EasyManuals Logo

Cisco IOS XR User Manual

Cisco IOS XR
254 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #186 background imageLoading...
Page #186 background image
Configuring AAA Services on Cisco IOS XR Software
Information About Configuring AAA Services
SC-174
Cisco IOS XR System Security Configuration Guide
Remote Database
AAA data can be stored in an external security server, such as CiscoSecure ACS. Security data stored in
the server can be used by any client (such as a network access server [NAS]) provided that the client
knows the server IP address and shared secret.
Remote AAA Configuration
Products such as CiscoSecure ACS can be used to administer the shared or external AAA database. The
router communicates with the remote AAA server using a standard IP-based security protocol (such as
TACACS+ or RADIUS).
Client Configuration
The security server should be configured with the secret key shared with the router and the IP addresses
of the clients.
User Groups
User groups that are created in an external server are not related to the user group concept that is used
in the context of local AAA database configuration on the router. The management of external
TACACS+ server or RADIUS server user groups is independent, and the router does not recognize the
user group structure. The remote user or group profiles may contain attributes that specify the groups
(defined on the router) to which a user or users belong, as well as individual task IDs. For more
information, see the Task IDs for TACACS+ and RADIUS Authenticated Users section.
Configuration of user groups in external servers comes under the design of individual server products.
See the appropriate server product documentation.
Task Groups
Task groups are defined by lists of permitted task IDs for each type of action (such as read, write, and
so on). The task IDs are basically defined in the router system. Task ID definitions may have to be
supported before task groups in external software can be configured.
Task IDs can also be configured in external TACACS+ or RADIUS servers.
AAA Configuration
This section provides information about AAA configuration.
Method Lists
AAA data may be stored in a variety of data sources. AAA configuration uses method lists to define an
order of preference for the source of AAA data. AAA may define more than one method list and
applications (such as login) can choose one of them. For example, console and auxiliary ports may use
one method list and the vty ports may use another. If a method list is not specified, the application tries
to use a default method list. If a default method list does not exist, AAA uses the local database as the
source.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco IOS XR and is the answer not in the manual?

Cisco IOS XR Specifications

General IconGeneral
Operating SystemCisco IOS XR
ArchitectureMicrokernel
High AvailabilityYes
TypeNetwork operating system
Developed byCisco Systems
LicenseProprietary
Programming LanguageC, C++
KernelQNX
Supported PlatformsCisco ASR9000, NCS series
Security FeaturesRole-Based Access Control (RBAC), Secure Boot, Encryption
Management InterfaceCLI, SNMP, NETCONF, RESTCONF
Release Date2004
Target DevicesHigh-end core routers, service provider edge routers, data center interconnect (DCI) routers
Supported HardwareCisco routers and switches
Networking ProtocolsBGP, OSPF, IS-IS, MPLS
Virtualization SupportVirtualization-ready, supports network function virtualization (NFV) and containerization technologies.

Related product manuals