<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA server on ASA - Asynchronous Routing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-server-on-asa-asynchronous-routing/m-p/2761500#M56953</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering if anyone can help me. &amp;nbsp;I&amp;nbsp;have an ASA setup with an AAA server to authenticate users authenticating with the ASA, the RADIUS server is located off the ASA on another network and to get to it the AAA server&amp;nbsp;it routes the request out the access interface. &amp;nbsp;The issue is that we have put in a leasedline which now acts as the primary route to get to the AAA server, so i have had to manually change the interface which the AAA request is sourced from and also change a route back on the router which hosts the AAA server to avoid asynchronous routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously there re now 2 paths to get to the AAA server and i have to manually set an outgoing interface against one of them, so if the primary link fails and the request is sourced from the primary interface but is routed out the backup, then the ASA will drop the packet when it comes back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can only add one server within an AAA group with the same IP as i was going to add 2 servers with the same ip with two different outgoing interfaces but it does not work.&lt;/P&gt;&lt;P&gt;Is there a way to get this to work? &amp;nbsp;maybe turn off asynchronous routing somehow just for this AAA server? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could anybody tell me how i can get this to work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:11:19 GMT</pubDate>
    <dc:creator>Matthew burnley</dc:creator>
    <dc:date>2019-03-11T06:11:19Z</dc:date>
    <item>
      <title>AAA server on ASA - Asynchronous Routing</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-on-asa-asynchronous-routing/m-p/2761500#M56953</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering if anyone can help me. &amp;nbsp;I&amp;nbsp;have an ASA setup with an AAA server to authenticate users authenticating with the ASA, the RADIUS server is located off the ASA on another network and to get to it the AAA server&amp;nbsp;it routes the request out the access interface. &amp;nbsp;The issue is that we have put in a leasedline which now acts as the primary route to get to the AAA server, so i have had to manually change the interface which the AAA request is sourced from and also change a route back on the router which hosts the AAA server to avoid asynchronous routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously there re now 2 paths to get to the AAA server and i have to manually set an outgoing interface against one of them, so if the primary link fails and the request is sourced from the primary interface but is routed out the backup, then the ASA will drop the packet when it comes back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can only add one server within an AAA group with the same IP as i was going to add 2 servers with the same ip with two different outgoing interfaces but it does not work.&lt;/P&gt;&lt;P&gt;Is there a way to get this to work? &amp;nbsp;maybe turn off asynchronous routing somehow just for this AAA server? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could anybody tell me how i can get this to work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:11:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-on-asa-asynchronous-routing/m-p/2761500#M56953</guid>
      <dc:creator>Matthew burnley</dc:creator>
      <dc:date>2019-03-11T06:11:19Z</dc:date>
    </item>
    <item>
      <title>Hi Matt , You can try to</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-on-asa-asynchronous-routing/m-p/2761501#M56954</link>
      <description>&lt;P&gt;Hi Matt ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can try to apply a TCP-bypass to this traffic to allow the AAA server reply &amp;nbsp;in a different ASa interface where it was sourced.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check examples below&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/conns_tcpstatebypass.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/conns_tcpstatebypass.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope it helps&lt;/P&gt;&lt;P&gt;-Randy-&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 05:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-on-asa-asynchronous-routing/m-p/2761501#M56954</guid>
      <dc:creator>rvarelac</dc:creator>
      <dc:date>2015-10-27T05:21:18Z</dc:date>
    </item>
    <item>
      <title>Hi Randy, I'll have to give</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-on-asa-asynchronous-routing/m-p/2761502#M56956</link>
      <description>&lt;P&gt;Hi Randy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll have to give the TCP bypass a go.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What happens if i create two AAA groups and put the same server IP &amp;nbsp;in each group but specify different outgoing interfaces for the server?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 23:17:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-on-asa-asynchronous-routing/m-p/2761502#M56956</guid>
      <dc:creator>Matthew burnley</dc:creator>
      <dc:date>2015-10-27T23:17:09Z</dc:date>
    </item>
  </channel>
</rss>

