Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » Cisco » ACS on outside Interface
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
ISP speed increased-still but router can't use it »
« [Config] QOS for Cisco 800 w/ Dialer interfaces using NBAR  
AuthorAll Replies

aryoba
Premium,MVM
join:2002-08-22

reply to wasiim
Re: ACS on outside Interface

Why do you set such privilege command list on your PIX? That would beat the purpose of having TACACS+ server, wouldn't it?

Set those command restriction on your TACACS+ server instead since it is TACACS+ server's job to decide whether specific command is approved for specific user under specific privilege level.

wasiim

join:2008-03-12

thanks for the reply, but i m concern about the fact that what will happen when tacacs will unavailable, i will not able to login even via console, that is why i m configuring the local command set in case if ACS down, at least i will be able to get in.

Please correct me, I will use command authorization service only from tacacs which i m using already and it is working fine for me. If ACS will goes down, what will happen, I wil able to login bcz of this command
aaa authentication serial console tacacs+ local

how the command authorization will react at that time.

aryoba
Premium,MVM
join:2002-08-22

said by wasiim See Profile :

thanks for the reply, but i m concern about the fact that what will happen when tacacs will unavailable, i will not able to login even via console, that is why i m configuring the local command set in case if ACS down, at least i will be able to get in.
That's the reason why you need to issue aaa authentication serial console TACACS+ LOCAL. When you or somebody console in, the person will authenticate with TACACS+ server when the server is available. When the server is unavailable, the person will authenticate locally.

If you want, you can do some testing by power down or disconnect your TACACS+ server off the network. You can then verify the authentication behavior when TACACS+ server is available and when it is unavailable.
Forums » Equipment Support » Hardware By Brand » CiscoISP speed increased-still but router can't use it »
« [Config] QOS for Cisco 800 w/ Dialer interfaces using NBAR  


Sunday, 12-Oct 19:55:11 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [147] It's Cable TV Rate Hike Season
· [98] Wholesale Bandwidth Prices Still Dropping
· [96] Symmetrical FiOS No Longer Qualifies For Bundle Discounts
· [95] Is Comcast Cooking Up a 22Mbps/5Mbps Tier?
· [93] Time Warner's Ugly Feud With LIN TV
· [77] Half Of New iPhone Owners Came From Verizon
· [70] Supreme Court TiVo/Echostar Ruling
· [70] Microsoft: U.S. Broadband Policy 'Total Failure'
· [69] Verizon Unveils Blackberry Storm
· [64] XOHM Online In Additional Launch Markets
Most people now reading
· Hit from behind [General Questions]
· Man with 36 accounts, raids by himself [World of Warcraft]
· Extreme HD and Essentials [Verizon FIOS TV]
· [NFL] NFL Week 6 Games, 2008 [Sports Chat]
· Why do mustangs sound so good? [Automotive]
· Fake MS update letter w/attachment [Security]
· Safty Question about K & T wiring. Very worried... [Home Repair & Improvement]
· Flu Shot...good or bad?? [Rants, Raves, & Praise]
· Should hourly workers work for free thru lunch [General Questions]
· Does Boston have a free store? [General Questions]