Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

MARS with ACS

I have integrated MARS 4.3.1 with ACS but I need to know how I can assign privilege levels for the users on the ACS for different privilege on MARS.

3 REPLIES
Silver

Re: MARS with ACS

Hi Rohit,

The privilege levels are only assigned on the MARS box itself. There is nothing on the ACS which will assign users different privileges on MARS.

You can create four types of Users in MARS:

Admin--Superuser

Security Analyst--all privileges except Admin

Notifications Only--this account receives emails or reports generated by MARS

Operator-Read Only access

This is from the 4.3 User Guide:

"When the MARS Appliance operates with the AAA authentication method, every login except the administrator accounts are authenticated by the external AAA server.

All authentication method changes, successful logins, and failed logins are captured as event messages."

Hope this helps.

Paul

New Member

Re: MARS with ACS

Hi Paul

Thanks for the quick reply. My client already has ACS with users with privileges assigned for the various network devices. Since MARS had authentication feature through ACS-Radius, I was planning to create users on ACS and assign them different privilege and depending on the privilege which will be assigned through ACS, they will be assigned Analyst or Operator role.

Is this possible or am I interpreting the ACS integration in a wrong way.

If I cannot assign privilege levels for users why would I want authentication of MARS with ACS. Any ideas.

Silver

Re: MARS with ACS

Hi Rohit,

I believe you are interpreting the ACS integration in the wrong way. Though it's a good idea and a valid Product Enhancement Request.

The only reason you would have authentication of MARS users by an ACS would be to record failed logins. Many companies are required by their auditors to record these sort of events.

I readily admit this isn't much but it's going to take time for a more granular approach to be developed between MARS and ACS.

Hope this helps.

Paul

130
Views
5
Helpful
3
Replies