Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Webcast-Catalyst9k
New Member

LMS 2.5.1 in aaa mode - ACS 3.3 configuration

Hi,

I have configured the LMS server in AAA mode and we can login on the LMS server but whenever we try to access any of the pages in LMS we get authorisation errors.

Following the documentation, we need to make configuration changes in the "CiscoWorks" fields under the group settings on the ACS server. However I cannot find the CiscoWorks fields under the group or user settings. Am I missing something ?

Many thanks,

Cameron

5 REPLIES
New Member

Re: LMS 2.5.1 in aaa mode - ACS 3.3 configuration

Did you tick the box to register all CiscoWorks applications in ACS? It's the last option on the AAA setup page in LMS.

Silver

Re: LMS 2.5.1 in aaa mode - ACS 3.3 configuration

Besides doing the registration (which is suppose to be automatic, but really isn't) you need to create a new super user role in ACS and give all the attributes for all the applications to it. The default registration just doesn't cut it.

New Member

Re: LMS 2.5.1 in aaa mode - ACS 3.3 configuration

The info you are looking for will appear under "Shared Profile Components" in ACS, once you have registered all applications with ACS.

Then you'll need to create a user in ACS for CiscoWorks, and give a role to his account based on the roles you define in "Shared Profile Components".

HTH

Nick

New Member

Re: LMS 2.5.1 in aaa mode - ACS 3.3 configuration

I have another questions regarding Ciscoworks configured with AAA to ACS server.

Once the registration is done and the super user creation is done, I could not see all my devices in CW. I believe this is because some of the devices' IP address in CW are not listed in ACS.

For devices with multiple IP addresses, is there a way to force CW to choose a particular IP address?

New Member

Re: LMS 2.5.1 in aaa mode - ACS 3.3 configuration

thanks for your help guys, what I found was that the registration was failing because the username I was using was not an admin in ACS. once I added this account it was sweet.

cheers,

Cameron

115
Views
7
Helpful
5
Replies
CreatePlease to create content