22.05.2017 Views

nx.os.and.cisco.nexus.switching.2nd.edition.1587143046

Nexus Switching 2nd Edition

Nexus Switching 2nd Edition

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

NX7k-SGA(config)# cts device-id NX7k-SGA password<br />

CTS_TrustSec123<br />

To enable 802.1x <strong>and</strong> CTS features on the NX-OS device for CTS support on NX7k-SGA,<br />

enter the following comm<strong>and</strong>s:<br />

NX7k-SGA# conf t<br />

NX7k-SGA (config)# feature dot1x<br />

NX7k-SGA (config)# feature cts<br />

To verify that 802.1x <strong>and</strong> CTS features are enabled, enter the following comm<strong>and</strong>:<br />

NX7k-SGA # show run cts<br />

feature dot1x<br />

feature cts<br />

Configuring AAA for Cisco TrustSec<br />

You can use Cisco Secure ACS for Cisco TrustSec authentication. You must configure<br />

RADIUS server groups <strong>and</strong> specify the default AAA authentication <strong>and</strong> authorization<br />

methods on one of the Cisco TrustSec-enabled Cisco NX-OS devices in your network<br />

cloud. Because Cisco TrustSec supports RADIUS relay, you need to configure AAA only on<br />

a seed Cisco NX-OS device that is directly connected to a Cisco Secure ACS. For all the<br />

other Cisco TrustSec-enabled Cisco NX-OS devices, Cisco TrustSec automatically<br />

provides a private AAA server group, aaa-private-sg. The seed devices use the management<br />

VRF to communicate with the Cisco Secure ACS.<br />

Note<br />

Only the Cisco Secure ACS or the Cisco Identity Services Engine (ISE) supports<br />

Cisco TrustSec.<br />

Example 5-24 shows how to configure a RADIUS server h<strong>os</strong>t with a key <strong>and</strong> proxy autoconfig<br />

(PAC) file on NX7k-SGA.<br />

Example 5-24. Configuring the RADIUS Server H<strong>os</strong>t with a Key <strong>and</strong> PAC on NX7k-<br />

SGA<br />

Click here to view code image<br />

NX7k-SGA # conf t<br />

NX7k-SGA (config)# radius-server h<strong>os</strong>t 10.1.100.3 key<br />

TrustSec123 pac<br />

! Specifying the RADIUS server group <strong>and</strong> enter RADIUS<br />

server group configuration<br />

mode on NX7k-SGA

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!