Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,I have one question regarding lan based failover connected pix-es (one pix with UR + second pix with FO license).If primary unit (UR license) failed, secondary unit (FO license) will be active unit. Theoretically, I won't be able to change/repaire...
I would like to use extended authentication of IPSEC VPN client users on the PIX against ACS for UNIX (v2.3.6) using tacacs. My idea is to implement Network access restriction for specific group on tacacs ACS server - to allow authenticate on the PIX...
ok, but is somewhere on cisco web any docs where the exact behaviour for this case (UR+FO) is described. I think FO license has an exact limitations, how it should work and how it shouldn't work for specific pix os release.
I am running pix os 6.3.3I saw the conversation below, but the question is how is failover working in this configuration?I didn't find any useful docs about it.
Hi,ok, it's configured in this way on the ACS, and records in csuslog are:May 2 14:06:01 server CiscoSecure: [ID 722389 local0.debug] DEBUG - Authentication - LOGIN successful; [NAS=pix, Port=0, User=jmvpn, Priv=1]May 2 14:06:01 server CiscoSecure:...