cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1050
Views
0
Helpful
2
Replies

Routers Not Defined in ACS Allowing AAA viaTACACS

gerardwest
Level 1
Level 1

We use 6 Cisco ACSs with ver 3.2 with routers running IOS 11.1 thru 12.3. Entries are made on 1 ACS and its database is replicated to the other 5 ACSs. Routers with the same IOS ver are configured with the same AAA statements. Depending on a router's location it will communicate with a certain server via the tacacs-server command. All the routers and ACSs use the same tacacs-server key. In some cases routers not built into ACS but configured with AAA statements with TACACS are allowing authenicated logins. I can't figure out why this is happening. Our ACS server is not setup to allow access from a range of IP addresses. Each router and its associated IP addr is defined individually.

2 Replies 2

Not applicable

Did you check the bug tool kit for any known issues??

I did. I looked under Cisco Secure ACS for Windows for ver 3.2 and couldn't find anything related to my problem.