cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

839
Views
0
Helpful
1
Replies
Highlighted
Beginner

ASA cut-through proxy and ACS 5.3

Hi, I'm planning to migrate a customer from ACS 4.2 to ACS 5.3.

I have migrated the configuration for all the services but I'm thinking how to configure ASA 8.4 cut-through proxy service in TACACS+.

The same ASA uses TACACS+ for device mngt and RADIUS for vpn remote-access services.

How to ?

thank you in advance

rs

1 REPLY 1
Highlighted
Advocate

RS,

Hi here is the guide that helps you configure the cut-through proxy from the ASA this is a good example:

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_fwaaa.html

When configuring the ACS portion you can use two methods: "Cisco ACS" downloadable access-lists, "Any Radius Server" downloadable access-lists (my favorite), or you can send the filter attribute which points the user to a defined acl on the ASA. Either way you choose, you will have to first create a network authorization profile which will have the radius attributes in the formats that are outlined in this guide. You will create an authorization policy that will call this authorization policy as the result when they meet this condition.

Let me know how things go, if you get stuck, please posts screenshots so I can help you further.

Thanks,

Tarik admani

Tarik Admani
*Please rate helpful posts*

Content for Community-Ad