Re: [c-nsp] Router 2 factor authentication

2010-08-26 Thread Mark Tech
- Original Message From: Dominik Bay d@rrbone-bb.net To: cisco-nsp@puck.nether.net Sent: Thu, August 26, 2010 6:28:22 AM Subject: Re: [c-nsp] Router 2 factor authentication On Thu, 26 Aug 2010 10:42:28 +1000 Ben Steele b...@bensteele.org wrote: Out of curiosity can you tell me what led

Re: [c-nsp] Router 2 factor authentication

2010-08-26 Thread Dominik Bay
Hi Mark, On Thu, 26 Aug 2010 01:45:17 -0700 (PDT) Mark Tech techcon...@yahoo.com wrote: Hi Dominik Your solution sounds like what I'm looking for. Are you using RADIUS or TACACS as your AAA? With regard to the cli that you will see from the router, do you just enter username and

Re: [c-nsp] Router 2 factor authentication

2010-08-26 Thread John Kougoulos
we are using Cisco ACS with RSA ACE integration for these devices. You will get a standard prompt like: TACACS+ Username: myuser Password: token-pin+token-one-time-password The login is fast, and from what I hear the ACS+ACE setup is stable enough to not being punished by your server

Re: [c-nsp] Router 2 factor authentication

2010-08-26 Thread Tim Franklin
The problem, IMHO, with SecurID for management access of network devices, is that you have to wait 1 minute to logon to another device. So it's ok for provisioning tasks, but when you have a problem and you need to login instantly to 4-5 devices, it's rather unpleasant to wait 1 minute

[c-nsp] Router 2 factor authentication

2010-08-25 Thread Mark Tech
Hi I am looking for a 2FA solution in order to connect to Cisco devices. I would like to use either Radius or TACACS as the AAA part, however I'd like to know whether/how I could interconnect this to a 2nd auth such as a token based RSA securID platform I'd appreciate any input if this is

Re: [c-nsp] Router 2 factor authentication

2010-08-25 Thread Heath Jones
How about users appending the token digits to the password? Of course this would mean your storing plain text passwords on the tacacs server somewhere.. On 25 August 2010 21:06, Mark Tech techcon...@yahoo.com wrote: Hi I am looking for a 2FA solution in order to connect to Cisco devices. I

Re: [c-nsp] Router 2 factor authentication

2010-08-25 Thread Chris Mason
I am looking for a 2FA solution in order to connect to Cisco devices. I would like to use either Radius or TACACS as the AAA part, however I'd like to know whether/how I could interconnect this to a 2nd auth such as a token based RSA securID platform I'd appreciate any input if this is

Re: [c-nsp] Router 2 factor authentication

2010-08-25 Thread Daniel Roesen
On Wed, Aug 25, 2010 at 01:06:24PM -0700, Mark Tech wrote: I am looking for a 2FA solution in order to connect to Cisco devices. I would like to use either Radius or TACACS as the AAA part, however I'd like to know whether/how I could interconnect this to a 2nd auth such as a token based RSA

Re: [c-nsp] Router 2 factor authentication

2010-08-25 Thread Michael K. Smith - Adhost
Hello Mark: -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- boun...@puck.nether.net] On Behalf Of Mark Tech Sent: Wednesday, August 25, 2010 1:06 PM To: cisco-nsp@puck.nether.net Subject: [c-nsp] Router 2 factor authentication Hi I am looking

Re: [c-nsp] Router 2 factor authentication

2010-08-25 Thread Ben Steele
Out of curiosity can you tell me what led you to wanting 2FA for these devices, and how the traditional acl/tacacs method failed your requirements? Of course anyone who has implemented it is free to chime in, just generally interested in peoples security concerns around this and how you feel it

Re: [c-nsp] Router 2 factor authentication

2010-08-25 Thread Michael K. Smith - Adhost
Hello Ben: -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- boun...@puck.nether.net] On Behalf Of Ben Steele Sent: Wednesday, August 25, 2010 5:42 PM To: Mark Tech Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] Router 2 factor authentication Out

Re: [c-nsp] Router 2 factor authentication

2010-08-25 Thread Dominik Bay
On Thu, 26 Aug 2010 10:42:28 +1000 Ben Steele b...@bensteele.org wrote: Out of curiosity can you tell me what led you to wanting 2FA for these devices, and how the traditional acl/tacacs method failed your requirements? We are using RSA SecurID on P and PE Routers to secure the core network