<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA can backup aaa-server group in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585257#M1088911</link>
    <description>&lt;P&gt;Thank for answer .&amp;nbsp;&lt;/P&gt;&lt;P&gt;as your mention &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; about I can configure only 1 aaa-group for aaa authentication .&amp;nbsp; can you provide official document for me ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2022 13:41:30 GMT</pubDate>
    <dc:creator>jewfcb001</dc:creator>
    <dc:date>2022-04-04T13:41:30Z</dc:date>
    <item>
      <title>ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585197#M1088902</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know ASA can configure aaa-server group for backup if aaa-server primary down ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;as configuration below. If Radius-1 group fail can i configure automatic to switchover to Raidius-2 group.?&lt;/P&gt;&lt;P&gt;aaa-server Radius-1 protocol radius&lt;BR /&gt;aaa-server Radius-1 (inside) host 10.10.10.1&lt;BR /&gt;key xxx&lt;BR /&gt;aaa-server Radius-1 (inside) host 10.10.10.2&lt;BR /&gt;key xxx&lt;/P&gt;&lt;P&gt;aaa-server Radius-2 protocol radius&lt;BR /&gt;aaa-server Radius-2 (inside) host 20.20.20.1&lt;BR /&gt;key xxx&lt;BR /&gt;aaa-server Radius-2 (inside) host 20.20.20.2&lt;BR /&gt;key xxx&lt;/P&gt;&lt;P&gt;aaa authentication http console Radius-1 LOCAL&lt;BR /&gt;aaa authentication enable console Radius-1 LOCAL&lt;BR /&gt;aaa authentication serial console Radius-1 LOCAL&lt;BR /&gt;aaa authentication ssh console Radius-1 LOCAL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you .&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 12:43:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585197#M1088902</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-04-04T12:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585221#M1088905</link>
      <description>&lt;P&gt;The order would be in your case Inside the first radius-1 will checked if not reachable it will go to second. same for Radius-2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;however you need to call Radus-2 in your aaa authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The security appliance contacts the first server in the group. If that server is unavailable, the security appliance contacts the next server in the group, if configured. If all servers in the group are unavailable, the security appliance tries the local database if you configured it as a fallback method (management authentication and authorization only). If you do not have a fallback method, the security appliance continues to try the AAA servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="pB2_Body2"&gt;If you configured a fallback method using the local database (for management access only; see the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/mgaccess.html#wpxref93995" target="_blank"&gt;&lt;SPAN class="cXRef_Color"&gt;"Configuring AAA for System Administrators" section on page&amp;nbsp;40-5&lt;/SPAN&gt;&lt;/A&gt; and the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/mgaccess.html#wpxref25506" target="_blank"&gt;&lt;SPAN class="cXRef_Color"&gt;"Configuring TACACS+ Command Authorization" section on page&amp;nbsp;40-11&lt;/SPAN&gt;&lt;/A&gt; to configure the fallback mechanism), and all the servers in the group fail to respond, then the group is considered to be unresponsive, and the fallback method is tried. The server group remains marked as unresponsive for a period of 10 minutes (by default) so that additional AAA requests within that period do not attempt to contact the server group, and the fallback method is used immediately. To change the unresponsive period from the default, see the &lt;STRONG class="cBold"&gt;reactivation-mode&lt;/STRONG&gt; command in the following step.&lt;/P&gt;
&lt;P&gt;&lt;A name="wp1039802" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class="pB2_Body2"&gt;If you do not have a fallback method, the security appliance continues to retry the servers in the group.&lt;/P&gt;
&lt;P&gt;&lt;A name="wp1051406" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class="pSsN_StepsubNext"&gt;&lt;STRONG&gt; c. &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SherazSalim_0-1649078207831.gif" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/148024i54829EFE267BFEEC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SherazSalim_0-1649078207831.gif" alt="SherazSalim_0-1649078207831.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="pSsN_StepsubNext"&gt;If you want to specify the method (reactivation policy) by which failed servers in a group are reactivated, enter the following command:&lt;/P&gt;
&lt;P class="pSsN_StepsubNext"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/aaa.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa72/configuration/guide/conf_gd/aaa.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 13:17:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585221#M1088905</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-04-04T13:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585223#M1088906</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;however you need to call Radus-2 in your aaa authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- you mean i need to manual edit configuration my understand correct ? don't have any way to do automatic .&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 13:15:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585223#M1088906</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-04-04T13:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585226#M1088907</link>
      <description>&lt;P&gt;I search and check both command reference and ASDM, both point to same&amp;nbsp;&lt;BR /&gt;YOU CAN USE ONLY ONE GROUP for each auth/authz/account and additional you can select Local as fallback and this recommend.&lt;BR /&gt;&lt;BR /&gt;So sorry even if you have multi group only one support with aaa auth http .........etc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 13:18:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585226#M1088907</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-04T13:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585244#M1088910</link>
      <description>&lt;P&gt;I have double check on the command line no you would only able to called the Radius-1 in aaa authentication. you cant call the Radius-2 authentication. one server group name at one time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but what you can do is called all the ip addresses in Radius-1 In case if 1 ip not available it will fallback to other and so on.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 13:32:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585244#M1088910</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-04-04T13:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585257#M1088911</link>
      <description>&lt;P&gt;Thank for answer .&amp;nbsp;&lt;/P&gt;&lt;P&gt;as your mention &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; about I can configure only 1 aaa-group for aaa authentication .&amp;nbsp; can you provide official document for me ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 13:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585257#M1088911</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-04-04T13:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585258#M1088912</link>
      <description>&lt;P&gt;you can added them in one server the ip addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;aaa-server Radius-1 protocol radius
aaa-server Radius-1 (inside) host 10.10.10.1
key xxx
aaa-server Radius-1 (inside) host 10.10.10.2
key xxx
aaa-server Radius-1 protocol radius
aaa-server Radius-1 (inside) host 20.20.20.1
key xxx
aaa-server Radius-1 (inside) host 20.20.20.2
key xxx
aaa authentication http console Radius-1 LOCAL
aaa authentication enable console Radius-1 LOCAL
aaa authentication serial console Radius-1 LOCAL
aaa authentication ssh console Radius-1 LOCAL&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;The range is from 1 and 5. The default is 3.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p"&gt;If you configured a fallback method using the local database (for management access only), and all the servers in the group fail to respond, or their responses are invalid, then the group is considered to be unresponsive, and the fallback method is tried. The server group remains marked as unresponsive for a period of 10 minutes (by default), so that additional AAA requests within that period do not attempt to contact the server group, and the fallback method is used immediately. To change the unresponsive period from the default, see the &lt;STRONG id="ID-2113-00000920__ID-2443-000003ea" class="ph b"&gt;reactivation-mode&lt;/STRONG&gt; command in the next step.&lt;/P&gt;
&lt;P class="p"&gt;If you do not have a fallback method, the ASA continues to retry the servers in the group.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 13:43:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585258#M1088912</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-04-04T13:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585260#M1088913</link>
      <description>&lt;P&gt;yes here the the link&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/general/asa-98-general-config/aaa-radius.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/general/asa-98-general-config/aaa-radius.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can add all the ip address in one group server the default is 3 but you can add up to 1 to 5&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 13:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585260#M1088913</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-04-04T13:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585264#M1088914</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for information .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;you can add all the ip address in one group server&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;as your mention . I worry asa will be confuse because radius-1 and radius-2 not sync database or session .&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 13:50:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585264#M1088914</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-04-04T13:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585276#M1088916</link>
      <description>&lt;P&gt;Is 10.x.x.x and 20.x.x.x are behind asa inside interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;oh ok I got you. The 10 rang and 20 range radius serves are not syn&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In that’s case you have limited options either you can use 10 or 20. But if range 10 is not responding than 20 will kick in&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 14:11:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585276#M1088916</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-04-04T14:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585389#M1088923</link>
      <description>&lt;P&gt;From&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to summarize. ASA can apply only 1 aaa-server group for aaa authentication .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 15:48:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585389#M1088923</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-04-04T15:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can backup aaa-server group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585407#M1088925</link>
      <description>&lt;P&gt;you can have multiple aaa-server in your firewall (asa)&lt;/P&gt;
&lt;PRE&gt;aaa-server Radius1 protocol radius
 max-failed-attempts 5
aaa-server Radius1 (MGMT) host 172.x.x.x
 timeout 60
 key *****
 authentication-port 1812
!
aaa-server Radius2 protocol radius
 max-failed-attempts 5
aaa-server Radius2 (MGMT) host 172.x.x.x
 timeout 60
 key *****
 authentication-port 1812
&lt;/PRE&gt;
&lt;P&gt;as these aaa-server are used in for authentication purposes (any-connect-authentication,remote access authentication etc).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;having said but for aaa-authentication you can only call in one server. only one not more than one as CLI and ASDM wont allow it if you try to add "aaa authentication http console Radius-2 LOCAL" it will give you error "Range already exists." assume Radius-2 Is defined in aaa-server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;aaa authentication http console Radius-1 LOCAL
aaa authentication enable console Radius-1 LOCAL
aaa authentication serial console Radius-1 LOCAL
aaa authentication ssh console Radius-1 LOCAL&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Conclusion: in your case you can not add aaa authentication with Radius1 and Radius2. either Radius1 or Radius2 will work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope it will help and clear your understanding.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 16:13:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-backup-aaa-server-group/m-p/4585407#M1088925</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-04-04T16:13:43Z</dc:date>
    </item>
  </channel>
</rss>

