data:image/s3,"s3://crabby-images/63ee4/63ee43318eb5d075ebf6dcdf06f981140c0516a3" alt="基础tacacs+及raduis实验_第1张图片"
Setp 1.路由器基本配置
r1(config)#show ip int b
Interface
IP-Address OK? Method Status Protocol
FastEthernet0/0
192.168.1.254 YES manual up up
FastEthernet1/0
192.168.10.254 YES manual up up
r1(config)#exit
r1#ping 192.168.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 20/53/76 ms
r1#ping 192.168.10.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.10.1, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 40/67/96 ms
r2#show ip int b
Interface
IP-Address OK? Method Status Protocol
FastEthernet0/0
192.168.1.253 YES manual up up
FastEthernet1/0
192.168.10.253 YES manual up up
r2#ping 192.168.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 28/47/72 ms
r2#ping 192.168.10.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.10.1, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 36/42/48 ms
Setp 2.ACS基本配置
1.安装AD-benet.com
data:image/s3,"s3://crabby-images/4b463/4b4635eb78faa7a622b2f69573aa1657db43e6ed" alt=""
2.安装ACS(必需安装java)
data:image/s3,"s3://crabby-images/944d3/944d332ec1a4b953eb7e8ffc1c1d9e5ffe432512" alt=""
3.调整IE安全级别
data:image/s3,"s3://crabby-images/20ae0/20ae00dbc2555eac88fe5fc15376298afa8afbad" alt=""
4.在AD中创建相应的OU、组、用户。其中hw用于raduis 、cisco用于tacacs+
data:image/s3,"s3://crabby-images/751a2/751a268a5192295535d830f6df314db462b3b5f2" alt=""
5.勾选network device groups显示相应界面
data:image/s3,"s3://crabby-images/12d8f/12d8f1d59ce63d635d8e9b4bd5194785fc2d071b" alt=""
6.定义tacacs+ 及raduis 客户端及服务器信息
data:image/s3,"s3://crabby-images/8a631/8a631c8d4da8f3696816319be082ee0deb2afcce" alt=""
data:image/s3,"s3://crabby-images/d4a8f/d4a8f54f92d25c2e424c4c49ad57e29e01db8fea" alt=""
data:image/s3,"s3://crabby-images/cee7e/cee7e6d3e5ae80eef3652825ef86baf4cd7d98cd" alt=""
7.AD组及ACS组关联
data:image/s3,"s3://crabby-images/ea9ad/ea9adbcacc1935aba36521bd3d5e583b9c03e6ee" alt=""
.8. 重新启动服务
data:image/s3,"s3://crabby-images/3b53a/3b53ac4eb4db2cd62b6b7d270b82f41cf1fdb917" alt=""
Setp 3.测试PC基本配置
data:image/s3,"s3://crabby-images/d95cc/d95cc867ae899f4825d8627f8c181e93a44c42c4" alt=""
Setp 4.R1做为tacacs+客户端配置及测试
r1(config)#aaa new-model
r1(config)#tacacs-server host 192.168.10.1 key cisco
r1(config)#aaa authentication login cisco group tacacs+ local
r1(config)#line vty 0 4
r1(config-line)#login authentication cisco
r1(config-line)#exit
r1(config)#exit
r1#test aaa group tacacs+ cisco 1 new-code
Trying to authenticate with Servergroup tacacs+
Sending password
User successfully authenticated
data:image/s3,"s3://crabby-images/11a15/11a1519ea8abd9e44b69b9805c95376a7b275486" alt=""
Setp 5.R2做为raduis客户端配置及测试
r2(config)#aaa new-model
r2(config)#radius-server host 192.168.10.1 key cisco
r2(config)#aaa authentication login cisco group radius local
r2(config)#line vty 0 4
r2(config-line)#login authentication cisco
r2(config-line)#exit
r2(config)#exit
r2#test aaa group radius hw 1 new-code
Trying to authenticate with Servergroup radius
User successfully authenticated
data:image/s3,"s3://crabby-images/86a13/86a13ac45555781425eee66191de84db2e5bdc99" alt=""
Setp 6 ACS 用户验证及ebable密码
1.路由器启用enabe密码认证
r1(config)#aaa authentication enable default group tacacs+ enable
2.在ACS上新建用户A设置login及enable密码
data:image/s3,"s3://crabby-images/10ac3/10ac36298977c1ba7ffaac6bf3696cc5cae580bf" alt=""
data:image/s3,"s3://crabby-images/2eae4/2eae47ce666270e2015ef668e159feb94bdd3873" alt=""
3.PC登入R1测试
data:image/s3,"s3://crabby-images/7ead2/7ead25ca1c052a3b05161f301ed2ef2aaae799ff" alt=""
setp 7 级别授权
1.路由器启用级别授权及测试失败结果图
r1(config)#aaa authorization exec default group tacacs+ local
data:image/s3,"s3://crabby-images/afae8/afae8050d06169b7b1b6183c73084fa91703265e" alt=""
2.ACS进行级别授权
data:image/s3,"s3://crabby-images/11627/11627ad9f9549ba46ecf178b46b9fbfbb688b9a0" alt=""
3.登入R1测试成功
data:image/s3,"s3://crabby-images/e14bc/e14bce8b11a3cd200fe87d381453d902228dc132" alt=""
Setp 8 15级别命令授权
1.R1上启用命令授权
r1(config)#aaa authorization commands 15 default group tacacs+ local
2.ACS上面没做配置之前测试结果图
data:image/s3,"s3://crabby-images/34c09/34c0943fe4ebe04a38598bf77b5e9c322713c44e" alt=""
3.ACS配置命令授权
data:image/s3,"s3://crabby-images/a1f5d/a1f5d89fe31bf060132d0ccde49da3ce1f32a37d" alt=""
4.登入测试,只能使用指定命令
data:image/s3,"s3://crabby-images/fe787/fe787cc193bdcccadc234d7dc6a209f111b8cc42" alt=""
Setp 10 审计
1.R1路由器审计所有级别配置
r1(config)#no aaa authorization commands 15 default group tacacs+ local
r1(config)#aaa accounting commands 15 default start-stop group tacacs+
r1(config)#aaa accounting commands 1 default start-stop group tacacs+
r1(config)#aaa accounting commands 0 default start-stop group tacacs+
r1(config)#aaa accounting commands 2 default start-stop group tacacs+
2.telnet R1测试输入部分命令
data:image/s3,"s3://crabby-images/102e1/102e17285b6d0f44c8950689b8ca561bc1761214" alt=""
3.ACS查看审计结果图
data:image/s3,"s3://crabby-images/8340b/8340b9127c96cd3380e7e8993679330808d31d5d" alt=""
实验总结:
R1采用ACS -tacacs+认证授权审计.
1. 认证调用AD-ciscogroup组里Cisco用户进行login认证.AD-Cisco用户enable密码实验没有做成功(在ACS上新建用户a来做enable认证),没有找出原因.
2. 在Tacacs+上对AD用户cisco进行级别和命令授权.
3. 在Tacacs+上对级别0\1\2\15级别命令进行审计
R2采用ACS-raduis认证
1. 认证周用AD-hwgroup组里hw进行login认证