cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
649
Views
0
Helpful
4
Replies

Cisco ACS. Two-factor authenticaion.

Raketckii
Level 1
Level 1

Hello.

We intend to use scheme of connection: cisco asa + cisco acs 5.4 + rsa securid.
We use two groups on Cisco ACS . Group "A" must use two-factor authentication, and the group "B" don't.
how to create this rule?

1 Accepted Solution

Accepted Solutions

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Perform rule base identity selection with dap-tunnel-group-name as selector. 

ASA will send tunnel group name in auth request. 

 

Example attached.

 

View solution in original post

4 Replies 4

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Perform rule base identity selection with dap-tunnel-group-name as selector. 

ASA will send tunnel group name in auth request. 

 

Example attached.

 

Hello Marcin.

I do not understand how this rule will apply to the base secureid? You associate  ASA with securid or ACS?

ASA associates with ACS, ACS with RSA over RADIUS. 

Everything works. Thank you!