User $enable15$ in Cisco Secure ACS
Hi all,
I have a Cisco Secure ACS server, by default it has a username called "$enable15$"; I am using TACACS as the authentication protocol.
The question is if I need the $enable15$ user configured in the ACS server even if I am using TACACS as the authentication protocol. I want to delete it but I am not sure if it is possible.
regards
Regards.
Group Setup, select the group and click on edit settings and scroll down to "Cisco IOS/PIX 6.x RADIUS Attributes" and enable "cisco-av-pair" and enter shell:priv-lvl=15.
Similar Messages
-
Hello Everybody,
I am working with Cisco Secure ACS 4.2 and it is integrated with Active Directory at a Windows 2008 R2 functional level, user accounts that are set with lockout parameters (3 incorrect attempts) are locked out prematurely after the user enters the wrong credentials just once, the integration is done via LDAP.
I wonder if anybody has any idea why this is happening, because when I connect to a Cisco device or VPN, and type my password wrongly, on the Active Directory I get extra bad password counts.
Thanks in advance and regards....Hello Scott,
Thanks for your answer. However we checked the ACS logs and it shows that we entered bad credentials just once, but in the Active Directory our account sometimes is blocked because we get at least 2 and sometimes 3 failures. This problem is only presented when we authenticate Cisco devices or through VPN, in normal circumstances, when users enter bad credentials on their computers, it works fine.
Thanks and regards... -
With Cisco Secure ACS For Windows TACACS+, authentication fails with AD
I am setting up a Cisco Secure ACS 4.2 server to act as a TACACS server for Switches and Routers I am using Windows 2003 server for the ACS,
and a Windows 2003 Active Directory server. The AD server is fine, as it is used for many other things.
I have set up ACS as defined nit he installation guide, including all the steps in the 'Member Server' section of the install guide
when using AD as an external database (i.e. setting up the services to run with a domain admin account, setting up a machine called 'CISCO'
on the domain etc).
I've set the unknown user policy to use the Windows database if the internal database doesn;t contain the user details.
If I add a user to the internal database, the authentication goes through fine, with an entry in the 'Passed Authentications' log,
02/24/2010,05:07:03,Authen failed,eXXXX,Network Administrators(NDG) ,X.X.X.X,(Default),Internal error,,(geting error message as INternal Error)
I've scoured google etc, and just cannot come up with any reason why this should be happening.
I've followed all the install guides to the letter. I need to get this up and running as soon as possible,
so am looking forward to finding out if anyone can help me with this one!
THanks and regards
SharanHi Jesse,
Thasts a great answer and Soution.
My previous version was 4.2 and it was installed on 64 bit machine hence getting internal Error.
After this answer i have upgraded it to ACS4.2.1 and its started working fine
Thanks very much for the help
Dipu -
Setting privileges in Cisco Secure ACS Version 5.1.0.44
I am setting privileges in Cisco Secure ACS Version 5.1.0.44.
In the command sets from the ACS server, I denied few commands as can be seen in the attached screenshot and selected 'Permit any command that is not in the table below'.
I am unable to see some commands like "Show running-configuration" from the router I was testing. What changes should I do to see all the commands other than the denied commands. Your help will be rated. Thank you.Hi,
The ACS is able to handle permit or deny commands.
I created a configuration example that will help you to understand command shell.(see attach doc)
Instead of using show running-config please use show config.
also make sure that all the users are using privilege 15.
Regards, -
Cisco Secure ACS with UCP assistance and enable password
I am running Cisco Secure ACS version 4.2 running on a
Standalone Windows 2003 Enterprise 2003with the lastest
windows service pack and update. Secure ACS is running
fine and I can authenticate with Cisco routers and
switches. The Windows 2003 server is also running Microsoft
IIS Server. In other words, the IIS server and Cisco
Secure ACS is running on the same windows 2003 server.
I am trying to get Cisco User-Changeable password to work
with Cisco Secure ACS. I followed the release notes lines
by lines and the work around provided below:
Also server require more privileges for the internal windows user that runs CSusercgi.exe.
The name of the windows user that runs UCP is IUSR_<machine_name>.
Workaround steps:
1) Install UCP 4 on a machine that runs IIS server.
2) Open IIS manager
3) Locate Default Web Site
4) Double click on the virtual name 'securecgi-bin'
5) Right click on CSusercgi.exe and choose Properties
6) Choose 'File Security' tab
7) Choose 'Edit' in 'Authentication and access control' area
8) Change username from IUSR_<machine_name> to 'Administrator' and enter his
password (make sure that 'Integrated Windows authentication' is checked)
I still can NOT get this to work. I got this error:
It says:
The page cannot be found
The page you are looking for might have been removed,
had its name changed, or is temporarily unavailable.
HTTP Error 404 - File or directory not found.
Internet Information Services (IIS)
I modified everything in the Windows 2003 to be "ALLOWED" by
EVERYONE. In other words, there are NO security on the windows 2003.
It is still NOT working.
The other question I have is that can Cisco UCP allow user
to change his/her enable password?
Can someone help? Thanks.Yes bastien,
Thank you.
But one thing more i want to know that in its Redundant AAA server, when i try to open IIS 6.0 window 2003; it prompts for Username and Password.
I've given it several time; also going through Administrator account with administrative credentials but it always failed.
Any suggestions/solution/?
This time many thanks in advance.
Regards
Mehdi Raza -
Cisco secure ACS - RDBMS Rename a Group-
Hi,
I'm currently working with Cisco secure ACS 3.1 and I'm trying to use RDBMS synchronisation with a csv file. I create a accountactions.csv file where I create a new user.
1,0,TESTuser,,100,,,,,,0,,,0
2,0,TESTuser,,102,,test,,,,0,,,0
Until here, all is working fine. But now, I would like to put this user into a Group. This should be done with :
3,0,TESTuser,Group 30,106,,,,,,0,,,0
But I would like to know if it's possible to rename or create one Group (e.g rename Group 30 with Group TEST) directly in my csv file ?
Thank you
Regards
Pascal TOURNIERHere is what i found works for renaming a default group, as you cannot create more groups beyond what is there.
SequenceId,Priority,UserName,GroupName,Action,ValueName,Value1,Value2,Value3,DateTime,MessageNo,ComputerNames,AppId,Status
1,1,,Group 100,210,,BPM,,,,0,,,0
2,2,,Group 101,210,,CHANNEL SECURE OPS,,,,0,,,0
3,3,,Group 102,210,,CISCO CNC,,,,0,,,0
4,4,,Group 103,210,,CISCO NOS,,,,0,,,0
5,5,,Group 104,210,,CTS,,,,0,,,0
6,6,,Group 105,210,,DCI,,,,0,,,0
line 1
Rename "Group 100" to named group "BPM" using code 210 to perform the Action
Gerald -
Cisco Secure ACS license question.
On the Cisco ACS server under the internal identity stores… is “users” and “host” counted against the "base server license" or “network device license”?
Guess you are running ACS 5.x
With the Base license, Cisco Secure ACS 5.3 appliances or software virtual machines can support deployments of up to 500 network devices (authentication, authorization, and accounting [AAA] clients). The number of network devices is based on how many unique IP addresses are configured. This is not a limit for each individual appliance or instance, but a deployment-wide limit that applies to a set of ACS instances (primary and secondary) that are configured for replication.
The optional Large Deployment add-on license allows a deployment to support more than 500 network devices. Only one Large Deployment license is required per deployment as it is shared by all instances.
For more info:
http://www.cisco.com/en/US/prod/collateral/netmgtsw/ps5698/ps6767/ps9911/product_bulletin_c25-689829.html
~BR
Jatin Katyal
**Do rate helpful posts** -
Hi
I am trying to delete all users that belong to a specific ACS group.
Does anybody know how to delete the entire group (both group settings and all users that reside on this group)?
Now, I have to delete users one by one.
BRThis cannot be done directly from the ACS GUI. To delete users from the ACS server, we have to create a "import.txt" file and then import
the file through CSUtil on ACS server. The procedure is given below :
1. Create a "import.txt" file.
OFFLINE
DELETE:
DELETE:
DELETE:
DELETE:
[ username : which you want to delete ]
2. Save this file in C:/program files/cisco secure ACS v4.2/Utils folder.
3. Go to the windows command line and issue:
$BASE\utils\net stop csauth
$BASE\utils\csutil -i import.txt
$BASE\utils\net start csauth
$BASE is the directory where the software is installed.
Regards,
Jatin Katyal
- Do rate helpful posts - -
Troubleshooting Cisco Secure ACS on Windows - Q&A clarification.
In a Cisco Press publication "Troubleshooting Cisco Secure ACS on Windows" (http://www.ciscopress.com/articles/article.asp?p=474238&seqNum=6&rl=1), I read the following question:
How can I disable the users' option to change the password by using Telnet to access the router?
It has an answer describing certain details. However, the question itself is not clear to me. Could someone explain them a little more clearly?
Thanks.At the command prompt on a router its possible to start a password change request over TACACS to the ACS server.
I think you enter an empty password twice as I recall.
This can cause problems if users change their password on a "slave" ACS which is then replicated to from a "master" thus setting the password back to its pre-changed value. -
Cisco Secure ACS 4.2 with Oracle
hi there...
Our campus using WisM (WS-SVC-WISM-1-K9) as wireless controller , Cisco 1130 access point and Cisco Secure ACS 4.2 Solution Engine 1113 Appliance as radius server. For username and password, ACS will export the data from Oracle database(production DB).
The problem that we are facing right now is password that store in oracle database is in encrypted format. Base feedback from our database administrator, the encryption is done by oracle - application layer and cannot be decrypt back. In Oracle they call it "Oracle Stored Procedures"
My questions :
1- Can Cisco Secure ACS 4.2 work with Oracle 10G or 11G?
2- Is there any option to tackle the encrypted password? Can ACS handle the "Oracle Stored Procedures" function?
Please advice.
ThanksMicrosoft SQL Server and Case-Sensitive Passwords
If you want your passwords to be case sensitive and are using Microsoft SQL Server as your ODBC-compliant relational database, configure your SQL Server to accommodate this feature. If your users are authenticating by using PPP via PAP or Telnet login, the password might not be case sensitive, depending on how you set the case-sensitivity option on the SQL Server. For example, an Oracle database will default to case sensitive, whereas Microsoft SQL Server defaults to case insensitive. However, in the case of CHAP/ARAP, the password is case sensitive if you configured the CHAP stored procedure.
For example, with Telnet or PAP authentication, the passwords cisco or CISCO or CiScO will all work if you configure the SQL Server to be case insensitive.
For CHAP/ARAP, the passwords cisco or CISCO or CiScO are not the same, regardless of whether the SQL Server is configured for case-sensitive passwords.
Sample Routine for Generating a PAP Authentication SQL Procedure
The following example routine creates a procedure named CSNTAuthUserPap in Microsoft SQL Server, the default procedure that ACS uses for PAP authentication. Table and column names that could vary for your database schema appear in variable text. For your convenience, the ACS product CD includes a stub routine for creating a procedure in SQL Server or Oracle. For more information about data type definitions, procedure parameters, and procedure results, see ODBC Database.
if exists (select * from sysobjects where id = object_id (`dbo.CSNTAuthUserPap') and
sysstat & 0xf = 4)drop procedure dbo.CSNTAuthUserPap
GO
CREATE PROCEDURE CSNTAuthUserPap
@username varchar(64), @pass varchar(255)
AS
SET NOCOUNT ON
IF EXISTS( SELECT username
FROM users
WHERE username = @username
AND csntpassword = @pass )
SELECT 0,csntgroup,csntacctinfo,"No Error"
FROM users
WHERE username = @username
ELSE
SELECT 3,0,"odbc","ODBC Authen Error"
GO
GRANT EXECUTE ON dbo.CSNTAuthUserPap TO ciscosecure
GO
Sample Routine for Generating an SQL CHAP Authentication Procedure
The following example routine creates in Microsoft SQL Server a procedure named CSNTExtractUserClearTextPw, the default procedure that ACS uses for CHAP/MS-CHAP/ARAP authentication. Table and column names that could vary for your database schema appear in variable text. For more information about data type definitions, procedure parameters, and procedure results, see ODBC Database.
if exists (select * from sysobjects where id = object_id(`dbo.CSNTExtractUserClearTextPw')
and sysstat & 0xf = 4) drop procedure dbo.CSNTExtractUserClearTextPw
GO
CREATE PROCEDURE CSNTExtractUserClearTextPw
@username varchar(64)
AS
SET NOCOUNT ON
IF EXISTS( SELECT username
FROM users
WHERE username = @username )
SELECT 0,csntgroup,csntacctinfo,"No Error",csntpassword
FROM users
WHERE username = @username
ELSE
SELECT 3,0,"odbc","ODBC Authen Error"
GO
GRANT EXECUTE ON dbo.CSNTExtractUserClearTextPw TO ciscosecure
GO
Sample Routine for Generating an EAP-TLS Authentication Procedure
The following example routine creates in Microsoft SQL Server a procedure named CSNTFindUser, the default procedure that ACS uses for EAP-TLS authentication. Table and column names that could vary for your database schema appear in variable text. For more information about data type definitions, procedure parameters, and procedure results, see ODBC Database.
if exists (select * from sysobjects where id = object_id(`dbo.CSNTFindUser') and
sysstat & 0xf = 4) drop procedure dbo.CSNTFindUser
GO
CREATE PROCEDURE CSNTFindUser
@username varchar(64)
AS
SET NOCOUNT ON
IF EXISTS( SELECT username
FROM users
WHERE username = @username )
SELECT 0,csntgroup,csntacctinfo,"No Error"
FROM users
WHERE username = @username
ELSE
SELECT 3,0,"odbc","ODBC Authen Error"
GO
GRANT EXECUTE ON dbo.CSNTFindUser TO ciscosecure
GO
Reference:
http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/d.html#wp355420 -
Cisco Secure ACS 4.2 for Windows web-based Admin Console log in problems
To Whomever Can Assist,
I am running two deployments of Cisco Secure ACS for Windows 4.2 and I can login into the admin web-console just fine. However, when I create a new or test user that mirror my configuration that user cannot login to the admin web-console. The user can login it to devices with the appropriate privileges, but can't administer his/her account within ACS. This has proven very problematic and needs a remedy. Thanks for the assistance.Bradbryant.dhs,
Where are you creating the new admin user who should have access to ACS web gui under internal users or administration.
Internal user and ACS administrator accounts are completely different.
Adding administrator account
http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4-2/user/guide/ACS4_2UG/Admin.html
Regards,
Jatin Katyal
** Do rate helpful posts ** -
Unauthorized device logging in via Cisco Secure ACS 3.2
We have the Cisco Secure ACS v 3.2. There is a devices that we recently discovered is not added into the network configuration on the ACS. This device running IOS 12.2(29) does have all of the correct tacacs settings that should allow it to authenticate via Tacacs.
So basically, the ACS is allowing users to use this device to login, even though it's not in the Network Config.
When we look at the Logged-in Users report, it show the host name as "Tacacs+ Default". We aren't sure what that is supposed to mean, and why it's allowing it.
Thank You for your time,
AndrewAndrew,
Make sure that you not using any Wildcards inplace to IP address in network configuration. Eg using 192.168.*.*
This will open tacacs request from whole network 192.168
Also check the passed attempts and check the NAS IP address from the where the request is coming. Search for that IP in network configuration and see if that IP belong to that switch in question. L3 switch can have multiple ip address.
If that IP belong to that swtich , then you need to take that out from network configuration.
Regards,
~JG
Do rate helpful posts -
About Cisco secure ACS v3.0
HI
I have rebuilt the Tacac server for cisco secure ACS v3.0 and then retore all the data via the "data restore" under the system configuration.
After rebuilt, it was only working for one day... and then it fails to authenticate users. I checked the event viewer, the error message is:
ODBC authentication dll failed to initalise, code -1110
and
CSMon message: Problem Logging on to CSTacacs. Got as far as Starting Processing in Auth module
any idea?
ThanksHi
When I tried to view it, it says:
This bug is no longer available in Bug Toolkit. Click bug ID for details.
would you be able to provide more information for this bug please?
Thanks
kind regards
Rachel -
Features of Cisco Secure ACS Appliance
Hi,
/* Style Definitions */
table.MsoNormalTable
{mso-style-name:"Normale Tabelle";
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-style-noshow:yes;
mso-style-priority:99;
mso-style-qformat:yes;
mso-style-parent:"";
mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
mso-para-margin:0cm;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
mso-ascii-font-family:Calibri;
mso-ascii-theme-font:minor-latin;
mso-fareast-font-family:"Times New Roman";
mso-fareast-theme-font:minor-fareast;
mso-hansi-font-family:Calibri;
mso-hansi-theme-font:minor-latin;
mso-bidi-font-family:"Times New Roman";
mso-bidi-theme-font:minor-bidi;}
I’m working on an evaluation of NAC systems. Therefore, I’ve chosen the Cisco Secure ACS as representative of a 802.1X based solution.
There are a few questions I wasn’t able to answer by reading the product information available on Cisco.com. I hope that someone here might be able to help me. Any information is highly appreciated.
The questions I wasn’t able to answer are:
• Can the ACS work in a heterogeneous environment (i.e. Cisco and Alcatel Switches)?
• What happens if the server(s) fail?
o Can already authorized users still work?
o Can known users still be authorized?
o Are unknown users still blocked?
• Is the ACS capable of authorizing users through routed networks or VPN tunnels?
• Does a change of the assigned VLAN work without relogin (or even reboot) of the client?
• Is there (besides of the reports) some kind of status overview with the ACS?
• Which kinds of Attacks can the ACS (alone) prevent?
o Can it prevent MAC Spoofing?
o Can it prevent MAC Flooding?
o Can it prevent ARP Attacks?
o Can it prevent IP Spoofing?
o Can it eliminate rouge DHCP servers?
o Can it prevent STP Attacks
• And the last one: What happens if I plug in an unknown device into an IP-Phone? Is the switchport to which the IP-Phone is connected blocked or only the unknown device?
Thanks for all answers.
Regards,
taouriSee inline answers:
The questions I wasn’t able to answer are:
• Can the ACS work in a heterogeneous environment (i.e. Cisco and Alcatel Switches)?
Yes, as long as those devices support RADIUS and TACACS+ IETF standards. Some devices require the configuration of vendor-specific AV-pairs to work properly, which the ACS in general can do. You'll need to get details from the specific vendor on their requirements to insure it'll work.
• What happens if the server(s) fail?
o Can already authorized users still work?
This is driven by the AAA client, not the ACS. In general, if it isn't reauthenticating the users, then yes, they'll still work
o Can known users still be authorized?
In general, no, not by the ACS, but for some cases such as dot1x, it may be possible to configure fallback to local authentication or define a critical VLAN.
o Are unknown users still blocked?
Without contact to the server, the AAA client has no way of knowing what user is known / not known barring the above items.
• Is the ACS capable of authorizing users through routed networks or VPN tunnels?
Yes, as long as the VPN device is capable of sending Radius or TACACS+ requests to the ACS
• Does a change of the assigned VLAN work without relogin (or even reboot) of the client?
Yes, if using a supplicant that detects the EAP success message and knows to refresh the IP.
• Is there (besides of the reports) some kind of status overview with the ACS?
Yes, this is covered in the documentation for the appropriate ACS solution. Incidentally, the word ACS could mean ACS 4.x, or ACS 5.x, both of which are substantially different.
• Which kinds of Attacks can the ACS (alone) prevent?
ACS authenticates and authorizes users. It isn't in and of itself a device for prevention of the L2 attacks you list.
o Can it prevent MAC Spoofing?
o Can it prevent MAC Flooding?
o Can it prevent ARP Attacks?
o Can it prevent IP Spoofing?
o Can it eliminate rouge DHCP servers?
o Can it prevent STP Attacks
• And the last one: What happens if I plug in an unknown device into an IP-Phone? Is the switchport to which the IP-Phone is connected blocked or only the unknown device?
This depends on how you configure the dot1x parameters on the port. In general, this is often configured in single-host mode with a voice vlan for the phone. The phone passes through the EAPoL traffic the client passes, and in single host mode we rely on CDP bypass for the phone itself to bypass authentication. There are excellent documents for the various dot1x configuration options in our IBNS (identity-Based Network Solutions) section here:
http://www.cisco.com/en/US/customer/products/ps6638/products_ios_protocol_group_home.html -
Upgrade path for Cisco Secure ACS 4.X Solution Engine 1113 Appliance.
Hello,
I am having Cisco Secure ACS 4.X Solution Engine 1113 Appliance, and is running on version Cisco Secure ACS Release 4.1(1) Build 23 and now want to upgarde it to the latest version. Need to know the upgrade path for the same. As per my information ACS 4.1(1) runs on windows server and releases post to 5.X uses Linux. Please guide how can i upgrade Appliance 1113 from 4.1 to 5.xHi,
Cisco ACS 1113 appliance doesn't support ACS 5.x version. 1113 appliance supports till ACS 4.2.1 version.
Cisco ACS SE 1120/1121 appliance models are required for ACS 5.x
The upgrade path for ACS 4.1 to 4.2.1 version can be found in the following link :
http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/4.2.1/Installation_Guide/solution_engine/upgap.html#wp1237189
Regards,
Karthik Chandran
*kindly rate helpful post*
Maybe you are looking for
-
I have a Canon 70D and my old lightroom3 will not download raw files even though I have downloaded DNG 8.5 on my iMac. how can I overcome this problem?
-
Writing in a in file and going to a new line.
Hello. There's something in a program i am currently writing. I'm trying to write in 2 files with a format like this : line1..... line2..... In the first file, everything is ok but in the second file, with exactly the same instructions, instead og ge
-
Windows 7 64-bit hangs completely after some minut...
Hi all, My Windows 7 64-bit machine hangs completely after some minutes using Nokia Suite 3.3.89 connected with a E72 through USB cable. When connecting, everything goes fine and I can usually synchronize data successfully between the E72 and compute
-
MaxL Perl Module Result String Limit
I have a Perl script that uses the MaxL module to extract security filter rows to a text file. This script worked correctly under Essbase 6.2, but under 6.5, the strings returned my the MaxL module are limited to about 128 characters. I've tried incr
-
Won't charge! iPod touch 8gb
Charged it all up one day, next day, i turn it on and the empty red battery sign came up flashing showing I need to plug it in to be charged. So I plug it in to be charged, battery picture stays on with the little lightning symbol below, meaning it's