Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-12-05 Thread luismi
We are using tac_plus over ubuntu and it is ok for us. Take a look El jue, 20-11-2008 a las 08:30 -0900, Tom Simes escribió: > Hi all, > > We've got an aging Cisco Secure ACS install on the Windows platform > and we're looking for alternatives. We're only using TACACS+ for admin > authentication

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-25 Thread Laurent Geyer
On Tue, Nov 25, 2008 at 10:32 AM, Teller, Robert <[EMAIL PROTECTED]>wrote: > I am using radius and Microsoft's IAS server and that works just fine. > Radius works fine for authentication, but how are you handling accounting? - Laurent ___ cisco-nsp mai

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-25 Thread Christian Koch
my problem is the normal "#enable = 15" does not work for catos as it does with IOS in the later tac_plus software as it did in the earlier developed versions On Mon, Nov 24, 2008 at 11:27 AM, raymondh (NSP) <[EMAIL PROTECTED]> wrote: > You'll just need to fix your expressions in your tacacs co

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-25 Thread Teller, Robert
I am using radius and Microsoft's IAS server and that works just fine. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Yuval Ben Ari Sent: Monday, November 24, 2008 11:48 AM To: Tom Simes Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] Alternativ

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-24 Thread Yuval Ben Ari
Hi Tom, You did not mention your requirements like does it need to be GUI based or is conf file based is ok (tac_plus)? Also what is the reason you want to abandon the ACS? I'm asking because we actually migrated from tac_plus to ACS due to the improved management capabilities via GUI. I think the

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-24 Thread raymondh (NSP)
You'll just need to fix your expressions in your tacacs config. e.g. cmd = set { permit "^blah blah .*" } --raymondh On Nov 25, 2008, at 12:16 AM, Christian Koch wrote: Rich- thanks and sorry i guess i was a little vague... i meant to say i am looking for configuration for the tac_plus.con

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-24 Thread Rich Davies
Here is an example CatOS config for TACACS auth. It's been awhile since I used a CatOS device however if I remember correctly this config was structured so that if the device can't talk to the TACACS server it would fail back to a local userid (by using "if-authenticated" in the #authorization sec

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-24 Thread Christian Koch
Rich- thanks and sorry i guess i was a little vague... i meant to say i am looking for configuration for the tac_plus.conf side On Mon, Nov 24, 2008 at 11:02 AM, Rich Davies <[EMAIL PROTECTED]> wrote: > Here is an example CatOS config for TACACS auth. It's been awhile since I > used a CatOS devi

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-24 Thread Christian Koch
on a side note - has anyone had any success getting older catos switches and enable mode to work with the newer versions of tacplus? christian On Mon, Nov 24, 2008 at 10:41 AM, <[EMAIL PROTECTED]> wrote: > Hi, > >> The fork based on Cisco's code over at shrubbery has worked out well for me. >>

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-24 Thread A . L . M . Buxey
Hi, > The fork based on Cisco's code over at shrubbery has worked out well for me. > > > http://www.shrubbery.net/tac_plus/ agreed. also note, theres been hints of TACACS+ being part of future FreeRADIUS capability for some time too. alan ___ cisco-n

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-20 Thread Chris Marlatt
Laurent Geyer wrote: > On Thu, Nov 20, 2008 at 12:30 PM, Tom Simes <[EMAIL PROTECTED]> wrote: > >> What are folks using these days for a TACACS+ server that they're happy >> with? >> TIA! >> >> Tom > > > The fork based on Cisco's code over at shrubbery has worked out well for me. > > > http://

Re: [c-nsp] Alternatives to Cisco's TACACS server?

2008-11-20 Thread Laurent Geyer
On Thu, Nov 20, 2008 at 12:30 PM, Tom Simes <[EMAIL PROTECTED]> wrote: > > What are folks using these days for a TACACS+ server that they're happy > with? > TIA! > > Tom The fork based on Cisco's code over at shrubbery has worked out well for me. http://www.shrubbery.net/tac_plus/ Cheers, La

[c-nsp] Alternatives to Cisco's TACACS server?

2008-11-20 Thread Tom Simes
Hi all, We've got an aging Cisco Secure ACS install on the Windows platform and we're looking for alternatives. We're only using TACACS+ for admin authentication into our Cisco gear (not RADIUS), but we do have a variety of groups defined with differing access to commands and equipment and our u