cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
436
Views
0
Helpful
2
Replies

cut-thrgh authorization problem with acs and asa

diptanshusingh
Level 1
Level 1

hi i have a problem guys.. i am using an asa firewall with cisco acs 3.1. i want to use authorization with cut thrgh proxy using tacacs+..

access-list auth_prxy extended permit ip any any

aaa authentication match auth_prxy inside acs

aaa authorization match auth_prxy inside acs

aaa-server acs protocol tacacs+

aaa-server acs host Server

key secret

when i try it says not authorized.. i was trying to add auth-proxy attribute in acs for tacacs+ but it's not working..

2 Replies 2

Vivek Santuka
Cisco Employee
Cisco Employee

Hi,

Auth-proxy is an IOS concept.

On Asa cut through authentication is possible.

For Cut through to work you need not add the auth-proxy attribute in ACS. If the user exists and the password is correct, Asa would let the traffic go through.

This might help :-

http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_70/config/fwaaa.htm#wp1043681

Regards,

Vivek

Hi vivek

thanks for ur reply.. i had already figured it out.. we can do the authorization also for cut thrgh with the help of shell command authorization using tacacs+..