Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

some aaa question

Hi all,

Can anybody give me some hints to the follow aaa questions?

1. how to verify aaa config? I can not find any commands in the router like show aaa or something to summarize my aaa config.

2. If I config more than 1 radius servers or tacas servers and I config the authentication to use radius or tacas, what will the authentication like? the authentication will ask all the server or how? what will happen if the authentication fail for 1 server?

Thank You!

Waimen

1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: some aaa question

1)There are no commands like "show aaa" which can show you the aaa config on the router..BUT you can use sommand like this

sh run | include aaa

which will display running config with the lines which include "aaa" keyword.

2)More then one radius/tacacs server willbe listed in "sh run" depending on the way you enter. radius/tacacs server willbe contacted by the router in top-down order. So if you have like

radius-server host 1.1.1.1

radius-server host 2.2.2.2

then 1.1.1.1 willbe contacted all the time..If 1.1.1.1 will not respond then 2.2.2.2 will be contacted.

Now you can also configure the router to skip sending requests to the server which is dead or not responding.. Pl. visit

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122newft/122tcr/122tsr/fssprocr/sftrad.htm#1017571

3 REPLIES
Cisco Employee

Re: some aaa question

Hi ,

Say you are configuring telnet and you want to authenticate telnet session

with AAA , you open two telnet windows , one window as back up to configure

and change commands and another to telnet in and see if it works .

run debug aaa authenitcation .

You need to try actualling running login , telnet or PPP .

http://www.cisco.com/en/US/tech/tk583/tk547/technologies_configuration_example09186a00800fa54a.shtml

If there are multiple server , if first server is not reachable it will go to another

radius defined in it .

Now if first radius server sends REJECT than it will not go to second radius

you can conifgure radius group with AAA now .

http://www.cisco.com/en/US/products/sw/iosswrel/ps1834/products_feature_guide09186a0080080040.html

Nilesh

Cisco Employee

Re: some aaa question

1)There are no commands like "show aaa" which can show you the aaa config on the router..BUT you can use sommand like this

sh run | include aaa

which will display running config with the lines which include "aaa" keyword.

2)More then one radius/tacacs server willbe listed in "sh run" depending on the way you enter. radius/tacacs server willbe contacted by the router in top-down order. So if you have like

radius-server host 1.1.1.1

radius-server host 2.2.2.2

then 1.1.1.1 willbe contacted all the time..If 1.1.1.1 will not respond then 2.2.2.2 will be contacted.

Now you can also configure the router to skip sending requests to the server which is dead or not responding.. Pl. visit

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122newft/122tcr/122tsr/fssprocr/sftrad.htm#1017571

Cisco Employee

Re: some aaa question

Just to add, you can also configure how may re-tries that router needs to send the aaa server beforemarking it dead and move on to the next one..

By default 3 attempts will be made but you can modify that using "radius-server retransmit ..."command..Visit

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122newft/122tcr/122tsr/fssprocr/sftrad.htm#1017909

89
Views
0
Helpful
3
Replies
CreatePlease to create content