cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1858
Views
0
Helpful
2
Replies

CiscoSecure ACS ports through the firewall!

misramanish
Level 1
Level 1

My AP's sit outside the firewall and the ACS sits inside. What port(s) are needed between the AP and ACS to be allowed through the firewall (PIX) for authentication/communication to happen? This is using WPA/TKIP with LEAP.

Thanks!

2 Replies 2

sstudsdahl
Level 4
Level 4

The ports would depend on your configuration of the AAA servers on the AP.

If you are using TACACS+ in your AAA configuration, you will need to allow the AP to communicate to the ACS server on TCP port 49.

If you are using RADIUS, there are a couple of different ways to do this. Again, this depends on how your AP is configured. The ports that RADIUS uses are UDP based and are either ports 1645 & 1646, or 1812 & 1813.

Steve

Hi guys,

Although an old thread, I've a related question here:

 - are you guys using ACS for Internet exposed devices in terms of authentication or you just use local database there?

We have it on for all our Intranet devices but not sure if this is a good/secure idea on all Internet routers..?

Thanks,

Florin.

Review Cisco Networking for a $25 gift card