Hello All,
This question is a question based on configuration between the ASA and the ACS in a deployment.
I have a customer that would like to accomplish one of two scenarios:
Scenario 1:
The desire is that if we have two factor authentication we need for the first authentication to be processed by ACS based on AD user credentials.
The second authentication we would like to source from a different interface/IP address of the ASA so that we can filter that authentication attempt based on NAD IP in ACS to apply a completely different authorization profile that checks for users from the helpdesk group only.
We need for the auth to fail if we dont have the second helpdesk user login credentials.
Second Scenario:
The desire is that if we have two factor authentication we need for the first authentication to be processed by ACS based on AD user credentials.
The second authentication we would like to send to a different interface/IP address of the ACS so that we can filter that authentication attempt based on called-station-ip in ACS to apply a completely different authorization profile that checks for users from the helpdesk group only.
We need for the auth to fail if we dont have the second helpdesk user login credentials.
Between these two scenarios which one is possible and more plausible.
We are using the ASA and AnyConnect to prompt for both usernames and passwords simultaneously.
--
Grace and Peace,
Robert E Roulhac Jr
Virtual Systems Engineer II
Cisco TSN (Technical Solutions Network)
rroulhac@cisco.com
Office: 919.5745455