Cisco Cisco Access Registrar 4.2 manual

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94

Go to page of

A good user manual

The rules should oblige the seller to give the purchaser an operating instrucion of Cisco Cisco Access Registrar 4.2, along with an item. The lack of an instruction or false information given to customer shall constitute grounds to apply for a complaint because of nonconformity of goods with the contract. In accordance with the law, a customer can receive an instruction in non-paper form; lately graphic and electronic forms of the manuals, as well as instructional videos have been majorly used. A necessary precondition for this is the unmistakable, legible character of an instruction.

What is an instruction?

The term originates from the Latin word „instructio”, which means organizing. Therefore, in an instruction of Cisco Cisco Access Registrar 4.2 one could find a process description. An instruction's purpose is to teach, to ease the start-up and an item's use or performance of certain activities. An instruction is a compilation of information about an item/a service, it is a clue.

Unfortunately, only a few customers devote their time to read an instruction of Cisco Cisco Access Registrar 4.2. A good user manual introduces us to a number of additional functionalities of the purchased item, and also helps us to avoid the formation of most of the defects.

What should a perfect user manual contain?

First and foremost, an user manual of Cisco Cisco Access Registrar 4.2 should contain:
- informations concerning technical data of Cisco Cisco Access Registrar 4.2
- name of the manufacturer and a year of construction of the Cisco Cisco Access Registrar 4.2 item
- rules of operation, control and maintenance of the Cisco Cisco Access Registrar 4.2 item
- safety signs and mark certificates which confirm compatibility with appropriate standards

Why don't we read the manuals?

Usually it results from the lack of time and certainty about functionalities of purchased items. Unfortunately, networking and start-up of Cisco Cisco Access Registrar 4.2 alone are not enough. An instruction contains a number of clues concerning respective functionalities, safety rules, maintenance methods (what means should be used), eventual defects of Cisco Cisco Access Registrar 4.2, and methods of problem resolution. Eventually, when one still can't find the answer to his problems, he will be directed to the Cisco service. Lately animated manuals and instructional videos are quite popular among customers. These kinds of user manuals are effective; they assure that a customer will familiarize himself with the whole material, and won't skip complicated, technical information of Cisco Cisco Access Registrar 4.2.

Why one should read the manuals?

It is mostly in the manuals where we will find the details concerning construction and possibility of the Cisco Cisco Access Registrar 4.2 item, and its use of respective accessory, as well as information concerning all the functions and facilities.

After a successful purchase of an item one should find a moment and get to know with every part of an instruction. Currently the manuals are carefully prearranged and translated, so they could be fully understood by its users. The manuals will serve as an informational aid.

Table of contents for the manual

  • Page 1

    Americas Headquarters Cisco Systems, In c. 170 West Tasman Drive San Jose, CA 951 34-1706 USA http://www.ci sco.com Tel: 408 526-4000 800 553-NETS (638 7) Fax: 408 527-0883 Installing and Conf iguring Cisco A ccess Registrar , 4.2 November 20 08 Text Part Number: OL -17221-02[...]

  • Page 2

    THE SPECIFICATION S AND INFORMAT ION REGARDING THE PRODUCTS IN THIS MANU AL ARE SUBJECT T O CHANGE W ITHOUT NOTICE. A LL STATEMENTS , INFORMATION, AND RECOMMENDATI ONS IN THI S MANUAL ARE BE LIEVED TO BE A CCURATE BUT ARE PRESENTED WI THOUT WARRANTY OF ANY KIND, EX PRESS OR IMPLIED. USERS MUST TAKE FULL RESPO NSIBILITY FOR THEIR APPLICAT ION OF ANY[...]

  • Page 3

    iii Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 CONTENTS About This Guide ix Obtaining Documentation ix Cisco.com ix Documentation Feedback x Cisco Product Security Overview x Reporting Security Problems in Cisco Prod ucts x Obtaining Technical Assistance xi Cisco Technica l Support & Documentati on Website xi Submitting[...]

  • Page 4

    Contents iv Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 CHAPTER 2 Installing Cisco Access Registrar 4.2 2-1 Installing the Cisco Access Registrar 4.2 License File 2-1 Installing Cisco Access Re gistrar 4.2 Software on Solaris 2-1 Deciding Where to Install 2-2 Installing Cisco Access Re gistrar Software from CD-ROM 2-2 Instal[...]

  • Page 5

    Contents v Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Installing Cisco Access Registrar Software from CD-ROM 3-14 Common Linux In stallation Steps 3-15 Backup Copy of Original Configuration 3-17 Removing Old VSA Names 3-18 VSA Update Script 3-18 Configuring SNMP 3-19 Configuring SNMP 3-19 Restarting Replication 3-19 CHAPTER[...]

  • Page 6

    Contents vi Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Enabling SNMP in the Cisco Access Regist rar Server 4-14 Stopping the Master Agent 4-14 Modifying the snmpd.con f File 4-14 Access Control 4-15 Trap Recipient 4-15 System Contact Information 4-16 Restarting the Master Agent 4-16 Configuring Dynamic DNS 4-16 Testing Dyna[...]

  • Page 7

    Contents vii Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Configuring Services 5-14 Creating the Services 5-14 Configuring the Script 5-15 Choosing the Scripting Poin t 5-15 Configuring Session Management 5-16 Configuring a Resource Manager 5-16 Creating a Resource Manager 5-16 Configuring a Session Manager 5-17 Creating a Se[...]

  • Page 8

    Contents viii Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02[...]

  • Page 9

    ix Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 About This Guide The Installing and Conf iguring Cisco A ccess Registra r , 4.2, provides informat ion about installing, confi guring, and customizing CAR 4.2. This gu ide is intended to be used by experienced netw ork administrators with w orking kno wledge of the Solaris UNIX [...]

  • Page 10

    x Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 About This Guide Y ou can access internationa l Cisco websites at this URL: http://www .cisco.com/public/cou ntries_languages.shtml Documentation Feedback Y ou can rate and provide feedback about Cisco tech nical documents by completing the onlin e feedback form that appears with[...]

  • Page 11

    xi Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 About This Guide In an emer gency , you can also reach PSIR T by telephone: • 1 877 228-7302 • 1 408 525-6532 Ti p W e encourage you to use Pretty Good Pri v ac y (PGP) or a compatible product (for e xample, GnuPG) to encrypt any sensitiv e information that you send to Ci s [...]

  • Page 12

    xii Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 About This Guide output. Search results sho w an illustration of yo ur product with the serial number labe l location highlighted. Locate the serial numb er label on your product and record the information before placing a service call. Submitting a Service Request Using the on[...]

  • Page 13

    xiii Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 About This Guide Obtaining Additional Publications and Information Information about Cisco products, techno logies, and networ k solutions is av ailable from v arious onlin e and printed sources. • The Cisco Pr oduct Quic k Refer ence Guide is a handy , compact referen ce to[...]

  • Page 14

    xiv Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 About This Guide • W orld-class networking train ing is av ailable from Cisco. Y ou can view curr ent of ferings at this URL: http://www .cisco.com/en/ US/learning/inde x.html[...]

  • Page 15

    CH A P T E R 1-1 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 1 Overview This chapter pro vides an overvi ew of the software instal lation process. Y ou can install the CAR 4.2 software on a machine f or the first ti me, or you can upgrade the existing Cisco AR software on a workstation to CAR 4.2. Y ou might receive the Cisc[...]

  • Page 16

    1-2 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 1 Overvi ew Installation Dialog Overview Installation Location The next questi on in the installation d ialog asks, “W here do you want t o install?” The default location to install the softw are is /opt/C SCOar . Y ou can choose to specify another location by enter[...]

  • Page 17

    1-3 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 1 Overview Downloading Cisco Access Registrar Softw are Example Configuration The installation dialog asks if you want to instal l the example conf iguration. Y ou can use the example configuration to learn a bout Cisco AR an d to refer to the examples that appear later[...]

  • Page 18

    1-4 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 1 Overvi ew Cisco Access Registrar 4.2 Licensing • CSCOar -4.2.1-sol10-k9.tar .gz for Solaris 10 • CSCOar -4.2.1-lnx26-install-K9.sh for RedHat Enterprise Linux (RHEL) 4.0 Complete the follo wing steps to do wnload the software. Step 1 Create a temporary di rectory [...]

  • Page 19

    1-5 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 1 Overview Cisco Access Registrar 4.2 Licensing CAR can be deployed in a t wo-tier architecture—front- end and back-end server . The front-end server performs AAA functions and i t needs the base license and the TPS license. The back-end server performs session mana g[...]

  • Page 20

    1-6 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 1 Overvi ew Cisco Access Registrar 4.2 Licensing If you receiv e a Software License Claim Certif icate, you can get y our Cisco AR lice nse file at one of the two follo wing URLs: • www .cisco.com/go/license Use this site if you are a register ed user of Cisco Connect[...]

  • Page 21

    1-7 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 1 Overview Cisco Access Registrar 4.2 Licensing Displaying License Information Cisco AR provid es two ways of getting license information using aregcmd : • aregcmd command-line optio n • Launching ar egcmd aregcmd Command-Line Option Cisco AR provides a ne w -l comm[...]

  • Page 22

    1-8 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 1 Overvi ew Cisco Access Registrar 4.2 Licensing[...]

  • Page 23

    CH A P T E R 2-1 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 2 Installing Cisco Access Registrar 4.2 This chapter pro vides information about installing CAR 4 .2 software. The softw are is av ailable in CD-R OM form and can also be do wn loaded from the Cisco.com website. The installation instructions dif fer slightly depend[...]

  • Page 24

    2-2 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 2 Insta lling Cisco Access Registrar 4.2 Installing Cisco Access Registrar 4.2 Software on Solaris Installing Cisco Access Regist rar 4.2 Software on Solaris This section describes the software instal lation proc ess when inst alling Cisco AR software on a Solaris works[...]

  • Page 25

    2-3 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 2 Installin g Cisco Access Registrar 4.2 Installing Cisco Access R egistrar 4.2 Software on Solaris This section includes the following subsections: • Deciding Wh ere to Inst all • Installing Cisco Access Re gistrar Software from CD-R OM • Installing Do wnloaded S[...]

  • Page 26

    2-4 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 2 Insta lling Cisco Access Registrar 4.2 Installing Cisco Access Registrar 4.2 Software on Solaris Step 3 Use the follo wing command line to u ncompress the tarfi le and extract t he installation package f iles. zcat CSCOar -4.2.1-sol9-K9.tar .gz | tar xvf - Note These [...]

  • Page 27

    2-5 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 2 Installin g Cisco Access Registrar 4.2 Installing Cisco Access R egistrar 4.2 Software on Solaris http://java.sun.com/ Where is the J2RE installed? [?,q] /nfs/insbu-cnstools/java The J2RE is req uired to use the Cisco AR GUI. If you already ha ve a Ja va 2 pl atform i[...]

  • Page 28

    2-6 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 2 Insta lling Cisco Access Registrar 4.2 Installing Cisco Access Registrar 4.2 Software on Solaris Do you want to install these as setuid/setgid files [y,n,?,q] Step 13 Enter Y to install t he setuid/setgid file s . This package contains scripts which will be executed w[...]

  • Page 29

    2-7 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 2 Installin g Cisco Access Registrar 4.2 Installing Cisco Access Registrar 4.2 Software on Linux Configuring SNMP If you choose not to use the SNMP features of CAR, the inst allation process is complet ed. T o use SNMP features, complete the conf iguration procedure des[...]

  • Page 30

    2-8 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 2 Insta lling Cisco Access Registrar 4.2 Installing Cisco Access Registrar 4.2 Software on Linux Deciding Where to Install Before you be gin the softwa re installation, you sh ould decide where you wa nt to install the ne w software. The def ault installation directory [...]

  • Page 31

    2-9 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 2 Installin g Cisco Access Registrar 4.2 Installing Cisco Access Registrar 4.2 Software on Linux Step 3 Enter the name of the script f ile to begin the installation: ./CSCOar -4.2.1-lnx26-install-k9.sh Name : CSCOar Relocations: /opt/CSCOar Version : 4.2.1 Vendor: Cisco[...]

  • Page 32

    2-10 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 2 Insta lling Cisco Access Registrar 4.2 Installing Cisco Access Registrar 4.2 Software on Linux Step 7 When prompted whether to install the e xample configu ration no w , enter Y or N to cont inue. Note Y ou can delete the example conf iguration at any time by running[...]

  • Page 33

    CH A P T E R 3-1 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 3 Upgrading Cisco Access Registrar Software CAR 4.2 supports softw are upgrades from your pre vious ly installed Cisco AR software wh ile preserving your exist ing config uration database. Cisco AR supports an up grade path for both the Solaris or Linux versions of[...]

  • Page 34

    3-2 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 3 Upgrad ing Cisco Access Registrar Softwa re Linux Softwar e Upgrade Ov erview Step 2 If you hav e modif ied the snmpd.conf fi le in the /cisco-ar/ucd-snmp/share /snmp directory , you must back up this fi le before doing the upgrade process. The pkgrm remo ves the snmp[...]

  • Page 35

    3-3 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 3 Upgrading Cisco Access Registra r Software Software Upgrade Task s Step 2 If you hav e modif ied the snmpd.conf fi le in the /cisco-ar/ucd-snmp/share /snmp directory , you must back up this fi le before doing the upgrade process. The pkgrm remov es the snmpd.conf file[...]

  • Page 36

    3-4 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 3 Upgrad ing Cisco Access Registrar Softwa re Software Upgrad e Tasks [ //localhost/Radius/Replication ] RepType = None RepTransactionSyncInterval = 60000 RepTransactionArchiveLimit = 100 RepIPAddress = 0.0.0.0 RepPort = 1645 RepSecret = NotSet RepIsMaster = FALSE RepMa[...]

  • Page 37

    3-5 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 3 Upgrading Cisco Access Registra r Software Software Upgrade Task s 2973: terminated 2971: terminated, wait status 0x000f 2965: terminated Access Registrar Server Agent shutdown complete. # removing /etc/rc.d files # done with preremove. ## Removing pathnames in class [...]

  • Page 38

    3-6 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 3 Upgrad ing Cisco Access Registrar Softwa re Software Upgrad e Tasks Access Registrar Server Agent shutdown complete. # removing /etc/rc.d files # done with preremove. ## Removing pathnames in class <snmp> /opt/CSCOar/ucd-snmp/share/snmp/snmpd.conf /opt/CSCOar/uc[...]

  • Page 39

    3-7 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 3 Upgrading Cisco Access Registra r Software Installing the Cisc o Acc ess Registrar License File 4 processes left.3 processes left.......2 processes left.......k0 processes left.0 processes left Access Registrar Server Agent shutdown complete. Installing the Cisco Acce[...]

  • Page 40

    3-8 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 3 Upgrad ing Cisco Access Registrar Softwa re Upgrading Cisco Ac cess Registrar Solaris Softwar e Installing Cisco Access Registrar Software from CD-ROM The follo wing steps descr ibe ho w to begin th e software inst allation process when installin g software from the C[...]

  • Page 41

    3-9 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 3 Upgrading Cisco Access Registra r Software Upgrading Cisco Acc ess Registrar Solaris Software (sparc) 4.2.1 Copyright (C) 1998-2008 by Cisco Systems, Inc. This program contains proprietary and confidential information. All rights reserved except as may be permitted by[...]

  • Page 42

    3-10 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 3 Upgrad ing Cisco Access Registrar Softwa re Upgrading Cisco Ac cess Registrar Solaris Softwar e Do you want to preserve the local database in /opt/CSCOar [y]: [y,n,?,q] y Step 6 Enter Y to preserv e the local database. The upgrade procedure needs administrator access[...]

  • Page 43

    3-11 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 3 Upgrading Cisco Access Registra r Software Upgrading Cisco Acc ess Registrar Solaris Software inflating: /opt/CSCOar/jakarta-tomcat-4.0.6/webapps/tomcat-docs/RUNNING.txt inflating: /opt/CSCOar/jakarta-tomcat-4.0.6/webapps/tomcat-docs/security-manager-howto.html infla[...]

  • Page 44

    3-12 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 3 Upgrad ing Cisco Access Registrar Softwa re Upgrading Cisco Ac cess Registrar Solaris Softwar e ############################################################### # # A backup copy of your original configuration has been # saved to the file: # # /opt/CSCOar/temp/10062.o[...]

  • Page 45

    3-13 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 3 Upgrading Cisco Access Registra r Software Upgrading Cisco Acc ess Registrar Linux Software # to perform the update. The script is located in: # # /opt/CSCOar/temp/10062.manual-changes # # Review the script to make sure it does not conflict with # any of your VSA cha[...]

  • Page 46

    3-14 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 3 Upgrad ing Cisco Access Registrar Softwa re Upgrading Cisco Access Registrar Linux So ftware cd /opt/CSCOar/bin arserver stop Waiting for these processes to die (this may take some time): AR RADIUS server running (pid: 1403) AR Server Agent running (pid: 29310) AR MC[...]

  • Page 47

    3-15 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 3 Upgrading Cisco Access Registra r Software Upgrading Cisco Acc ess Registrar Linux Software Step 5 Change the permissions of the CSCOar-4.2.1- lnx26-install-k9.sh f ile to make it ex ecutable. chmod 777 CSCOar -4.2.1-lnx26-install-k9.sh T o continue the installation,[...]

  • Page 48

    3-16 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 3 Upgrad ing Cisco Access Registrar Softwa re Upgrading Cisco Access Registrar Linux So ftware Step 5 Enter the di rectory where you have stored the CAR 4.2 license file. Access Registrar provides a Web GUI. It requires J2RE version 1.4.* to be installed on the server.[...]

  • Page 49

    3-17 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 3 Upgrading Cisco Access Registra r Software Upgrading Cisco Acc ess Registrar Linux Software inflating: /opt/CSCOar/jakarta-tomcat-4.0.6/webapps/tomcat-docs/security-manager-howto.html inflating: /opt/CSCOar/jakarta-tomcat-4.0.6/webapps/tomcat-docs/ssl-howto.html crea[...]

  • Page 50

    3-18 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 3 Upgrad ing Cisco Access Registrar Softwa re Upgrading Cisco Access Registrar Linux So ftware Removing Old VSA Names The upgrade p rocess pro vides an analysis of the confi guration database, additio n of ne w database elements, and a search for obsolete VSA names. Wh[...]

  • Page 51

    3-19 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 3 Upgrading Cisco Access Registra r Software Configuring SNMP Step 11 Record the location of the u pgrade messages for future reference. ############################################################## # # These upgrade messages are saved in: # # /opt/CSCOar/temp/10062.u[...]

  • Page 52

    3-20 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 3 Upgrad ing Cisco Access Registrar Softwa re Restarting Replication[...]

  • Page 53

    CH A P T E R 4-1 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 4 Configuring Cisco Access Registrar 4.2 This chapter describe s how to configure a site. Ci sco Access Registrar 4.1 i s very fle xible. Y ou can choose to conf igure it in man y di fferent w ays. In addition, you can wr ite s cripts that can be in voked at dif fe[...]

  • Page 54

    4-2 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Access Registrar 4.2 Configuring a Basic Site Y ou can use CAR’ s command completion feature to see what commands are possible from your current directory location in the CAR server hierarchy b y pressing the T ab key . Y ou can also press the T ab[...]

  • Page 55

    4-3 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Ac cess Registrar 4.2 Configuring a Basic Site Step 1 Run the aregcmd command: aregcmd Step 2 When asked for “Cluster , ” press Enter . Step 3 Enter your administrat or name and password. When you install CAR software, th e installation process c[...]

  • Page 56

    4-4 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Access Registrar 4.2 Configuring a Basic Site Creating Additional Administrators Use the add command to add additional admini strators. Step 1 Use the cd command to change to the Administ rators lev el: cd /Administrators Step 2 Use the add command a[...]

  • Page 57

    4-5 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Ac cess Registrar 4.2 Configuring a Basic Site Checking the System-Level Defaults Because this site does not use incoming or outgoing scripts, you do not need to change the scripts’ properties (IncomingScr ipt and OutgoingScript). Since the default[...]

  • Page 58

    4-6 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Access Registrar 4.2 Configuring a Basic Site T o conf igure Cisco AR to use port s other than the default ports, complete the follo wing steps: Step 1 Change directory to /Radius/Advanced/P orts . cd /Radius/Adva nced/Ports [ //localhost/Radius/Adva[...]

  • Page 59

    4-7 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Ac cess Registrar 4.2 Configuring a Basic Site Cisco AR, by default, specif ies a Service called local-users t hat has the type local and uses the Default UserList ( Figure 4-1 ). Figur e 4-1 Choosing Appr opriat e Services Displaying the Default Use[...]

  • Page 60

    4-8 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Access Registrar 4.2 Configuring a Basic Site Description = Password = <encrypted> Enabled = TRUE Group~ = Telnet-users BaseProfile~ = AuthenticationScript~ = AuthorizationScript~ = UserDefined1 = AllowNullPassword = FALSE Attributes/ CheckItem[...]

  • Page 61

    4-9 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Ac cess Registrar 4.2 Configuring a Basic Site • PPP-users— uses the BaseProf ile default-P PP-users to specify the attrib utes of PPP service to provide the user . The BaseProfile defaul t-PPP-use rs contains the attributes that are added to the[...]

  • Page 62

    4-10 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Access Registrar 4.2 Configuring a Basic Site set IncomingScript ParseServiceHints EnableDynamicA uthorization TR UE EnableNotif ications TR UE The script, ParseServiceHints , checks the username for %PPP or %SLIP . It uses these tags to modify the [...]

  • Page 63

    4-11 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Ac cess Registrar 4.2 Configuring a Basic Site When you need to set an attrib ute to a value that includes a space, you must double-quote the v alue, as in the follo wing: set Framed-Routing "192.168.1.0/24 192.168.1. 1" Adding Multiple Ci[...]

  • Page 64

    4-12 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Access Registrar 4.2 Configuring a Basic Site Step 2 Use the rel oa d command to reload your server . rel o ad Testing Your Configuration No w that you ha ve conf igured some users and a N AS, you are ready to test your co nfiguratio n. There are tw[...]

  • Page 65

    4-13 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Ac cess Registrar 4.2 Configuring Accounting p001 send p002 Step 6 Enter the response identif ier to display the contents of the Access-Accept pac ket: p002 Packet: code = Access-Accept, id = 1, length = 38, attributes = Login-IP-Host = 196.168.1.9[...]

  • Page 66

    4-14 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Access Registrar 4.2 Configuring SNMP After you sa ve and reload the CAR server conf iguration, the CAR server writes accounting messages to the accounting.log f ile in th e /opt/CSCOar/log s directory . The CAR server stores information i n the acc[...]

  • Page 67

    4-15 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Ac cess Registrar 4.2 Configuring SNMP /opt/CSCOar/bin/arser ver stop Modifying the snmpd.conf File The path to the snmpd.conf file is /cisco-ar/ucd -snmp/share/snmp . Use vi (or another te xt editor) to edit the snmpd.conf fil e. There are three pa[...]

  • Page 68

    4-16 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Access Registrar 4.2 Configuring Dynamic DNS Trap Recipient The follo wing e xample sho ws the default co nfigu ration that sets up trap recipients for SNMP v ersions v1 and v2c. Note Most sites use a single NMS, not two as shown belo w . # --------[...]

  • Page 69

    4-17 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Ac cess Registrar 4.2 Configuring Dynamic DNS Y ou enable dynamic DNS updates b y creating and conf iguring ne w Resource Managers and ne w RemoteServer s, both of type dynami c-dns. The d ynamic-dns Reso urce Managers specify which zones to use for[...]

  • Page 70

    4-18 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Access Registrar 4.2 Configuring Dynamic DNS set IP Address 10.10.10.1 (ip address of primary dns server f or zone) set ForwardZoneTSIGK ey f oo.com set Rev erseZoneTSIGKey f oo.com If the re verse zone wil l be updated and if the primary serv er fo[...]

  • Page 71

    4-19 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Ac cess Registrar 4.2 Configuring Dynamic DNS Step 1 Launch aregcmd and log in to the Cisco AR server . cd /opt/CSCOar/bin aregcmd Step 2 Us e the trace command to set the trace to lev el 4. trace 4 Step 3 Launch radclient . cd /opt/CSCOar/bin radcl[...]

  • Page 72

    4-20 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 4 Configuring Cisco Access Registrar 4.2 Configuring Dynamic DNS[...]

  • Page 73

    CH A P T E R 5-1 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 5 Customizing Your Configuration After you ha ve conf igured and tested a basic site, yo u can begin to make changes to better address you r o wn sites’ s needs. This chapter prov ides information th at describes ho w to: • Use groups to s elect the appro priat[...]

  • Page 74

    5-2 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 5 Customizing Yo ur Configuration Configuring Grou ps Creating and Setting Group Membership Step 1 Run the aregcmd command: aregcmd Step 2 Use the cd command to change to the UserGr oups object. cd /Radius/UserGr oups Step 3 Use the add command to create a user group, s[...]

  • Page 75

    5-3 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 5 Custom izing Your Configuration Configuring Group s Configuring a Default Group If you allo w users to request dif ferent Services ba sed on ho w they specify thei r username, you c an use a script to determine th e type of Service to pro vide. F or example, the u ser[...]

  • Page 76

    5-4 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 5 Customizing Yo ur Configuration Configuring Multiple UserLists Step 6 Use the set command to set the user’ s group membership to the name of that group . The follo wing exa mp le set s beth ’ s group membership to th e Default group. set Group Def ault Step 7 Use [...]

  • Page 77

    5-5 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 5 Custom izing Your Configuration Configuring Mu ltiple UserLists Configuring Separate UserLists Di vide your site along organizat ional or compan y lines, and create a UserList fo r each unit. Creating Separate UserLists Step 1 Run the aregcmd command. aregcmd Step 2 U[...]

  • Page 78

    5-6 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 5 Customizing Yo ur Configuration Configuring Multiple UserLists add beth telemarketing 123 TR UE PPP-users Step 3 Repeat for the other users yo u want to add. Y ou can use the script, add-100-users , which is located in the /opt/CSCOar/ examples/cli director y to autom[...]

  • Page 79

    5-7 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 5 Custom izing Your Configuration Configuring Mu ltiple UserLists In this situati on, when beth@North.QuickExample.com makes an Access-Request, the script will strip of f the word North and use it to set the v alue of the en vironment v ariable A uthentication-Service a[...]

  • Page 80

    5-8 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 5 Customizing Yo ur Configuration Configuring a Remote Server for AA Step 3 Use the cd command to change to Scripts . cd /Radius/Scripts Step 4 Use the add command t o add the new script, specifying the name, descriptio n, language , filename and an optional entry point[...]

  • Page 81

    5-9 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 5 Custom izing Your Configuration Configuring a Re mote Server for AA Note Although these services dif fer in the way they handle authentication and au thorization, the procedure for conf iguring a remote serv er is the same independent of its type. F or more informatio[...]

  • Page 82

    5-10 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 5 Customizing Yo ur Configuration Configuring a Remote Server for AA Step 5 Use the set command to specify the protocol ldap : set protocol ldap Step 6 Use the set command to specify the re quired LD AP properties. At the very least you must specify: • IP Address—t[...]

  • Page 83

    5-11 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 5 Custom izing Your Configuration Configuring a Re mote Server for AA Creating Services Step 1 Run the aregcmd command: aregcmd Step 2 Use the cd command to change to the Ser vices lev el: cd /Radius/Services Step 3 Use the add command to add the appropriate LD AP se r[...]

  • Page 84

    5-12 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 5 Customizing Yo ur Configuration Configuring a Remote Server for AA T o hav e Cisco AR perform authentication and authori zation against inf ormation from the LD AP server , you must change the Def aultAuthenticationSer vice and DefaultAuth orizationService at the Rad[...]

  • Page 85

    5-13 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 5 Custom izing Your Configuration Configuring a Re mote Server for AA Figur e 5-2 Using a Scr ipt to Choose a Remote Serv er Ta b l e 5-5 provides an ov erview of the process. The foll o wing sections describe th e process in more detail. Repe at for each Rem oteServer[...]

  • Page 86

    5-14 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 5 Customizing Yo ur Configuration Configuring a Remote Server for AA Step 4 Use the cd command to change to the North RemoteServ ers lev el: cd /Radius/RemoteServ ers/North Step 5 Use the set command to specify the protocol radius : set protocol radius Step 6 Use the s[...]

  • Page 87

    5-15 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 5 Custom izing Your Configuration Configuring a Re mote Server for AA Step 7 Create another Service (SouthUse rs-ra dius) for the South remote server . Configuring the Script When you hav e multiple RemoteServers, you need a script that dete rmines the authentication a[...]

  • Page 88

    5-16 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 5 Customizing Yo ur Configuration Configuring Sessio n Management Configuring Session Management Y ou can use session management to track user ses sions, and/or alloca te dynamic resources to users for the lifetime of their sessions. Y ou can define one or more Session[...]

  • Page 89

    5-17 Installing and Configuring Cisco A ccess Registrar, 4.2 OL-17221-02 Chapter 5 Custom izing Your Configuration Configuring Session Managemen t Step 1 Run the aregcmd command: aregcmd Step 2 Use the cd command to change to the Resour ceManagers lev el: cd /Radius/ResourceManagers Step 3 Use the add command to add a ne w ResourceManager . The fol[...]

  • Page 90

    5-18 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 Chapter 5 Customizing Yo ur Configuration Configuring Sessio n Management Step 5 Use the set command to specify the ResourceManagers yo u want tracked per user session. Specify a number and the name of the Reso urceManager . N ote, you can list th e ResourceManager objects in [...]

  • Page 91

    IN-1 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 INDEX Symbols %PPP 5-3 %Telnet 5-3 /localhost 4-3 /opt/AICar1/usrb in 4-3 A Access control 4-15 Access Registrar add command 5-2 configuration valid ation 4-11 health 4-5 saving changes 5-2 system defaults 4-5 Access Registrar User’s Guide 5-1 Accounting setting up 4-13 add [...]

  • Page 92

    Index IN-2 Installing and Configuring Ci sco Access Registrar, 4.2 OL-17221-02 Configuring cl ients 4-9 Configuring UserGrou ps 5-1 count-sessions command 4-2 D DefaultAccountingSer vice 4-4 DefaultAu thenticat ionService 4-4, 5-12 DefaultAuthorization Service 4-4, 5-12 Default ports 4-6 default-PPP-users 4-9, 4-10 DefaultS essionManagm ent 4-5 Def[...]

  • Page 93

    Index IN-3 Installing and Configuring Cisc o Access Registrar, 4.2 OL-17221-02 L Launching ar egcmd 1-7 LDAP properties 5-10 server configuration 5-10 service 5-11 License file 2-1 location 1-2 local serv ice 4-6, 5-6 local-user s 4-7 login command 4-2 Login conve ntions 5-3 logout command 4-2 ls command 4-2 M Master agent stopping 4-14, 4-16 Multi[...]

  • Page 94

    Index IN-4 Installing and Configuring Ci sco Access Registrar, 4.2 OL-17221-02 S Sample users 4-7 save command 4-2, 4-11, 5-2, 5-4, 5-8, 5-12, 5-15, 5-18 Saving 4-11 Saving changes 5-2 Scripting Point 5-7 Scripts choosing loc ation 5-7 handling multipl e 5-8 send command 4-12 Server commands 4-2 Server health 4-5 Server virtualization 2-6 Service t[...]