cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
304
Views
0
Helpful
3
Replies

Enrolling ASA to ACS

fatalXerror
Level 5
Level 5

Hi Experts,

 

Good Day!

 

I need help for my implementation of AAA in ASA. Technically, my ASA has a 2 interfaces which are listed below,

  • INTERNAL
  • Management

My ACS is located at the INTERNAL interface but we need to enroll in the ACS the Management IP of the ASA which is in the Management interface. So, my configuration of AAA look like below,

aaa-server ACS protocol tacacs+

  max-failed-attempts 3

  accounting-mode simultaneous

aaa-server ACS (INTERNAL) host <acs-ip-address>

  key <shared-secret>

My question is, should I configure INTERNAL or Management in the "aaa-server" command? 

 

Thanks,

 

niks

3 Replies 3

Pavel Trinos
Level 1
Level 1

I do not think you can do that. You will need to specify your inside IP in ACS.

Hi Pavel,

 

Good Day!

 

Unless there's a link from MGMT port to ACS right? 

 

Thanks

If you do "show route <IP-of-ACS-server>" it will tell you the answer. It should be the interface that the server is reached on.