08-02-2005 12:48 PM - edited 02-21-2020 12:18 AM
Is there a way to use a Pix to permit users on authentication to have all IP (or a subset of ports) for a limited time period? For example in order for user on network 192.168.1.0/24 to be able to reach a system on 192.168.2.0/24 - the user browses to the pix and enters a user name and pw. Then that user has access to 192.168.2.0/24 for say 2 hours and then no more access. Doable with the pix in conjunction with Cisco ACS radius or tacacs? I believe it's possible - but mostly unclear about being able to set and absolute time limit. Thanks.
08-08-2005 01:42 PM
You can use the timout command, but this will only ask the user to reenter the password.
08-08-2005 02:32 PM
That could be perfect. So they stop having access until they enter a password? What would the command line read? AAA tacacs ... timeout X ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide