows 7 PC. this may happen on my Fabricv Manager Installer, as well. Any help would be appreciated.
    Thanks

    Senthil, Horacio,
    I would not recommend using a 8.5(x) client against a 8.0(x) server (the OP suggests UCCE 8.0 is used). Even though they _should_ be compatible, they usually are not.
    Upgrading the server side to 8.5 is the way to go IMHO.
    G.

  • Cisco Call Manager and LifeSize Endpoints

    Hello dear support community,
    last week I asked which version of Cisco Call Manager supports BFCP (https://supportforums.cisco.com/message/3966334).
    Unfortunately I asked the wrong question.
    As it turns out I just didn't need to know which version of Call Manager supports BFCP, which I know now, I also need to know if Call Manager is compatible with LifeSize systems?
    Here is the setting, so you know what I'm dealing with:
    The costumer uses Cisco Call Manager (Ver. 9.1) as SIP registrar for his LifeSize endpoints. The problem is, when he is making a video conference (via SIP) and he wants to share a presentation, the other side either sees him or the presentation, but not both.
    We tried it with our Call Manager (Ver. 9.0) and some LifeSize endpoints. As soon as the LifeSize endpoint uses CUCM as SIP registrar, the option to share the presentation is completely gone. 
    I guess the costumer switched sources from cam to pc. That would explain why he just sees either video or presentation. But, as you might have guessed, it's not an acceptable solution for the costumer.
    And yes, we made sure that BFCP is enabled for the endpoints.
    So, what I'm asking myself and you is:
    Is this known? And more important, is there a reliable workaround?
    Thanks a lot in advance.
    Best regards
    Tobias

    I've been down this road and when I asked the question Lifesize's stance was that it wasn't supported by THEM. I pointed out that CUCM now supports line-side BFCP but they essentially shrugged their shoulders. Either they are blatently disabling content sharing by virtue of using a SIP Proxy or they have a priorietary SDP/header that CUCM isn't passing through.
    Either you can call Lifesize and shake them up a bit or you can wireshark the SIP dialog to see what the codec asks CUCM before disabling the sharing button. Once you know that you might be able to use SIP transparancy to pass the header through.

  • Where is the device manager on the g-7 1150us?

    I have an     HP Pavilion g7-1150us, and I do not know where the device manager is located. Can someone please help? Thank you,BeeBudd
    This question was solved.
    View Solution.

    Hi,
    If no change, your machine runs Windows 7 Home Premium. Device Manager is in the Control Panel. Please
    Click Start then click Control Panel. You can see Device Manager in there
    Regards.
    BH
    **Click the KUDOS thumb up on the left to say 'Thanks'**
    Make it easier for other people to find solutions by marking a Reply 'Accept as Solution' if it solves your problem.

  • No switch health or port utilization info displayed c2960-24tt device manager

    Hi there, I have a WS-C2960-24TT-L. running 12.2(58)SE2
    When I connect to this switch's Cisco Device Manager web interface, the "bandwidth used" and "Packet error" both show 0%, and no information appears in the port utilization graph.
    The temperature and fan indicators appear to work. The page auto-refreshes. Switchports change color as expected (i.e. go dark when disconnected). I have left the browser open for a reasonable period of time (i.e. over the lunch hour). Other items such as the table of port statistics show up as expected. I am using a secure session. I have tried both Firefox 27.0.1 and Internet Explorer 9.0.25 and see the same result in both browsers.
    I am thinking I need to configure something in the switch to enable this information to appear.
    Thanks for your suggestions!

    Well, yes, but it would be nice to have the graphic summary.

  • Cisco Prime Infrastructure - I can't see the hardware virtual image when I selected a device managed by Prime Infrastructure. See attached picture

    My Cisco Prime Infrastructure ver. 1.2.1.12
    Cisco Prime Infrastructure - I can't see the hardware virtual image when I selected a device managed by Prime Infrastructure. See attached picture.
    Please let me know how to access or enable the feature.
    Thanks,
    Tek

    This is by no means a full solution, but deleting and re-adding only takes a few minutes if you use the "Export Device" and "Bulk Import" features from the Device Work Center. You can export the desired devices to a CSV file, delete them, then import from the CSV. 
    Of course, you might lose historical data when deleting the devices, but I'm guessing that's not as relevant since the devices themselves have been replaced by different hardware.

  • Problems with device manager tacacs authentication

    We've recently upgraded our Device Manager to 4.1(3a) and have a mix of switches running this version as well as older versions (3.3(3)). We use AAA tacacs+ on the switches to a Cisco ACS server for user authentication. The ACS server backends out to our Windows Domain authentication service. Typically usernames are formatted as follows: domain\username
    This has worked fine for a long time, however now DM 4.1(3a) can't authenticate a user on a 3.3(3) switch. Various debugs and logs on the ACS point to problems handling the \ character in the username. A single \ gets "eaten" by either DM or the switch(don't know which) and the ACS sees a login attempt from domainusername, which of course fails.  A \\ doesn't work either, in this case both \ characters are passed through to the ACS which now see a login attempt from domain\\username which also fails.
    Looked at all the release notes, CCO bug searches, google and previous forum articles and found nothing on this.
    Any help would be appreciated.
    thanks,
    Peter

    Hi Dexios and welcome to the forums!
    Here is the knowledgebase article on desktop/Bluettoth connection:
    http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB04132&sliceId=SAL_Pub...
    Thanks,
    Please remember to resolve your thread. Put the check mark in the green box that contained your answer! Thanks
    Click Accept as Solution for posts that have solved your issue(s)!
    Be sure to click Like! for those who have helped you.
    Install BlackBerry Protect it's a free application designed to help find your lost BlackBerry smartphone, and keep the information on it secure.

Maybe you are looking for

  • Error Calling Data Provider for Return PO in Me21N Message Number FES011

    Hi Experts, I am trying to create a Return PO using ME21N. Im giving all the parameters and values. But While saving its generating an Error. it states "Error calling Data Provider". Message No. FES011 What could be the possible error . Any clues? Th

  • Cloud Service has suddenly started calling itself repeatedly.

    I have a cloud service.  I have an OperationContract method, the first line of which logs "START" to a database. The method is called from a web page (however after discovering the problem, I am now calling from a Unit Test method.  The web site logs

  • Drag and drop tabs not working

    Dragging and dropping tabs no longer works. I cannot drag a tab out to a new window or reorder the tabs. This used to work and is a very nice feature. Reordering bookmarks by dragging them around also appears to be broken. Disabling plugins or resett

  • TS1702 Difficulty purchasing apps.

    It is not allowing us to purchase a paid app. We have credit on the App Store and a valid credit card.

  • Calling Instance Method in a Global Class

    Hi All, Please can you tell me how to call a instance method created in a global class in different program. This is the code which I have written, data: g_cl type ref to <global class>. call method g_cl -> <method name> I am not able to create Creat