cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
349
Views
0
Helpful
2
Replies

Time limited IP access via Pix

mmedwid
Level 3
Level 3

Is there a way to use a Pix to permit users on authentication to have all IP (or a subset of ports) for a limited time period? For example in order for user on network 192.168.1.0/24 to be able to reach a system on 192.168.2.0/24 - the user browses to the pix and enters a user name and pw. Then that user has access to 192.168.2.0/24 for say 2 hours and then no more access. Doable with the pix in conjunction with Cisco ACS radius or tacacs? I believe it's possible - but mostly unclear about being able to set and absolute time limit. Thanks.

2 Replies 2

b.speltz
Level 4
Level 4

You can use the timout command, but this will only ask the user to reenter the password.

That could be perfect. So they stop having access until they enter a password? What would the command line read? AAA tacacs ... timeout X ?

Review Cisco Networking for a $25 gift card