cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
883
Views
5
Helpful
3
Replies

LMS-FreeRadius integration

cmartinvalle
Level 1
Level 1

Hi,

I know that it's possible to create different groups of devices in LMS through ACS, in such a way that a specific user cannot access to devices not assigned to him.

Is it possible to do it with a FreeRadius instead of a ACS?

Many thanks.

2 Accepted Solutions

Accepted Solutions

Joe Clarke
Cisco Employee
Cisco Employee

No. ACS and TACACS+ are required to do this. With only a Radius server, you will only be able to provide external centralized authentication. None of the custom roles or device grouping capabilities will be available.

View solution in original post

However, this will not work with LMS. In order to restrict what devices an LMS user can manage, you need Cisco Secure ACS.

View solution in original post

3 Replies 3

Joe Clarke
Cisco Employee
Cisco Employee

No. ACS and TACACS+ are required to do this. With only a Radius server, you will only be able to provide external centralized authentication. None of the custom roles or device grouping capabilities will be available.

yjdabear
VIP Alumni
VIP Alumni

Generally, I'd say no, RADIUS is not a direct substitute for TACACS. But in this case, you can try emulating that basic behavior with huntgroups/sqlhuntgroups in FreeRadius:

http://wiki.freeradius.org/SQL_Huntgroup_HOWTO

However, this will not work with LMS. In order to restrict what devices an LMS user can manage, you need Cisco Secure ACS.