How to configure ACS 5.2 to manage the Junos 10.4R6.5 fwl via GANYMEDE.

Hi all

I have a camera ACS 5.2 newly installed, integrated with our announcement and his work with cisco product, routers switches and etc.  Now I would like to include Juniper firewalls so to be authenticated via ACS 5.2 either via ssh and web access.  Can someone share me how to initiate this, creating policies.

FYI: I have 14:00 groups regionaladm and regionalops, read/write and read-access, respectively.

Kind regards

Marlon

Marlon,

I stuck in a config below file I made for our ScreenOS Firewall work with Cisco ACS v5.2.  This configuration may not work because yours is Junos, but it could bring closer you reach to understand.  Also, if you have not been on the Juniper J-Net ask autour, give it a shot. (forums.juniper.net)

Good luck!

-Chris

Title: Example configuration - GSU of Juniper and Cisco ACS v5.x

Product: SSG320M juniper (Cisco ACS v5.x)

Version: 6.3.0r10.0 ScreenOS (Cisco ACS v5.2.0.26.8)

Network topology:

[Juniper SSG320M]-[Cisco 3560 Switch]-[Cisco ACS VM]

Description:

Goal - authenticate GSU administrators using GANYMEDE + instead of local connections

Description - This configuration for Cisco ACS v5.x, JTACS had only configuration v3.3.

ACS v5.x is a VM based on Linux with a completely new user interface and structure.

Configuration:

Configure the Juniper (CLI)

1. Add configuration Cisco ACS and GANYMEDE +.

Set id CiscoACSv5 of auth-server 1
set the auth-CiscoACSv5 server ServerName 192.168.1.100
set server CiscoACSv5-type of admin account
set the server CiscoACSv5 auth type Ganymede
Define auth-server CiscoACSv5 Ganymede secret CiscoACSv5
define CiscoACSv5 Ganymede 49 auth-server port
Set the server auth admin CiscoACSv5
Set admin auth distance primary
Remote admin auth root set
define outer-get administrator privileges

Configure the Cisco ACS (GUI) v5.x
1. navigate to elements of strategy > authorization and permissions > peripheral Administration > Shell profiles
Create the profile of Shell of Juniper.
Click the button [create] at the bottom of the page
Select the general tab
Name: Juniper
Description: Custom for Juniper SSG320M attributes
Select the custom attributes

Add the vsys attribute:
Attribute: vsys
Requirement: required
Value: root
Click on the [Add ^] button above the field for the attribute

Add the attribute of privilege :

Attribute: privilege
Requirement: required
Value: root

Note : you can also use "read-write", but then the local admin does not work correctly
Click on the [Add ^] button above the field for the attribute
Click the button [send] at the bottom of the page

2. navigate to access policies > Access Services > default device Admin > authorization
Create the authorization policy of Juniper and filter by IP address.
Click [customize] at the bottom right of the page
In terms of customize, select IP address in the left window
Click the [>] button to add
Click the [OK] button to close the window

Click the button [create] at the bottom of the page to create a new rule
In general, the name of the new rule Juniper and make sure that this option is enabled
In Conditions, check the box next to IP address
Enter the ip address of the Juniper (192.168.1.100)
Under results, click the [Select] button next to the Shell profile field
Select "Juniper" and click the [OK] button
Under results, click the [Select] button under the command field sets (if used)
Select "allow all the" and make sure all other boxes are not CHECKED
Click the [OK] button to close the window
Click the [OK] button at the bottom of the page to close the window
Check the box next to the policy of Juniper , and then move the policy to the top of the list
Click on the [Save] button at the bottom of the page

Audit:

Connect to the CLI of Juniper and GUI using an ACS internal user account and try to change something to check the level of privilege.

Tags: Cisco Security

Similar Questions

  • How to configure an application automatically starts when the unit is turned on

    I used the instructions in:

    How to-configure an application automatically starts when the unit is turned on

    Article number: DB-00002

    1. - in the BlackBerry JDE, right click on the project and select Properties.
    2. - in the Application tab, check the function of automatic execution on startup checkbox.
    3. - If you want your application to run in the background and not appear on the Ribbon, select the Module system.

    My application starts automatically in debugging, but not in my BB8100 pearl.

    Any ideas? THX...

    If you are looking for in the unit LOG immediately after startup, you should find out the reason.  I suggest to you that what follows is the most likely reasons:

    (a) application not signed

    (b) developed for a different level than the device OS.

  • How to configure nested ESXi 5 to take the EVC Clusters supported

    Can someone give me instructions on how to configure nested ESXi 5 Support EVC clusters help please?

    Thank you

    JOhn

    Please follow: how to configure nested ESXi 5 to the EVC Clusters of support | virtuallyGhetto

  • How Camera Raw and various profiles to manage the Transition to overexposure

    With all the attention that I had to pay to profiles lately, I've been opening many images with colors vivid blue (where my recent post on trying to get better blue color).

    One of the things I noticed is that the transition to overexposure seems to be treated VERY differently depending on the chosen profile.

    Of particular interest is an image that I shot recently to a stage where some blue lights shone on the crowd and in the goal of my Canon EOS - 40 d of.  I was surprised how differently the transition towards overexposure is based on the chosen profile.

    Not including one of the profiles provided by Adobe manages this transition smoothly at all, showing a few transitions strong - which explains why I had so much trouble with the color of the sky.

    Some examples follow (they have all been converted to sRGB for viewing through a browser).  Specifically, note the area around the blue light at the top right.

    Adobe Standard profile such that supplied with Camera Raw by Adobe:

    AdobeStandardProfileBlueOverexposure.jpg

    Camera Standard profile such that supplied with Camera Raw by Adobe:

    CameraStandardProfileBlueOverexposure.jpg

    Profile of landscape of camera, like that provided with Camera Raw by Adobe:

    CameraLandscapeProfileBlueOverexposure.jpg

    Very good 40 d profile "sRGB Standard of the DPP" Vit Novak gave me a few days earlier, based on measures of how Canon DPP manages the colors:

    VitNovak40DProfileBlueOverexposure.jpg

    The format of JPEG in camera:

    InCameraJPEGBlueOverexposure.jpg

    -Christmas

    This change in color when blue/cyan is intentional, also because blown blue colors are rendered around 190 degrees tinted sRGB, so transition should be smooth. But in the case of sRGB profile, it's suddenly somewhere near half of LUT (according to saturation), where the nonlinear values sRGB reached 1, while Adobe RGB, it is much more smooth. Looks like it's cut into sRGB

    About highlights and possible appearance of the hard core it's the Canon seems a built-in LUT that extends above the 1 brightness value, in order to cover the sensor output after whitebalancing, where R and B can be greater than 1 (because the R and B channels is less sensitive and they are multiplied with WB R and B multipliers). DNG profiles do not offer this capability - above 1 everything is cut prior to calculation of LUT, so I adjusted the calibration for the different process, but it can not be handled properly. So whatever I do, it won't be the same in this region (and there may be additional logic in the camera). But ACR has recovery slider, which compresses the upper region to fit into the LUT

    This topic is quite complex, really

  • How 2 Configure ACS 4.2 to delegate authentication to the radius server

    Hello

    We need run the following scenario:

    Cisco VPN client (or any connect, Cisco SSL VPN client)---> Cisco ASA 5520---> Cisco ACS 4.2---> CAT Authentication Server

    The CAT authentication server is a Radius server. It can receive Radius authentication requests and respond. It is used for strong authentication TFA WBS similar to RSA OTP tokens.

    The question is: how we set up the 4.2 ACS to delegate authentication request to another Radius server.

    Thnx

    Add the RSA server as an external database, configure the drop user profile or a group to authenticate on the new external database rather than ACS DB Local (or Windows DB).

    Easy as pie!

    Please rate if this is useful.

  • How to configure ACS 4 with 802. 1 X

    Hay

    How to set up my ACS server to support 802. 1 X with PEAP.in to authenticate the me (PC).

    Thank you initially

    You can skip the part of the certificate.

  • How have use ACS supported wireless users and the VPN user?

    I'm new to ACS and configure the following requirement:

    (1) ACS to authenticate users wireless with window AD.

    (2) once connected successfully to the radio, the user must use VPN for remote access with the ASA.

    (3) the end-user will have only 1 common username but different password.

    for example:

    username: password: cisco: cisco wireless.

    username: cisco password: 1234 for VPN.

    ACS support can this, if yes how can we do? Do I need 2 sets of ACS?

    Yes, acs should work properly according to your need.

    ACS, we have a feature called NAP "network access profile" where we can define the condition based on ip source or attributes which allow to say if the request comes from wireless device acs will forward to AD and if the request is of the acs VPN will forward to this diff of database.

    Basically, we need to use two acs database.

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/NAPs.html

    Kind regards

    ~ JG

    Note the useful messages

  • 5.2 ACS using ad to manage the creation of strategies of network device Admin

    Hi all

    Need to light here, we were able to integrate our newly installed ACS 5.2 in our regional area.  now I create an Admin Access political device for the regional network administrator group and regional network operators. each with full and reading access respectively.

    I already have the default identity policy and authorization with order policy defines fullaccess and showonly for each group, now I don't know how can I match the AD Group regionaladm and regionalops so that each user is part of one of these groups will have a proper read/write access.

    Kind regards

    Marlon

    You need start adding rules to the authorization policy

    Reach

    Access policies > access > default device Admin > authorization

    Press 'Customize' and make groups of AD1: External a condition select and press OK

    You can now make rules based on the content of the AD groups

    Tap on create and check the option AD1 groups: External and now can now enter the groups that you want to check for access

    Note all of the groups can be selected is defined in

    Users and identity stores > external identity stores > Active Directory

    Only the groups selected here are available in politics

  • How to configure Windows 7 to automatically install the drivers, mine is set to never install drivers.

    Ineed to install an audio driver, when I go to do this, I get a message that says my computer / Win 7 is configured to never install drivers. How to change that?

    You don't want to automatically install drivers from Windows Update or another source.

    If you want to update the drivers, do it manually and get them directly from the device manufacturer websites.

    Do NOT use the finders of pilot no more...

  • How to configure details WorkRepository to them in the console of the ODI. ?

    Hello world

    I freshly created some interfaces in ODI studio in two repositories named: WorkRep_1 and WorkRep_test and interface test_1 in WorkRep_1 and test_2 in WorkRep_test.
    Yet after configured WorkRepositories in the Console of the ODI.

    WorkRep_1:

    WORKREP_1
    JDBC/odiMasterRepository
    SUPERVISOR
    JDBC/odiWorkRepository

    WorkRep_test:

    WORKREP_Test
    JDBC/odiMasterRepository
    SUPERVISOR
    JDBC/odiWorkRepository

    I am getting same interface in two repositories when opened in console with different repositories, please help me.

    Thank you

    Shakur.

    Hello

    As you can see in both cases, you specified jdbc/odiWorkRepository as URL JNDI to work while you get connected to a deposit in both cases. If the steps you must follow to create Console ODI connections for two repositories:

    1. create a new JNDI with the details of the schema of data base for WORKREP_Test, targeting for your managed server where you have deployed your odiconsole.

    2. then, you configure a connection of repository odiconsole to WORKREP_Test mentioning the JNDI newly created for your WORKREP_Test.

    Steps to create the new JNDI:

    To create a JNDI, connect to the Weblogic administration Console > go to Services (on the left panel) > Data Sources

    You will see the list of configured JNDI names already. You must add one more favorite JNDI for your schema repository work connection. You can reference existing repository work connection JNDI (odiWorkRepository) for the sample of the parameters values.

    Thank you

    Parag

  • I'm new on this. How can I get player OSMF to manage the RTMP stream? It is not in the docs.

    Hi all

    I want to stream RTMP or RTMPE using the OSMF player on my site and said the using_fmp_smp_post1.0.pdf of the file this reader can be configured for RTMP, NOWHERE in this file, it tells how. Keep in mind, not all of us are software engineers. Some of us save every penny to buy software like FMIS (which I did) and I want to use OSMF player to deliver the goods.

    Then...

    Tell us HOW to put back the screw RTMP goods!

    Please, I beg you.

    See you soon,.

    wordman

    This forum out this media link by adding space to the break.

    Remove the file name space and it works on the Configurator page.

    This:

    Sylvie ai_10_year_500.mov

    Must be:

    akamai_10_year_500.mov

    Post your own RTMP here link if you want to try that too.

  • Windows Vista: how to configure windows Security Center to stop the status of the antivirus monituring

    I use Bit Defender and Windows Security Center keeps locking things up through anti-virus and anti-spyware monituring and Bit Defender is on for it to not recognize (that is - I checked). Verification of reliability and said performance "setting up windows Security Center to stop monituring" them. How can I do this?

    http://Windows.Microsoft.com/en-us/Windows-Vista/using-Windows-Security-Center

  • How Windows 7 ULT is supposed to manage the JPEG2000 files?

    I try to open and view a JPEG2000 file in Windows 7 in the last month

    V12 for Windows Media Player does not open a JPEG2000 file.

    I then downloaded a plugin for the "GIMP 2.6.11" image editing application, but I get a failure message when I try to open a JPEG2000 image like this.

    Then I did a search for a visualization of JPEG2000 application and I found 'Image Access Solutions Viewer 3.1', which seems to be a SUN/JAVA based app by the look of the icon of the application, but this app, after successful installation, gives this message when I try to open a JPEG2000 file... "Initialization error - unable to locate all the DLLs. Shutting down. Native Library C:\Program Files\Java\jre6\bin\msvcr71.dll already loaded into an another ClassLoader".

    But there is no other applications running that has that "msvcr71.dll" file loaded, and the error message is contradicting himself by saying first that he cannot locate all the required DLLs, then indicates that the msvcr71.dll file is already running in another charger 'class '.

    How should Windows 7 being manipulate JPEG2000 files natively?... This is a relatively common format today which is used in many ways.

    Thanks for any help,

    NuMetro

    Try the free software IrfanView:

    (FWIW... it's always a good idea to create a system)
    Restore point before installing software or updates)

    IrfanView and IrfanView plugins
    http://www.download.HR/download-IrfanView.html
    (Download plugins too)

  • How to configure widget menu mobile slider on the master and the mobile Muse Web site pages

    Adobe Muse slider Mobile Menu Widget by MuseThemes

    I am new to the design of mobile websites and Muse, I love this widget, but I don't know how to set up on several pages.

    Should I put it on the master? Content covers it when it is the master, I can use some help.

    Thank you very much, anyone knows of tutorials or can someone give me a game plan to be implemented. Thank you very much!

    Yes, the site shows a mobile version, otherwise you can try emulators to display different version of your site:

    https://www.browserstack.com/

    Thank you

    Sanjit

  • How to configure applications 'Find my iPhone' on the Apple Watch of fallback to iCloud, when the bluetooth connection is interrupted?

    It would be ideal if applications of "Find my iPhone" Apple Watch can be redirected via iCloud when the watch is connected to wifi, but the bluetooth with the phone connection is lost.

    Ongoing enforcement watch OS 2.1, coupled with the iPhone 6 more (iOS 9.2). Thank you!

    Hello

    The feature you described is not currently available on Apple Watch.

    It is a community of support based on the user, but if you want to suggest that Apple considers adding that as a new feature, you can do so here:

    https://www.Apple.com/feedback/watch.html

    All submissions are read (even if you do not expect to receive a response).

Maybe you are looking for

  • HP f800g memory problem

    I have a HP f800g camera car and I use a mikrosdxs I have 10 64GB kingston.It assumes that the standard loop recording technology prevents the storage overhead by deleting the oldest previously saved file and its replacement by a new, but after a few

  • constant path block

    When I copy and paste a path from the Windows Explorer in teststand as a constant, I should add an extra "-" in front of all the "------" manually.  Is there a faster way?  Thank you!

  • RedHat Linux on Ts140

    Hello I would like to buy a server TS140. Can I run/install RedHat Linux on this server?

  • Adding a Cache of SSD drive for my laptop

    I posted earlier about this and got a response from Hüffer... Maybe I misunderstood, but installing the msata ssd is proving to be more complex and more complex that I read in response to Hüffer. When I install the SSD and start the system, I not giv

  • Cannot read Psychonauts off Steam error - the game could not create the Direct3d device. Please make sure your video drivers are installed properly

    Original title: Running Win7 on Bootcamp. Error: The game could not create the Direct3d device. Please make sure your video drivers are installed properly. I try to play Psychonauts out of steam. I am currently running Windows 7 via Bootcamp on my Ma