How To: Elevate the RADIUS Login Privilege Level for a Cisco Switch Integration

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: 9.1, 9.2

     

    Overview

    This article explains how to configure a Cisco switch RADIUS integration so that logged-in users are granted privileged EXEC mode (privilege level 15) instead of the default user EXEC mode (privilege level 1). This is useful when every user authenticating through the integration is a network administrator who needs full enable-level command access, not just the commands available at the standard router prompt.

     

    Elevate the Login Privilege Level

    1. In the RADIUS server's installation folder, open the default dictionary file -- by default, C:\IdPRadius\bin\default_dictionary.txt. Use an editor such as Notepad++ so the character set isn't altered.
    2. Add the following two lines to the end of the file:
    VENDOR      9  Cisco
    VENDORATTR  9  cisco-avpair  1  String
    1. In the RADIUS Server's web configuration console, add the new attribute to the client configuration, mapped to a free IdP attribute field (for example, an Aux ID) or a global Aux value.
    2. Restart the RADIUS service.
    3. Map the Aux ID field you chose to a valid Active Directory field, and enter the following value in it:
    shell:priv-lvl=15


     

    Special Considerations

    The exact dictionary attribute and syntax needed may vary depending on the Cisco switch software version being integrated with.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.