Can you control switch and router access with AD (Kerberos)

I am standing up a small environment with less than 20 switches and I want to configure the authentication so that dedicated Active Directory accounts provide access to the switches. We are not going to be able to put up an ACS box, and I don't want to use RADIUS unless I have to. Since both AD and Cisco support Kerberos, is it possible to us an AD group to control access to my switches and routers?

Sam,
Have you looked at these at Cisco?
http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/sec_cfg_kerberos.html
Section "Login Authentication Using Kerberos"
http://www.cisco.com/en/US/docs/ios/12_2/security/command/reference/srfindx.html
or these
http://www.techrepublic.com/article/configure-cisco-routers-to-use-active-directory-authentication-the-windows-side/6180954
HTH,
Arnold

Similar Messages

  • Can you control Lion on your desktop with an iPhone?

    Can you control Lion on your desktop with an iPhone?  I do not want to buy a wireless trackpad.  Who needs all those batteries?  Hoepfully the iPhone can control it in the meantime, and then they need to make wired trackpads. 

    fliplip1 wrote:
    hhmmm. possibility, buT why? It's there in black and white, it just takes a few more mins to read it.
    I guess there are multiple ways in which people interpret the same sentence. Not everything is obvious to everyone.
    If confused, people generally ask in the forums.

  • How can I create public AND private access with a wireless VPN router?

    I am thinking about getting one of the new pre-n wireless routers that has a builtin VPN.  I will need to have a private net for my office and a public net for my customers.  On the private side- my employees will need to access all network resources and servers etc.  On the public side, my customers just need to get to the Internet and maybe print on that side too.
    Both sides will be DHCP.
    Can I set this up with 1 device ro do I need 2?  How can I do this?  Any help is greatlu appreciated.
    Thanks all.
    Message Edited by Gman on 10-14-200607:08 PM

    The only safe way to do this is to creat user groups On your server and give specific assess to the users who log into the network.
    Using a single router , bifurcating a public from a private network is not possible.You will not be able to use the VPN since the users hav e to be connected to the VPN to log into your network.

  • How can I control cc1 and cc7 together with my modwheel?

    I would like to control controller cc1 (dynamics) and cc7 (Volume) at the same time with my midi keyboard modwheel, I believe I can make this happen with the help of a transformer object in the envirement, but am not sure. Anyone knows how to do this?
    André

    Understanding Home Sharing:  http://support.apple.com/kb/HT3819
    iTunes: Setting up Home Sharing in your computer, http://support.apple.com/kb/HT4620
    Troubleshooting Home Sharing:  http://support.apple.com/kb/TS2972

  • Branch office setup with L3 switch and router with IOS security

    Hello,
    I am in the process of putting together a small branch office network and I am in need of some design advise. The network will support about 10-15 workstations/phones, 3-4 printers, and 4-5 servers. In addition we will eventually have up to 25-30 remote users connecting to the servers via remote access VPN, and there will also be 2-3 site-to-site IPSec tunnels to reach other branches.
    I have a 2911 (security bundle) router and 3560 IP Base L3 switch to work with. I have attached a basic diagram of my topology. My initial design plan for the network was to setup separate VLANs for workstation, phone, printer, and server traffic. The 3560 would then be setup with SVIs to perform routing between VLANs. The port between the router and switch would be setup as a routed port, and static routes would be applied on the switch and router as necessary. The thought behind this was that I'd be utilizing the switch backplane for VLAN routing instead instead of doing router-on-a-stick.
    Since there is no firewall between the switch and router my plan was to setup IOS firewalling on the router. From what I am reading ZBF is my best option for this. What I was hoping for was a way to set custom policies for each VLAN, but it seems that zones are applied per interface. Since the interface between the router and switch is a routed interface, not a trunk/subinterface(s), it doesn't seem like there would be a way for me to use ZBF to control traffic on different VLANs. From what I am gathering I would have to group all of my internal network into one zone, or I would have to scrap L3 switching all together and do router-on-a-stick if I want to be able to set separate policies for each VLAN. Am I correct in my thinking here?
    I guess what I am getting at is that I really don't want to do router-on-a-stick if I have a nice switch backplane to do all of the internal routing. At the same time I obviously need some kind of firewalling done on the router, and since different VLANs have different security requirements the firewalling needs to be fairly granular.
    If I am indeed correct in the above thinking what would be the best solution for my scenario? That is, how can I setup this network so that I am utilizing the switch to do L3 routing while also leveraging the firewall capabilities of IOS security?
    Any input would be appreciated.
    Thanks,
    Austin

    Thanks for the input.
    1. I agree, since I have only three to four printers, they need not be in a separate VLAN. I simply was compartmentalizing VLANs by function when I initially came up with the design.
    2. Here's a little more info on the phone situation. The phones are VoIP. The IP PBX is on premise, but they are currently on a completely separate ISP/network. The goal in the future is to converge the data and voice networks and setup PBR/route maps to route voice traffic out the voice ISP and data traffic out the other ISP. This leads up to #3. 
    3. The reason a router was purchased over a firewall was that ASA's cannot handle routing and dual ISPs very well. PBR is not supported at all on an ASA, and dual ISPs can only be setup in an active/standby state. Also, an ASA Sec+ does not have near the VPN capabilities that the 2911 security does. The ASA Sec+ would support only 25 concurrent IPSec connections while the 2911 security is capable of doing an upwards of 200 IPSec connections.
    Your point about moving the SVI's to a firewall to perform filtering between VLANs makes sense, however, wouldn't this be the same thing as creating subinterfaces on a router? In both cases you are moving routing from the switch backplane to the firewall/routing device, which is what I am trying to avoid.  

  • Using APex with Airtunes from an iMAc can you control playing tunes?

    Hi, got an imac at Xmas, am looking into Airport stuff, and found this APex, with wireless play of iTunes music, Ive been looking into the Philips streamium and stuff doe playing tunes.
    My question is once setup from your iMac to play music wirelessly how can you control it? Ive read the manual but doesnt say anything. So can all you do is press shuffle on the iMac and then it plays everything?
    I know you could do playlists and stuff, but I have all my music, kids music, wife's music in my library, so theres a real mixture, and Im sick of listening to High School Musical!!
    So can you contol the song playing, ie skip etc with it?
    cheers

    iTunes needs to be running in order to stream music to the Airport Express so therefore - no - the Mac running iTunes cannot be in sleep mode. It must be powered up and running, though you could blank the screen if you wish.
    Why did Apple not build the function of the Keyspan Express remote into the Airport Express. Likely because it would have increased the cost of the product by 50%, while at the same time adding a feature most people would be happy to live without - in other words, not a great idea from a product marketing perspective.

  • My question was how do you control bass and treble on your Mac pro? he act of the matter is you can't. Why don't they just say that rather than reading all of the ********

    My question was how do you control bass and treble n a Mac Pro with the latest software.
    The answer is you can't
    In summary why don't you say that upfront?
    Instead of reading a bunch of crap that says nothing

    just a suggestion: try soundflower or Audio Hijack Pro. I know with the 2nd one, you can control the bass, treble, and all that, with anything that makes sound, from itunes, to Safari, DVD player, Skype ( I guess) and other stuff. Worth the $, IMO, so in answer to your question  dbumgardner1, no, no you can't.  I suppose in that sense, Windows has us at a loss. We also need 2nd party stuff to play BluRay's, too. However, I haven't seen any Macintosh viruses (virii?) for a long long time....
    so, there's that....
    JB

  • I have Microsoft Office 2008 and only use Word and Excel. It takes 980 mb. I am considering replacing it with Apple iWorks 2013. If I do, can I delete Office, and still access and modify my Word and Excel documents?

    I have Microsoft Office 2008 and only use Word and Excel. It takes 980 mb. I am considering replacing it with Apple iWorks 2013. If I do, can I delete Office, and still access and modify my Word and Excel documents?
    I have a MacBook Air and OS 10.9.4

    Ron
    Just adding to what CSound has said.
    Pages and Numbers will change Word and Excel documents when they open and close them.
    Sometimes the change is subtle and sometimes not. With the latest versions of Pages and Numbers, more likely not.
    So don't think you are going to work with MsOffice files without problems. You will always have something not right and in some cases really annoyingly not right. Like having all the text from Pages appear bold in MsWord, or page breaks in the wrong place or some objects and graphics not appearing in one or the other.
    If working between different Operating Systems and MsOffice files, I also recommend LibreOffice. It opens and saves nearly all file formats. Unfortunately not .pages or numbers. Yet. The folks at LibreOffice are busy adding to it all the time, and making sure it works in all Operating systems, Mac, Windows and Linux and they are promising iOS as well soon.
    Peter

  • Can you please put me in touch with the support  for the trial copy of adobe acrobat XI pro which I had tried out on March 15 for 30 days. I have  been trying to cancel since the cost is too much and Acrobat Reader is OK for me. I can't find uninstaller.

    Can you please put me in touch with the support  for the trial copy of adobe acrobat XI pro which I had tried out on March 15 for 30 days. I have  been trying to cancel since the cost is too much and Acrobat Reader is OK for me. I can't find uninstaller.
    I have had to erase my disk since then with trouble with Apple Store not recognising my machine and the reload from Time Machine has given complications . Can you please cancel my trial and return my Trial money.

    If you paid for what you used then it was not a trial.
    Look thru the following links and use the chat option if required for your situation:
    Cancel your membership or subscription | Creative Cloud
    https://helpx.adobe.com/x-productkb/policy-pricing/cancel-membership-subscription.html
    https://forums.adobe.com/thread/1703848
    Chat support - For the link below click the Still Need Help? option in the blue area at the bottom and choose the chat option...
    Creative Cloud support (all Creative Cloud customer service issues)
    http://helpx.adobe.com/x-productkb/global/service-ccm.html ( http://adobe.ly/19llvMN )
    Phone support | Orders, returns exchanges
    http://helpx.adobe.com/x-productkb/global/phone-support-orders.html

  • Can you replace a powermac g5 mbd with and Intel mbd?

    Can you replace a powermac g5 mbd with and Intel mbd?

    I think you would have to do a lot of work in addition to just replacing the motherboard. Like getting a new power supply for instance as the cables won't match what Apple specs for their designed and built hardware. I think the best you can hope for is to reuse the Aluminum tower case, and that's about it.
    Some links related to this:
    http://hintsforums.macworld.com/archive/index.php/t-96460.html
    http://forums.macrumors.com/showthread.php?t=652438

  • How you can sync your contact and your mail with iTunes 11 as it's not there anymore ?

    How you can sync your contact and your mail with iTunes 11 as it's not there anymore ?

    ~ means your Home directory. Using the command above takes you to the Home directory on the boot drive.  Your backup files are now on another drive in a directory that used to be your Home but is now a subfolder of Users so you have to specify that drive after the /Volumes, then the user name, then the rest to go there
    I use OSX 10.4.11 and on it the libraries are still visible.  There's two at least.  One general one at the top level of the boot drive and another for each user (the one with the ~).  I think they made at least one of them invisible with newer OS versions.

  • Can you stream video and use the computer at the same time on a mac mini with hdmi

    Can you steam video and use the computer at the same time? I have a mac mini with hdmi.

    Shouldn't be a problem, unless you want to view it in Full Screen Mode at the same time with only one display.

  • Which Switch and Router to choose?

    I am interested in purchasing a Cisco Switch and Router, or possible a Cisco Switch Router.
    However, I am not sure of what model to go with.
    Currently, we have a network with about 200 Workstations and 30 Servers for our Corporation Infrastructure.
    Also, for our lab, we have about 50 Linux Based Servers, and 30 Solaris Based Servers, that are part of our Network. We are a Research and Development Company, and we have had issues with the Lab machines bringing down our network, as well as our corporate network adversely affecting the lab machines. What we would like to do is segment the network so that the different areas will be isolated. However, we also would like to have a lot of control over the traffic that will be able to cross from our network into the lab so that users will still be able to run their tests.
    Security is also an issue, and it would be great to have more control, and a better view of what kind of traffic is running through our network.
    Currently, we have about 8 Gigabyte Switches which are unmanaged (Linksys and NetGear). Our idea was to get a 1 or 2 Cisco Switch Routers, and then split them up into VLANS and cascade our current switches so that we can still make use of them. The other ideas was to just get a Cisco Switch and use our CheckPoint Router/Firewall to do the routing.
    Can you give me any advice as to what model of Cisco Product you would recommend?
    Is it better to go with a Switch Router, or simply get a separate Switch and Router?
    Please note that all of our Machines have 10/100/1000 NICs, so the device will need to be Gigabyte.
    Thanks you so much!

    You have two choices. Either to use a chassis based solution or to use stacable switches such as a 3750. Are all the cat 5(or 5e,6) runs coming into one centralized location ? Or are there separate wiring closets that you plan to put. If then we need to put separate switches at those locations and run fiber back to the central location which has a chassis based or stackable switch.
    If using a chassis based solution, you can get a 4506 (4507 for redundancy, with a redundant supervisor engine). Supervisor engine is nothing but the CPU of the switch. 4506 is a 6 slot modular switch with 2 power supplies for redundancy. You cannot add two Supervisor engines on a 4506 (4507 can).
    Slot 1 is always for supervisor engine, the remaining 5 slots you can fill using 48 port 10/100/1000 modules.(48 * 5 = 240). So your maximum port density is 240 ports on a 4506. (Note that there are 4507, 4510 which are similar models with more slots)
    If using 3750, you can stack upto 9 switches in a stack using stacking cables on the back side of the switch. Each switch will have 48 ports (10/100/1000) and you can stack 5 switches to get 240 ports.
    For the firewall I would recommend using a PIX 515E, (Why go for Checkpoint firewall when you can use all Cisco). For routing between the vlans, the switches that I recommended above are all Layer 3 switches. They will route between the different vlans. You can also configure ACLs to restrict traffic between multiple vlans.
    HTH

  • CRM 2011: Can you control which form is used based not security roles, but on a field value?

    I see that you can control which form is used based on security roles, but can you control it based on other field values?  I'd like a new record to use a different form until a given status is updated.  I have a status of draft and active. So
    it would be nice if I could use form1 for those in draft, form2 for those that are active.  But I only see where you can control that via the security roles.
    I can code all of this via JavaScript, but having the ability to use two separate forms would be nice.  Is that even possible.
    Best regards,
    Jon Gregory Rothlander

    Hello,
    Recheck following article - http://gonzaloruizcrm.blogspot.com/2014/11/avoiding-form-reload-when-switching-crm.html
    Dynamics CRM MVP/ Technical Evangelist at SlickData LLC
    My blog

  • Can you share songs and apps but use multiple apple ID's?

    Can you share songs and apps but use multiple apple ID's?

    hmm, that's a trick one! what I would do is go to Messages>preferences>accounts and then select imessages and then select account details and then sign out. Then your wife will need to sign in with her apple id.
    hope this helps!!
    let me know if that works because I've never actually tried it.
    simply adding both of your accounts to be reached at will prove to be faulty because when you reply you can only reply with the one email address. And even if you switch caller id's it probably still won't work. So I think my method would be the easiest way to do that at this time. 

Maybe you are looking for