Cisco AAA login authentication with Radius (MS IAS)

1) Configure IAS

Click “Start>Programs>Administrative Tools>Internet Authentication Service”

*** Create Remote access Policy ***

Select “Remote Access Policies”
(right pane) Delete all policies
(right pane) Right-Click and Select “New Remote Access Policy”
Click “Next” Select “Set up a custom policy” and give it a name
Click “Next”
Click “Add”
Select “Windows Groups”
Click “Add” Type “Domain Admins” (or any other group you would like to use)
Click “Ok”
Click “Next”
Select “Grant remote access permission”
Click “Next”
Click “Edit Profile”
Select the “Authentication” tab
Select “Unencrypted Authentication” only
Select the “Advanced” tab
Change the service-type from “framed” to “login”
Delete “Framed-Protocol” Click “Add”
Select “Vendor Specific” Click “Add”
Select “Cisco” from the drop-down box
Select “Yes. It conforms” Click “Configure Attribute”
Change Attribute Number to “1”
Set the Attribute Format to “String”
Type “shell:priv-lvl=15” in the Attribute Value field
Click “Ok”
Click “Ok”
Click “Close”
Click “Next”
Click “Finish”

*** Add Radius Clients ***

Click “RADIUS Clients”
Right-Click and click “New Radius Client”
Give the client a friendly name and enter the ip address
Click “Next”
Enter a shared secret password
Click “Finish”

=========================================
3) Configure Cisco Device
=========================================

*** IOS Configuration ***


aaa new-model
radius-server host 192.168.10.100 key P@ssw0rd
ip radius source-interface f0/0
aaa authentication login default group radius
!
local line vty 0 4
login authentication default


*** PIX Configuration ***

username blindhog password Raz0rb4ck

aaa-server RADIUS (inside) host 192.168.10.100 P@ssw0rd
aaa-server LOCAL protocol local

aaa authentication ssh console RADIUS LOCAL
aaa authentication telnet console RADIUS LOCAL