question

afeniello-0759 avatar image
0 Votes"
afeniello-0759 asked MarileeTurscak-MSFT answered

Enable AD authentication on csr1000v

Hello,

i m setting up a flex vpn tunnel between 2 routers:

Server router: CSR 1000v hosted on Azure
Edge router: IR809g on premise

Currently the tunnel works with local authentication but I would like to enable AAA authentication on the CSR1000v and connect it to my Azure AD.

It is possibile? How can i do?

azure-ad-domain-services
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

MarileeTurscak-MSFT avatar image
0 Votes"
MarileeTurscak-MSFT answered

Hi @afeniello-0759,

I understand that you are looking to enable Azure AD authentication on a Cisco CSR 1000v.

There does not appear to be any documentation for this on the Azure AD side, but Cisco offers these guidelines for how to set up the authentication.

In HA version 1, you create an application in the Azure Active Directory and grant it permission to access the route tables. In HA version 2, an application representing the CSR 1000v is automatically created in the Azure Active Directory via Azure Managed Identities.

Their support table covers the supported authentication scenarios:

190382-image.png

Since we do not have documentation for this on the Azure side, I would recommend reaching out on the Cisco community for questions around your specific configuration.

Thanks,

Marilee



If this answer was helpful to you, please consider "marking as answer" so that others in the community with similar questions can more easily find a solution.



image.png (175.2 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.