Application Acceleration
Highlighted
Application Acceleration

tacacs or radius management support for JWOS

‎02-03-2011 04:35 PM

Hi All,

 

Will JWOS be supporting RADIUS or TACACS for management of the box.  I know that it supports Radius for remote users, but what about admin users to the box itself?

 

We use central authentication for access to our network devices.  So its a must have for us to install these devices into our customers networks.

 

Thanks

Lanky

9 REPLIES 9
Highlighted
Application Acceleration

Re: tacacs or radius management support for JWOS

‎02-03-2011 04:46 PM

Yes, both RADIUS and TACACS are supported for admin access. The setup is outlined in KB17274.

 

http://kb.juniper.net/InfoCenter/index?page=content&id=KB17274

 

You can see a full list of security recommendations for the WXC series in KB18225

 

http://kb.juniper.net/InfoCenter/index?page=content&id=KB18225

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home
Highlighted
Application Acceleration

Re: tacacs or radius management support for JWOS

‎02-03-2011 04:57 PM

Hi Steve,

 

Thanks for the tips. I understand that you can add Radius to the WXC whilst running WXOS, but we are running JWOS.  Do you know if the same solutions applies please?

 

Thanks

Lanky

 

Highlighted
Application Acceleration

Re: tacacs or radius management support for JWOS

‎02-03-2011 05:03 PM

Yes, the administrative access configuration is the same for both versions.

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home
Highlighted
Application Acceleration

Re: tacacs or radius management support for JWOS

‎02-03-2011 05:16 PM

Hi Steve,

 

Thanks for the quick replies.  Unfortunatley we can't see it on our device.  Under the "Setup > AAA> Authentication"  We only have a link for "Local Users" and "Front panel access".  We are using a WXC590.  Maybe we get a different version down under in Aus.  Smiley Sad

 

Thanks

Lanky

Highlighted
Application Acceleration

Re: tacacs or radius management support for JWOS

‎02-03-2011 05:30 PM

It might be the hardware.  We are running 1800s and 2600 series.

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home
Highlighted
Application Acceleration

Re: tacacs or radius management support for JWOS

‎02-03-2011 06:00 PM

Just went in for a closer look.  The JWOS we had in was on evaluation so we didn't hook it into the RADIUS server.  But I swore the menu was there, it is not.

 

A run to the manual confirms that even in the new 6.1 release there is no RADIUS support in JWOS.

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home
Highlighted
Application Acceleration

Re: tacacs or radius management support for JWOS

‎02-03-2011 07:01 PM

Steve -

 

The only supported devices for JWOS are WXC590, WXC2600 and WXC3400. How are you using WXC1800 for that? Does it let you install the image on that device? If it does then it may be a bug.

 

And yes, just as there is no support for Radius in Australia,  there is no support for Radius even in United States either.

 

Don't know if it is in the roadmap at all.

 

Thanks

Iqbal Mirza

SRX Global JTAC

JNCIE-SEC#68, JNCIS-M, CCNP
_______________________________________
"Accepted Solution" = If the solutions works for you.
"Accepted Solution+Kudos" = If you really think I earned it.
Highlighted
Application Acceleration

Re: tacacs or radius management support for JWOS

‎02-03-2011 07:17 PM

Thank you both for your replies.  I appreciate your help.

I guess we shall continue to push our reps to get an update for the new JWOS.  Smiley Happy

 

Thanks

Lanky

Highlighted
Application Acceleration

Re: tacacs or radius management support for JWOS

‎02-04-2011 03:12 AM

The 1800s are on the branch side of our WAN solution deploy. 

 

I had thd JWOS in for evaluation but we could not make the client work with a Microsoft server based VPN solution.  It was not clear if the issue was with the MS solution since it is not supported or tested or was due to the fact that the server was on the compressed subnet for the WAN solution.  So we tabled this project.

 

We are rolling out SSL-VPN now so we may revisit it when that is complete.

 

I am very surprised that RADIUS/TACACS is not supported in JWOS for device admin.  This is is a very common solution for device management and it exists on the WAN series.

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home