cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1097
Views
0
Helpful
1
Replies

ASA auth-proxy with Radius and downloadable ACL

mlopacinski
Level 1
Level 1

Hello

I want to have ACLs which decide which traffic to allow after auth-proxy authorisation.

1. What options do i have for ASA+ACS ?

2. Can i use auth-proxy on ASA with ACS and radius and downloadable ACL ?

3. Can i use auth-proxy on ASA with ACS and radius 009/001 cisco-av-pair (will ASA understeand it ?)

4. Can i use auth-proxy on ASA with ACS and tacacs auth-proxy attributes (with ACL) ?

Thanx

1 Accepted Solution

Accepted Solutions

Tarik Admani
VIP Alumni
VIP Alumni

Hi,

Take a look over this guide to see if this helps answer your question. You can use both downloadable ACL or the cisco av-pairs, I have seen that the cisco-av-pair method works a little better because it has the username who logged in as a part of the acl which eases troubleshooting.

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_fwaaa.html#wp1150820

thanks,

Tarik Admani

View solution in original post

1 Reply 1

Tarik Admani
VIP Alumni
VIP Alumni

Hi,

Take a look over this guide to see if this helps answer your question. You can use both downloadable ACL or the cisco av-pairs, I have seen that the cisco-av-pair method works a little better because it has the username who logged in as a part of the acl which eases troubleshooting.

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_fwaaa.html#wp1150820

thanks,

Tarik Admani