cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
483
Views
0
Helpful
1
Replies

Use RSA tokens + user id/password to access CLI

lbbwsgbank
Level 1
Level 1

My customer was thinking to introduce a 2FA mechanism, to restrict access to ASA CLI. So he was suggesting to use RSA token. Is this possible?

1 Reply 1

mirober2
Cisco Employee
Cisco Employee

Hi Srinivasan,

To do this, you'll need to setup a AAA server group with a protocol of 'sdi'. Here are the guides that explains how to do this:

RSA/SDI Server Support:
http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_aaa.html#wp1053066

Identifying AAA Server Groups and Servers:
http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_aaa.html#wp1039757

Configuring Authentication for CLI and ASDM Access:
http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/access_management.html#wp1060011

Hope that helps.

-Mike

Review Cisco Networking for a $25 gift card