<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>ACS on outside Interface in Cisco</title>
<link>http://www.dslreports.com/forum/r20510927</link>
<description></description>
<language>en</language>
<pubDate>Wed, 20 Aug 2008 23:34:28 EDT</pubDate>
<lastBuildDate>Wed, 20 Aug 2008 23:34:28 EDT</lastBuildDate>

<item>
<title>Re: ACS on outside Interface</title>
<link>http://www.dslreports.com/forum/remark,20516457</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : <div class="bquote"><small>said by  wasiim <A HREF="/useremail/u/1536711"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>thanks for the reply, but i m concern about the fact that what will happen when tacacs will unavailable, i will not able to login even via console, that is why i m configuring the local command set in case if ACS down, at least i will be able to get in.<br></div>That's the reason why you need to issue <i>aaa authentication serial console TACACS+ LOCAL</i>. When you or somebody console in, the person will authenticate with TACACS+ server when the server is available. When the server is unavailable, the person will authenticate locally.<br><br>If you want, you can do some testing by power down or disconnect your TACACS+ server off the network. You can then verify the authentication behavior when TACACS+ server is available and when it is unavailable.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20516457</guid>
<pubDate>Wed, 21 May 2008 09:41:00 EDT</pubDate>
</item>

<item>
<title>Re: ACS on outside Interface</title>
<link>http://www.dslreports.com/forum/remark,20513845</link>
<description><![CDATA[<A HREF="/useremail/u/1536711"><b>wasiim</b></A> : thanks for the reply, but i m concern about the fact that what will happen when tacacs will unavailable, i will not able to login even via console, that is why i m configuring the local command set in case if ACS down, at least i will be able to get in.<br><br>Please correct me, I will use command authorization service only from tacacs which i m using already and it is working fine for me. If ACS will goes down, what will happen, I wil able to login bcz of this command<br>aaa authentication serial console tacacs+ local<br><br>how the command authorization will react at that time. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20513845</guid>
<pubDate>Tue, 20 May 2008 18:33:18 EDT</pubDate>
</item>

<item>
<title>Re: ACS on outside Interface</title>
<link>http://www.dslreports.com/forum/remark,20513293</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : Why do you set such privilege command list on your PIX? That would beat the purpose of having TACACS+ server, wouldn't it? :)<br><br>Set those command restriction on your TACACS+ server instead since it is TACACS+ server's job to decide whether specific command is approved for specific user under specific privilege level.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20513293</guid>
<pubDate>Tue, 20 May 2008 16:44:08 EDT</pubDate>
</item>

<item>
<title>Re: ACS on outside Interface</title>
<link>http://www.dslreports.com/forum/remark,20513273</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : Set serial authentication to use your TACACS+ server as primary and use LOCAL as backup; just like ssh and enable authentication. This way you should be able to authenticate with your TACACS+ server (or to authenticate locally if the TACACS+ server is unreachable) when console in.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20513273</guid>
<pubDate>Tue, 20 May 2008 16:41:34 EDT</pubDate>
</item>

<item>
<title>Re: ACS on outside Interface</title>
<link>http://www.dslreports.com/forum/remark,20513102</link>
<description><![CDATA[<A HREF="/useremail/u/1536711"><b>wasiim</b></A> : Problem solved, i removed the device and again add it and it is working fine now, but one more problem arise, and that is i m not able to console my firewall, i have applied the command authorization and it is working fine for me, but i m not able to console my device. I wanted to use this option in case, ACS goes down and i can console my firewall and but it is not working fine me. <br><br>aa-server TACACS+ protocol tacacs+<br>aaa-server TACACS+ (edn) host 172.28.31.132<br>aaa-server TACACS+ (edn) host 172.28.31.133<br>aaa authentication ssh console TACACS+ LOCAL<br>aaa authentication enable console TACACS+ LOCAL<br>aaa authentication serial console LOCAL <br>aaa authentication http console LOCAL <br>aaa authorization command TACACS+ LOCAL<br>aaa accounting command privilege 15 TACACS+<br>aaa accounting enable console TACACS+<br><br>but i m not able to login i m getting following eror<br><br>Command authorization failed<br>TDC-INT-525-01> exit<br>Command authorization failed<br>TDC-INT-525-01> exit<br>Command authorization failed<br>TDC-INT-525-01> enable<br>Command authorization failed<br><br>i also defined the local command authorization set like this<br><br>privilege cmd level 15 mode exec command exit<br>privilege show level 5 mode exec command running-config<br>privilege show level 15 mode exec command version<br>privilege show level 0 mode exec command access-list<br>privilege show level 0 mode configure command access-list<br>privilege cmd level 15 mode configure command exit<br>privilege cmd level 15 mode configure command no<br>privilege cmd level 0 mode configure command access-list<br>privilege cmd level 15 mode interface command exit<br>privilege cmd level 15 mode subinterface command exit<br>privilege cmd level 15 mode dynupd-method command exit<br>privilege cmd level 15 mode trange command exit<br>privilege cmd level 15 mode route-map command exit<br>privilege cmd level 15 mode router command exit<br>privilege cmd level 15 mode ldap command exit<br>privilege cmd level 15 mode aaa-server-host command exit<br>privilege cmd level 15 mode aaa-server-group command exit<br>privilege cmd level 15 mode context command exit<br>privilege cmd level 15 mode group-policy command exit<br>privilege cmd level 15 mode username command exit<br>privilege cmd level 15 mode tunnel-group-general command exit<br>privilege cmd level 15 mode tunnel-group-ipsec command exit<br>privilege cmd level 15 mode tunnel-group-ppp command exit<br>privilege cmd level 15 mode mpf-class-map command exit<br>privilege cmd level 15 mode mpf-policy-map command exit<br>privilege cmd level 15 mode mpf-policy-map-class command exit<br>privilege cmd level 15 mode mpf-policy-map-class command exit<br>privilege cmd level 15 mode mpf-policy-map-param command exit<br><br>Please tell me how to solve this problem ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20513102</guid>
<pubDate>Tue, 20 May 2008 16:13:38 EDT</pubDate>
</item>

<item>
<title>Re: ACS on outside Interface</title>
<link>http://www.dslreports.com/forum/remark,20511050</link>
<description><![CDATA[<A HREF="/useremail/u/676954"><b>aryoba</b></A> : The AAA commands you posted looked fine. Therefore I don't believe the problem lies on the AAA commands themselves. The problem might be the NAT or route statement.<br><br>Keep in mind that your ACS 172.28.x.x IP address is located outside. Therefore the PIX routing table should have the IP address accessible toward outside interface and not inside interface. As to NAT, you may need to implement no NAT statement to avoid NAT between inside and outside in order to authenticate with outside TACACS server.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20511050</guid>
<pubDate>Tue, 20 May 2008 10:27:34 EDT</pubDate>
</item>

<item>
<title>ACS on outside Interface</title>
<link>http://www.dslreports.com/forum/remark,20510927</link>
<description><![CDATA[<A HREF="/useremail/u/1536711"><b>wasiim</b></A> : I have pix 535, i want to configure it for ACS authentication, but problem is that, users tries to login from inside interface and ACS located on outside interface of pix firewall. <br><br>I have configured the following commands but still not able to get the authentication, <br><br>aaa-server TACACS+ protocol tacacs+ <br>aaa-server TACACS+ (outside) host 172.28.x.x x.x.x <br>aaa-server TACACS+ (outside) host 172.28.x.   xx <br>aaa authentication ssh console TACACS+ LOCAL <br>aaa authentication serial console LOCAL <br>aaa authentication enable console TACACS+ LOCAL <br>aaa authorization command TACACS+ <br>aaa accounting command privilege 15 TACACS+ <br>aaa accounting enable console TACACS+ <br><br>same configuration is working fine for me with rest of the firewalls of my network bcz ACS and users are located on the same interface side, only this firewall is having problem. <br><br>Firewall is not having any thing like source interface like routers have. <br><br>Please help me out. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20510927</guid>
<pubDate>Tue, 20 May 2008 10:00:04 EDT</pubDate>
</item>

</channel>
</rss>
