Unsolved

This post is more than 5 years old

2 Posts

1730

October 18th, 2009 23:00

Brocade switch radius authorisation with Cisco ACS

I have configured Brocade switch using radius authentication with our Cisco ACS server, when I authenticate into the switch, my role was only given me an user permission rather than admin permission.

I was wondering, how do you change the role to admin on the Brocade switch?

Model - DS-200B

6 Operator

 • 

2.1K Posts

October 19th, 2009 08:00

I'm pretty sure the role is set on the RADIUS server, not the switch itself.

October 19th, 2009 17:00

Any idea on how to configuring RBAC for radius (IETF) on Cisco ACS server, I have been looking at this yesterday, but can't figure it what options to change to make it work.

1 Message

October 21st, 2009 07:00

Hi

After the RADIUS server authenticates a user, it responds with the assigned switch role in a Brocade Vendor-Specific Attribute (VSA). If the response does not have a VSA role assignment, the ¿user¿ role is assigned

Don't know how to set it in Cisco ASC specific but you can set the role
The syntax used for assigning VSA-based account switch roles on a RADIUS serve

Type 26 1 octet
Length 1 1 octet, calculated by the server
Vendor ID 1588 4 octet, Brocade¿s SMI Private Enterprise Code


Vendor Assigned attribute : 1
Attribute Format : String
Attribute value : admin or any other you want to assign


Regards

Rene

6 Operator

 • 

2.1K Posts

October 23rd, 2009 13:00

And while I'm at it, welcome to the Forums rebu. Glad to see you jumping in with some detailed help right away. This is the kind of thing that is important even if you can't give a full answer. It might be enough to either let him get the rest from Cisco, or spark someone else to provide the missing piece.

That's one of the great things about Communities like this. No one has to know it all. Everyone can contribute a bit and in the end we still have the potential to end up with a full answer!

6 Operator

 • 

2.1K Posts

October 23rd, 2009 13:00

I'm afraid I can't give you details on Cisco ACS configuration either. I'm only a consumer of RADIUS services that our NetTech team provides for us. You could probably get the details from Cisco though based on the information rebu provided.
No Events found!

Top