Home  
  Microsoft  
  Cisco  
  CompTIA  
  CWNP  
  InfoSecurity  
  Forums  
  Blogs  
  Topsites  
  Watch free videos online  
     
  Subnet Calculator  
  Online Degrees  
  Exam Vouchers  
  Free Magazines  
     

  Watch free videos online  
   

 

Register Practice Exams TechNotes Members List Search Today's Posts Mark Forums Read
Go Back   TechExams.net IT Certification Forums > Cisco > CCNP
Reply
 
Thread Tools
Member
Registered Member
 
Join Date: Apr 2009
Posts: 65

marcusaureliusbrutus is on a distinguished road
Old 07-07-2009, 01:44 AM   #1 (permalink)
Default aaa with chap

Hi. I have configured a windows server as my NAS and my cisco devices to use aaa when logging in to the routers/switches. I would like to enable some sort of encryption between my cisco devices and win server during authentication(When someone ssh or telnets to the router). I believe ms chap ver 2 is more secured for windows. However i can't find any documentation that would do this. I keep on seeing the option to configure ppp on aaa and configure encap ppp on an interface. The thing is, what if i have several routers and my NAS is located or connected to just one switch interface. Does that mean that i have to enable ppp on every interface on my switches and routers. I apologize if my question may sound dumb but i would really appreciate any help or advise on this.

Thanks in advance.

marcusaureliusbrutus is offline   Reply With Quote

Login/register to remove this advertisement.
Village Idiot
Registered Member
 
dtlokee's Avatar
 
Join Date: Mar 2007
Location: NJ
Posts: 2,341

Certifications: CCIE #19991 R+S, CCNA, CCNP, CCIP, CCVP, CCSP, CCSI, MCSE NT4.0, 2000, 2003, + Messaging and Security, MCDBA, MCSD, MCAD
dtlokee has a spectacular aura aboutdtlokee has a spectacular aura aboutdtlokee has a spectacular aura about
Old 07-07-2009, 09:53 AM   #2 (permalink)

Are you using IAS on the windows box with RADIUS from the routers and switches for administrative access? This is a case where PPP CHAP is not going to help you.



__________________
The only easy day was yesterday!

dtlokee is offline   Reply With Quote
Member
Registered Member
 
Join Date: Apr 2009
Posts: 65

marcusaureliusbrutus is on a distinguished road
Old 07-07-2009, 09:42 PM   #3 (permalink)

The thing is i am just looking for a way to encrypt communication between the network access server (windows) and my cisco devices while using aaa. Can anybody recommend a solution.

Thanks.

marcusaureliusbrutus is offline   Reply With Quote
Senior Member
Registered Member
 
Join Date: May 2005
Location: Sydney, Australia
Posts: 394

Certifications: CCNA, CCNP
rakem is on a distinguished road
Old 07-08-2009, 07:49 AM   #4 (permalink)

Just use SSH. That should encrypt all authentication traffic. I think

rakem is offline   Reply With Quote
Village Idiot
Registered Member
 
dtlokee's Avatar
 
Join Date: Mar 2007
Location: NJ
Posts: 2,341

Certifications: CCIE #19991 R+S, CCNA, CCNP, CCIP, CCVP, CCSP, CCSI, MCSE NT4.0, 2000, 2003, + Messaging and Security, MCDBA, MCSD, MCAD
dtlokee has a spectacular aura aboutdtlokee has a spectacular aura aboutdtlokee has a spectacular aura about
Old 07-08-2009, 02:24 PM   #5 (permalink)

Quote:
Originally Posted by marcusaureliusbrutus View Post
The thing is i am just looking for a way to encrypt communication between the network access server (windows) and my cisco devices while using aaa. Can anybody recommend a solution.

Thanks.
If you are using RADIUS then it will not encrypt the "aaa" packets between the router and the aaa server. If you use TACACS+ then the packets are encrypted. If using RADIUS you could create a IPSec tunnel to the windows server.

I asked for more info and you didn't provide any, I am asking questions so I can help you find the most appropriate solution for what you are trying to do.



__________________
The only easy day was yesterday!

dtlokee is offline   Reply With Quote
Member
Registered Member
 
Join Date: Apr 2009
Posts: 65

marcusaureliusbrutus is on a distinguished road
Old 07-08-2009, 07:01 PM   #6 (permalink)

Hi Dtlokee,

I'm sorry i didn't provide additional details. My setup is such a way that i have multiple cisco switches/routers which i telnet to. I intend to enable ssh instead of telnet in the future. But first i wish to encrypt communication between my cisco devices and my aaa windows server. Checking my windows aaa server, it can only support mschap v2 at best. So i guess i'm stuck with mschap v2. So now i wish to enable mschap v2 login authentication on my cisco devices. I will look into your ipsec recommendation.

Thanks in advance.

marcusaureliusbrutus is offline   Reply With Quote
Village Idiot
Registered Member
 
dtlokee's Avatar
 
Join Date: Mar 2007
Location: NJ
Posts: 2,341

Certifications: CCIE #19991 R+S, CCNA, CCNP, CCIP, CCVP, CCSP, CCSI, MCSE NT4.0, 2000, 2003, + Messaging and Security, MCDBA, MCSD, MCAD
dtlokee has a spectacular aura aboutdtlokee has a spectacular aura aboutdtlokee has a spectacular aura about
Old 07-10-2009, 02:15 PM   #7 (permalink)

ok, the MSCHAP solution will not work for your case, that would only be if you were terminateing a PPP connection on the router like a dial in modem or a serial link with PPP authentication. You most likely have RADIUS configured ("aaa authentication login default group radius" or something like that). RADIUS messages are not encrypted so you would need to look at building a IPSec tunnel but if you have many routers it could become very time consuming. You could also look at a TACACS solution which would be encrypted.



__________________
The only easy day was yesterday!

dtlokee is offline   Reply With Quote
Bookmarks
Go Back TechExams.net IT Certification Forums > Cisco > CCNP
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



All times are GMT. The time now is 05:30 PM.

 
 
Featured Sponsors

TrainSignal - “Hands On” computer training for IT professionals. Network+ Training, MCSE, Cisco & more! Visit Train Signal’s free training site to get loads of Free Computer Training, videos, articles and practice exams.

Preplogic - Sign up now to get Unlimited Access to PrepLogic's entire video training library. Enjoy open access to Microsoft Server 2008, CCNA, CISSP®, PMP and many more. Get Unlimited Access

 

Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
TechExams.net 2009