06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>User</strong>-Defined RADIUS Vendors and VSA Sets<br />

C-20<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Appendix C CSUtil Database Utility<br />

Note ACS supports hex-numbering <strong>for</strong> the VSA ID feature. Values starting with 0x are assumed to be hex<br />

values.<br />

Use the following sample <strong>for</strong>mat of the vendor .ini file <strong>for</strong> setting the ID length and VSA values. In this<br />

example the,<br />

Need Internal Length value is TRUE.<br />

ID Length is two bytes.<br />

vendor VSA ID values are 264 and 0x109.<br />

[<strong>User</strong> Defined Vendor]<br />

Name=vendor-name<br />

IETF Code=vendor-IETF-code<br />

Need Internal Length = TRUE<br />

ID Length=2<br />

VSA 264=Ascend-Max-RTP-Delay<br />

VSA 0x109= Ascend-RTP-Port-Range<br />

[Ascend-Max-RTP-Delay]<br />

Type=INTEGER<br />

Profile=OUT<br />

[Ascend-RTP-Port-Range]<br />

Type=STRING<br />

Profile=OUT<br />

Deleting a Custom RADIUS Vendor and VSA Set<br />

You can use the -delUDV option to delete a custom RADIUS vendor from ACS.<br />

Note While CSUtil.exe deletes a custom RADIUS vendor from ACS, all ACS services are automatically<br />

stopped and restarted. No users are authenticated while this process is occurring.<br />

Be<strong>for</strong>e You Begin<br />

Verify that, in the Network Configuration section of the ACS web interface, no AAA client uses the<br />

RADIUS vendor. For more in<strong>for</strong>mation about configuring AAA clients, see Configuring AAA Clients,<br />

page 3-8.<br />

Verify that your RADIUS accounting log does not contain attributes from the RADIUS vendor that you<br />

want to delete. For more in<strong>for</strong>mation about configuring your RADIUS accounting log, see Configuring<br />

ACS Logs, page 10-22.<br />

To delete a custom RADIUS vendor and VSA set from ACS:<br />

Step 1 On the computer that is running ACS, open an MS-DOS command prompt and change directories to the<br />

directory containing CSUtil.exe. For more in<strong>for</strong>mation about the location of CSUtil.exe, see Location<br />

of CSUtil.exe and Related Files, page C-2.<br />

OL-14386-02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!