11-09-2004 01:39 AM - edited 03-10-2019 01:52 PM
Hi,
I have an ACS 3.2 version and i use it for aaa authentication for the PIX firewall.
Is it possible to use the sama ACS for aaa authentication for another cisco equipment, as i want to use it for the router authentication.
Thanks for your help
11-09-2004 01:54 AM
Of course. The ACS can be centrally used to manage all network components. you can add PIX,router,access server simultaneously and manage all these components through ACS. you just need to have IP connectivity to the component from the ACS server.
If your ACS server is behind PIX< you need to open TCP port 49 for the router to communicate with the ACS server.
Hope this helps.
All the best !! rate all replies if found useful.
11-09-2004 02:10 AM
so,
on the network server detail on the ACS, we can add all the IP addresses of the component with comma (,) as sepration ?
Thanks a lot
11-09-2004 02:22 AM
Hello.
No.. you will add the components one by one. Just configure the router details seperately as you did for the PIX. if the router is outside the PIX , open the port 49 TCP on the PIX . you cannot use a comma and configure all components at once.
11-09-2004 02:47 AM
Thanks a lot for your help
11-09-2004 03:09 AM
thanks.. please close off the post by checking that it solved your issue, so that people dont see it again.
All the best. rate the posts if found useful
11-10-2004 02:02 AM
Hello ,
You don't need to enter each equipments. You can use * instead if you have a lot . For example, you have some 50 Switches in one Vlan or subnet (10.12.10.1 --10.12.10.50 ) , then you can enter in ACS ver 3.2 as 10.12.10.*
We have approximately 150 Switches in Vlan 1 which obiviously requires lot of time to enter in ACS and we made in similar way.
Regards,
Raju
11-10-2004 02:07 AM
That was a useful info Raju. thanks.
11-10-2004 03:35 AM
Hi,
ok for the IP And for the naming host, how can i do if i have 50 equipments
Regards
Mohamed
11-10-2004 05:46 AM
Good question. Name does not matter . Just give a generic name like a Company name or location or Bldg name or Group of Switches etc.This is possible in ACS ver 3.2 only or may be above . I tried with ACS 3.0 ,it did not work. If you go to "Network Configuration " screen in ACS ver 3.2 , you will find the help on right side with "Adding a Network Device Group " and you can go thro it .
Regards...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide