<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello friends,Please allow me in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-tacacs-sdi-rsa-authentication-and-authorisation/m-p/1510960#M297541</link>
    <description>&lt;P&gt;Hello friends,&lt;/P&gt;&lt;P&gt;Please allow me to resurect this old post!&lt;/P&gt;&lt;P&gt;Did you find your answer? My IT manager is asking me to integrate RSA token with our TACACS. Is it possible to add that second factor of authentication for managing my whole network devices?&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jun 2014 01:38:41 GMT</pubDate>
    <dc:creator>alexdelangel</dc:creator>
    <dc:date>2014-06-23T01:38:41Z</dc:date>
    <item>
      <title>ASA TACACS + SDI (RSA) Authentication and Authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-tacacs-sdi-rsa-authentication-and-authorisation/m-p/1510957#M297512</link>
      <description>&lt;P&gt;Hi guys&lt;/P&gt;&lt;P&gt;Just wondering if this can be done:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a RSA server and TACACS server, all working fine.&lt;/P&gt;&lt;P&gt;We would like to put in 2 factor authentication using our RSA token to manage our ASA box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I have got the 2 factor authentication working (tested it with SSH to ASA box) but it seems like it allows anyone with an account on the RSA server to login to the box. We don't want this, we want to be able to lock it down to only few accounts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also have a TACACS server. Logging in to the ASA box using TACACS local accounts work fine &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that authorisation doesn't work with RSA, and one of the suggestions that I received was to add the RSA server into TACACS, create the user groups / users we want and use TACACS for both authentication and authorisation. Is that right? Some pointers would be appreciated &lt;span class="lia-unicode-emoji" title=":neutral_face:"&gt;😐&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-tacacs-sdi-rsa-authentication-and-authorisation/m-p/1510957#M297512</guid>
      <dc:creator>jafaruddinlie</dc:creator>
      <dc:date>2019-03-11T00:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA TACACS + SDI (RSA) Authentication and Authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-tacacs-sdi-rsa-authentication-and-authorisation/m-p/1510958#M297514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically the Tacacs+ is a AA protocol with authentication and authorisation at the same time. I configured the ASA with the ASDM for the Tacacs use. Therefore you should look for the problem with the timeouts, I had troubles that every 30 sec the RSA user ran into a timeout.&lt;/P&gt;&lt;P&gt;I suggest you that you create a group on the ACS for the firewall admins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Sep 2010 09:09:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-tacacs-sdi-rsa-authentication-and-authorisation/m-p/1510958#M297514</guid>
      <dc:creator>martin_knorre</dc:creator>
      <dc:date>2010-09-04T09:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA TACACS + SDI (RSA) Authentication and Authorisation</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-tacacs-sdi-rsa-authentication-and-authorisation/m-p/1510959#M297521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep maybe I didn't explain myself very well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Thank you for your reply, sorry it took this long for me to write back. I'll have a look at the timeout issue, thanks for the heads up. Could be some ports that need to be opened, who knows &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Sep 2010 09:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-tacacs-sdi-rsa-authentication-and-authorisation/m-p/1510959#M297521</guid>
      <dc:creator>jafaruddinlie</dc:creator>
      <dc:date>2010-09-16T09:49:24Z</dc:date>
    </item>
    <item>
      <title>Hello friends,Please allow me</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-tacacs-sdi-rsa-authentication-and-authorisation/m-p/1510960#M297541</link>
      <description>&lt;P&gt;Hello friends,&lt;/P&gt;&lt;P&gt;Please allow me to resurect this old post!&lt;/P&gt;&lt;P&gt;Did you find your answer? My IT manager is asking me to integrate RSA token with our TACACS. Is it possible to add that second factor of authentication for managing my whole network devices?&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2014 01:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-tacacs-sdi-rsa-authentication-and-authorisation/m-p/1510960#M297541</guid>
      <dc:creator>alexdelangel</dc:creator>
      <dc:date>2014-06-23T01:38:41Z</dc:date>
    </item>
  </channel>
</rss>

