cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1169
Views
0
Helpful
1
Replies

PIX tacacs+ authentication

sikkander
Level 1
Level 1

Hi folks

I hv setup cisco ACS for authentication using Tacacs+ protocol.When the PIX fw is configured for ACS authentication,can the local database configured for authentication be used incase the ACS server is not available.Infact I hv defined this in PIX but inspite of this,I am not able to use the username & pwd which has been created in the local database

Pl let me know what cud be the potential cause for this problem?

Tks

SS

1 Reply 1

ehirsel
Level 6
Level 6

I do not believe that you can do that like you can with IOS. If the AAA servers are down, you should be able to use the user name of pix and use the enable password as the password to get it.

An alternative solution is to use local for serial console access only and use AAA for telnet and ssh (remote) connections, so that you still have access in the event that AAA is down.

See the pix password recovery doc, and be prepared in case you test AAA authen and you lock yourself out of getting access to the PIX.