05-12-2015 08:58 PM - edited 03-12-2019 05:45 PM
Hi Experts,
Good Day!
I need help for my implementation of AAA in ASA. Technically, my ASA has a 2 interfaces which are listed below,
My ACS is located at the INTERNAL interface but we need to enroll in the ACS the Management IP of the ASA which is in the Management interface. So, my configuration of AAA look like below,
aaa-server ACS protocol tacacs+
max-failed-attempts 3
accounting-mode simultaneous
aaa-server ACS (INTERNAL) host <acs-ip-address>
key <shared-secret>
My question is, should I configure INTERNAL or Management in the "aaa-server" command?
Thanks,
niks
05-13-2015 05:28 AM
I do not think you can do that. You will need to specify your inside IP in ACS.
05-13-2015 08:17 AM
Hi Pavel,
Good Day!
Unless there's a link from MGMT port to ACS right?
Thanks
05-13-2015 12:52 PM
If you do "show route <IP-of-ACS-server>" it will tell you the answer. It should be the interface that the server is reached on.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide