10-12-2007 12:36 AM - edited 03-10-2019 03:26 PM
When ACS communicates with another authentication server (eg: ACE), does it include the NAS or the user's address in the ip packet payload?
The reason for this question is that we want to use NAT between ACS and ACE. Obviously the NAT won't work if the real address is put in the payload.
Thanks in advance
10-12-2007 06:03 AM
If on ACS, ACE configured as an External Database, then ACS wont send NAS ip to ACE.
The communication between ACS and ACE will be based on Radius protocol, and ACS will be added as a Radius client on ACE.
If ACS is acting as a pure proxy radius server, and forwarding request to ACE, then payload will have NAS.
How to configure Radius Token Server as an External Database on ACS:
Regards,
Prem
10-16-2007 12:05 AM
The definitive answer is no - not for want you need.
External authentication to RSA doesnt include anything about the end-user except credentials.
RADIUS proxy does - but then you bypass ACS authentication & authorisation completely.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide