cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
769
Views
0
Helpful
3
Replies

Overlapping IP range for AAA Client (ACS 4.1.4)

Jozef Cmorej
Level 1
Level 1

Hello,

I have a problem with overlapping IP range AAA Client's in ACS 4.1.4. I have one client with IP address range 10.*.*.* and I can't add another one client with more accurately range 10.64.*.*. It's possible to make overlapping IP ranges in version 3.2 but it is not in 4.1? Is it a feature or restriction of newer version? Thank you.

3 Replies 3

Jagdeep Gambhir
Level 10
Level 10

Hi Jozel,

Yes, you will not be able to add any IP of range 10.x.x.x as it is already covered in wild cards.

You can add same range IP only incase you use different protocol. (Tacacs / Radius)

I don't think it was possible on 3.x.

Regards,

~JG

Do rate helpful posts

Jatin Katyal
Cisco Employee
Cisco Employee

Hi,

This is an expected behavior since 10.*.*.* is already covered 10.64.*.* so you won't able to add this again. And this is applicable for all ACS version be it 3.x or 4.x

You may check this:

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/NetCfg.html#wp354890

HTH

JK

Plz rate helpful posts-

~Jatin

Hi,

we have the other one ACS version 3.2.1. We have defined AAA client with range 10.*.*.* there and I am able to add more specific range 10.144.10.* without problems, using the same protocol Tacacs+ inside the same Network Device Group.

So I am confused.

Thanx