jheary
Distinguished Systems Engineer

Cisco ACS 5.1 makes troubleshooting 802.1x a breeze

Analysis
Jun 14, 20104 mins

ACS 5.1 could be the keystone to mainstreaming 802.1x in the enterprise

Let’s face it 802.1x has been around for over a decade now and its still not widely deployed and suffers from a bad rap. One of the key reasons for this is that 802.1x suffers from serious operational shortcomings and lacks proper troubleshooting tools. Cisco ACS has never been known for its flashy GUI and great troubleshooting tools. In fact, previous to version 5.x, ACS was notorious for its lack of reporting, monitoring and troubleshooting features. Cisco gave ACS a major overhaul starting in version 5.0 and continuing to the current version 5.1. One of the major targets for ACS 5.x was improving 802.1x support. Read my previous 5.0 features blog here for details. ACS 5.1 is the first version that most ACS 4.x users can migrate to. ACS 5.0 was missing to many key features to be viable for nearly all. ACS 5.1 reaches feature parity with ACS 4.2 and blows past it in several other areas like 802.1x and trustsec support. ACS 5.x includes a brand new troubleshooting and monitoring section. Previously, troubleshooting 802.1x meant looking through the flat log file on ACS and finding the switch having the issues and issuing several debug commands from the switch CLI. Not a process you can easily operationalize to level 1 support staff. Here are some of the 802.1x troubleshooting tools that ACS 5.1 includes. Dashboard – This allows you to see snapshots of what is happening on your network. It includes tabs for Troubleshooting, General health, General stats and Authentication trends. You can add your own tab pages and fill them with your own content.

Live Authentications – Shows a live updating list of authentications performed on ACS. It includes both per permitted and denied authentications. Live authentications is one of the most powerful features in ACS 5.x. You can click on any of the links to proceed to troubleshooting or additional information. The magnifying glass icon brings you to authentication details. For a larger screenshot click here.

Authentication Detail – Shows an extremely detailed look at an individual authentication. It shows which identity store was used, what the authentication outcome was, username, network device the user is connected to, trustsec group, among other attributes. Everything you could possibly need or want to know about an authentication are shown.

You can also execute multiple Actions from this screen.

User Authentication Summary – This page, complete with links to additional information, shows a complete history for a particular username. It shows what device mac address was used for each login, switchport locations, failure reasons, active sessions,

Expert Troubleshooter– All sorts of advanced troubleshooting tools are available in this section.

Configuration Validator – this feature checks the running configuration of a switch against best practice 802.1x and trustsec templates. It then shows you which configuration items are missing, if any. You can choose which items you want to check. Then run the validation and it spits out all of the configuration errors and shows you the exact commands you need to add to your config.

These are just a few of the new troubleshooting tools available in ACS. I highlighted the 802.1x functionality but these also work for other radius (like wireless) and Tacacs+ troubleshooting as well. ACS 5.1 is a critical piece of the 802.1x puzzle. I think you’ll find that it does a good job at helping you deploy, operationalize and troubleshoot 802.1x in your environment. So what else are you waiting for before you deploy 802.1x on your network?

The opinions and information presented here are my PERSONAL views and not those of my employer. I am in no way an official spokesperson for my employer.
More from Jamey Heary: Credit Card Skimming: How thieves can steal your card info without you knowing it Google Nexus One vs. Top 10 Phone Security RequirementsWhy you should always shred your boarding pass Video rental records are afforded more privacy protections than your online dataThe truth about new SSL attacks 2009 Top Urban Legends in IT Security/a>Go to Jamey’s Blog for more articles on security.

*

*

*

*

*

*

jheary

Jamey Heary, CCIE #7680, is a Distinguished Systems Engineer at Cisco Systems. Jamey sits on the PCI Security Standards Council- Board of Advisors where he provides strategic and technical guidance for future PCI standards. Jamey has authored several security books, his latest is Cisco ISE for BYOD and Secure Unified Access. He also has a patent on a new DDoS mitigation and firewall IP reputation technique. Jamey leads numerous security advisory boards for Cisco Systems and is a founding member of the Colorado Healthcare InfoSec Users Group. He is also recognized as a Distinguished Speaker at Cisco Live. He has been working in the IT field for 19 years and in IT security for 15 years.

More from this author