Skip to content

Authentication and Policy Servers

Location in GUI: System » Settings » External Services » Authentication and Policy Servers

Diagram
NameTypeConstraintMandatoryDefault Value
authentication_and_policy_serversClass[authentication_and_policy_servers]No

authentication_and_policy_servers (catalyst_center.system_settings)

Section titled “authentication_and_policy_servers (catalyst_center.system_settings)”
NameTypeConstraintMandatoryDefault Value
iseClass[ise]No
aaaList[aaa]No

ise (catalyst_center.system_settings.authentication_and_policy_servers)

Section titled “ise (catalyst_center.system_settings.authentication_and_policy_servers)”
NameTypeConstraintMandatoryDefault Value
ip_addressIPYes
shared_secretStringYes
usernameStringYes
passwordStringYes
fqdnStringYes
pxgrid_enabledBooleantrue, falseNo
use_catc_cert_for_pxgridBooleantrue, falseNo
retriesIntegermin: 1, max: 3Yes
timeoutIntegermin: 2, max: 20Yes
protocolsClass[protocols]No

aaa (catalyst_center.system_settings.authentication_and_policy_servers)

Section titled “aaa (catalyst_center.system_settings.authentication_and_policy_servers)”
NameTypeConstraintMandatoryDefault Value
ip_addressIPYes
shared_secretStringYes
retriesIntegermin: 1, max: 3Yes
timeoutIntegermin: 2, max: 20Yes
protocolsClass[protocols]Yes

protocols (catalyst_center.system_settings.authentication_and_policy_servers.ise)

Section titled “protocols (catalyst_center.system_settings.authentication_and_policy_servers.ise)”
NameTypeConstraintMandatoryDefault Value
tacacsClass[tacacs]No
radiusClass[radius]No

tacacs (catalyst_center.system_settings.authentication_and_policy_servers.ise.protocols)

Section titled “tacacs (catalyst_center.system_settings.authentication_and_policy_servers.ise.protocols)”
NameTypeConstraintMandatoryDefault Value
portIntegermin: 1, max: 65535No

radius (catalyst_center.system_settings.authentication_and_policy_servers.ise.protocols)

Section titled “radius (catalyst_center.system_settings.authentication_and_policy_servers.ise.protocols)”
NameTypeConstraintMandatoryDefault Value
authentication_portIntegermin: 1, max: 65535No
accounting_portIntegermin: 1, max: 65535No
enable_key_wrapClass[enable_key_wrap]No

enable_key_wrap (catalyst_center.system_settings.authentication_and_policy_servers.ise.protocols.radius)

Section titled “enable_key_wrap (catalyst_center.system_settings.authentication_and_policy_servers.ise.protocols.radius)”
NameTypeConstraintMandatoryDefault Value
encryption_keyStringNo
message_keyStringNo

Example 1: Basic ISE server configuration with RADIUS protocol, including pxGrid integration for security context sharing and standard authentication settings:

catalyst_center:
system_settings:
authentication_and_policy_servers:
ise:
ip_address: 198.18.133.27
shared_secret: "Shared12345"
username: "admin"
password: "RandomPass12345"
fqdn: ise.example.net
pxgrid_enabled: true
use_catc_cert_for_pxgrid: false
retries: 3
timeout: 4
protocols:
radius:
authentication_port: 1812
accounting_port: 1813

Example 2: ISE server with TACACS and RADIUS key wrap encryption for enhanced security, demonstrating the use of encryption and message keys to protect shared secrets in transit:

catalyst_center:
system_settings:
authentication_and_policy_servers:
ise:
ip_address: 198.18.133.27
shared_secret: "Shared12345"
username: "admin"
password: "RandomPass12345"
fqdn: ise.example.net
pxgrid_enabled: true
use_catc_cert_for_pxgrid: false
retries: 3
timeout: 4
protocols:
tacacs:
port: 49
radius:
authentication_port: 1812
accounting_port: 1813
enable_key_wrap:
encryption_key: "qweqweqweqweqwe1"
message_key: "dsdsd123454545454545"

Example 3: Comprehensive deployment with ISE as primary policy server and multiple AAA servers for redundancy, demonstrating enterprise-grade authentication infrastructure with pxGrid integration, key wrap encryption, and geographically distributed AAA servers for resilience:

catalyst_center:
system_settings:
authentication_and_policy_servers:
ise:
ip_address: 198.18.133.27
shared_secret: "Shared12345"
username: "admin"
password: "RandomPass12345"
fqdn: ise.example.net
pxgrid_enabled: true
use_catc_cert_for_pxgrid: false
retries: 3
timeout: 4
protocols:
tacacs:
port: 49
radius:
authentication_port: 1812
accounting_port: 1813
enable_key_wrap:
encryption_key: "qweqweqweqweqwe1"
message_key: "dsdsd123454545454545"
aaa:
- ip_address: 198.18.133.111
shared_secret: "Shared12345"
retries: 3
timeout: 5
protocols:
tacacs:
port: 49
radius:
authentication_port: 1812
accounting_port: 1813
- ip_address: 198.18.133.112
shared_secret: "Shared12345"
retries: 3
timeout: 5
protocols:
tacacs:
port: 49
radius:
authentication_port: 1812
accounting_port: 1813
- ip_address: 198.18.133.113
shared_secret: "Shared12345"
retries: 2
timeout: 5
protocols:
tacacs:
port: 49
radius:
authentication_port: 1812
accounting_port: 1813
enable_key_wrap:
encryption_key: "qweqweqweqweasd1"
message_key: "dsdsd123454545454567"