cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
370
Views
0
Helpful
2
Replies

Tacacs and Local Authentication for Dial In.

robward
Level 1
Level 1

Hi all, I'm configuring a 3745 with an NM-16A connected to a modem bank and also a 30 port Mica Modem module served by an CE1 link to a PBX for dial in access. I'd like the majority of users to be able to authenticate via Tacacs but sysadmins to authenticate locally. Can this be done on a per port basis?

2 Replies 2

Not applicable

yes, i hope this can be done by giving different gateway to the users and different gateway to the sys admins.but care should be taken that the gateway should not mismatch to avoid unneccesary data should not traverese.

colin
Level 1
Level 1

This would be difficult to do on a per-port basis I would think.

I would probably partition them into two dialer-groups, which employ different AAA authenticators.

You might base the binding of the port based on ANI, so that the administrators can call one number and be authenticated locally, and the normal users can dial and be authenticated by TACACS+.

I hope this makes sense.

-colin.