networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 7 posts ] 
Author Message
PostPosted: Mon May 21, 2012 1:37 pm 
Offline
Ultimate Member
Ultimate Member

Joined: Wed Aug 03, 2011 12:24 pm
Posts: 504
Location: Charleston, SC
Certs: MCSE, MCP+I, SEC+ (working on CCENT/CCNA)
Folks-

I have a requirement to have Cisco logins authenticate against a RADIUS server, as per this site:
http://aaronwalrath.wordpress.com/2010/ ... r2-nps-for
-radius-authentication-for-cisco-router-logins/


My server lady did that side of the house, and then I carried on with the Cisco side, as per directions from a friend:

<necessarily anonymized for security>
ip radius source-interface <an IP interface name here>
aaa new-model
aaa group server radius <name of the group the server lady made>
server <IP of the RADIUS server> auth-port <port #> acct-port <port #>
radius-server key <PSK the server lady made during server build>
aaa authentication login default group <same name as in line 3, above> local

I do a "test aaa group <groupname> <username> <password> new-code" from the switch and it returns "rejected username". The account I am using is precisely the one that was configured on the RADIUS server.

Ideas?


Top
 Profile  
 
PostPosted: Mon May 21, 2012 2:10 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Thu Dec 30, 2010 2:05 pm
Posts: 1133
Location: Stockholm, SE
Certs: CCNP, CCNP SP, CCDA, CCNA DC, CCNA W, HP MASE
look at the NPS logs, they are actually pretty good.

_________________
som om sinnet hade svartnat för evigt.


Top
 Profile  
 
PostPosted: Tue May 22, 2012 10:58 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Sat Oct 20, 2007 11:05 am
Posts: 1952
Location: Plano, TX
Certs: CCNA
Wow. Funny your doing this because I actually just did this over the weekend. NPS logs are defiantly helpful for this.


Top
 Profile  
 
PostPosted: Wed May 23, 2012 8:30 am 
Offline
Ultimate Member
Ultimate Member

Joined: Wed Aug 03, 2011 12:24 pm
Posts: 504
Location: Charleston, SC
Certs: MCSE, MCP+I, SEC+ (working on CCENT/CCNA)
Thanks Texan, I may have to pick your brain on this. Don't suppose you work in Beaumont, do you? It would be ironic to see one of our teams here. :)

EDIT: nope, that's 5.5 hours down the road.. don't imagine you'd commute that far ;)


Top
 Profile  
 
PostPosted: Fri May 25, 2012 7:35 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Sat Oct 20, 2007 11:05 am
Posts: 1952
Location: Plano, TX
Certs: CCNA
If this is server 2008 you can find the logs very easy by going to "Event Viewer -> Custom Views -> Server Roles -> Network Policy and Access Services" and it will filter all of the NPS logs which makes it easy to find authentication attempts. Post the sanitized results.


Top
 Profile  
 
PostPosted: Fri May 25, 2012 8:50 am 
Offline
Ultimate Member
Ultimate Member

Joined: Wed Aug 03, 2011 12:24 pm
Posts: 504
Location: Charleston, SC
Certs: MCSE, MCP+I, SEC+ (working on CCENT/CCNA)
We just cleared our DIACAP, so this is MUCH less pressing- but I will be getting back on it shortly.


Top
 Profile  
 
PostPosted: Fri May 25, 2012 3:48 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Nov 13, 2009 5:15 pm
Posts: 1957
Location: Pittsburgh
Certs: CCIE R&S,CCIP,JNCIA,VCP510
I must say that is way better than the old IAS method in server 2003.

_________________
"I will prepare and some day my chance will come." - Abraham Lincoln
http://danielhertzberg.wordpress.com - I blog about networks!


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 7 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: Exabot [Bot], Google [Bot] and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group