User guide

Cisco ACS RADIUS Server
278
18. EnsurethattheActiveDirectory/LocalaccountfortheuserhasDial
Inaccessenabledintheiruserprofile. IftheWindows2000Domain
serverisinNativeModeandIASisregisteredwiththeActive
Directory,youcansettheUserProfile>DialInsettingtouseRem
ote
AccessPolicies.
Cisco ACS RADIUS Server
TheCiscoAccessControlServer(ACS)isanotherauthenticationsolution
supportedbytheDominionSXunit.FortheDominionSXtosupport
RADIUS,boththeunitandtheuserinformationmustbeaddedintothe
RADIUSconfiguration.
Configure the Dominion SX to use a Cisco ACS Server
ThefollowingprocedureconfigurestheDominionSXunittoworkwitha
CiscoRadiusServer.
1. ChooseUserManagement>Configuration>UserGroupListon
DSX.
2. ClickAddNewUserGroup.
Youcandefineportaccessanduserclass(operatororobserver).Thisuser
groupwillbeusedlaterasava
luetotheFilterIda
ttributeontheCisco
RadiusServer.TheDominionSXcomeswithfactorydefaultgroup
Adminthatwillbeusedasanexampleinthissection;however,anylocal
groupcanbeusedasvaluetotheFilterIdattributeontheCiscoACS
Server.
Notes:Groupnamesarecas
esen
sitiveandmustmatchexactlythose
definedinthe
FilterIdattributeontheRadiusserver.
OnlyVersion3.1oftheCiscoRadiusServerhasbeentested;however,
otherversionsoftheRADIUSservershouldoperatewiththeDSX.
Configure the Cisco ACS Server
1. LogontoCiscoACSServerusingthebrowser.
2. TypeyourUsernameandPassword.
3. ClickLogin.
4. ClickNetworkConfigurationintheleftpanelofthescreenandselect
AddEntrytoadd/editanAAAClient.Thismustbedoneforeach
unitthatisgoingtobeacce
ssedvi
aRADIUS.