08-10-2005 07:34 AM
Hi all, I'm configuring a 3745 with an NM-16A connected to a modem bank and also a 30 port Mica Modem module served by an CE1 link to a PBX for dial in access. I'd like the majority of users to be able to authenticate via Tacacs but sysadmins to authenticate locally. Can this be done on a per port basis?
08-16-2005 06:24 AM
yes, i hope this can be done by giving different gateway to the users and different gateway to the sys admins.but care should be taken that the gateway should not mismatch to avoid unneccesary data should not traverese.
08-22-2005 08:49 PM
This would be difficult to do on a per-port basis I would think.
I would probably partition them into two dialer-groups, which employ different AAA authenticators.
You might base the binding of the port based on ANI, so that the administrators can call one number and be authenticated locally, and the normal users can dial and be authenticated by TACACS+.
I hope this makes sense.
-colin.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide