cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
364
Views
0
Helpful
4
Replies

Switches and Routers can authenticate through ASA5520

majaj
Level 1
Level 1

routers & Switches (outside zone) can't authenticate using ACS (inside zone)

even if i permit any any

i can telnet to ACS port 49 , i can also ping to ACS

but there is no failed or passed attempt is coming from devices in outside Zone

4 Replies 4

rkalia1
Level 1
Level 1

Have you added the devices in the in the ACS. Also, have you conigured AAA on the routers and switches on the outside. A config of these will help answer better.

Raman

If I understand the post from Mohammed correctly there are no failed attempts reported. If the issue were that they were not configured in ACS then there would be entries in the failed attempt log - indicating attempts from an unknown host.

Asking to see some configs from devices that do not work is a very reasonable thing. It would allow us to see if there were issues that might prevent authentication. And it would allow us to see if the source interface is specified. Mohammed says that he can telnet to the server on port 49 which demonstrates that there is IP connectivity using the default choice of interface. I would like to see if that is the same interface that AAA is using.

If there are no failed attempts reported then that implies that either the firewall is denying the requests (which Mohammed implies is not the case) or they are not being sent from the router, or they are being misdirected. If seeing the configs does not point toward a solution perhaps the output of debug tacacs authentication would be helpful.

HTH

Rick

HTH

Rick

actually , there is no failed or passed attempt at ACS server

the router is choosing to authenticate locally , like if it is can't see the ACS.

but why it can't see the ACS?

As I suggested in my previous post:

If there are no failed attempts reported then that implies that either the firewall is denying the requests (which Mohammed implies is not the case) or they are not being sent from the router, or they are being misdirected. If seeing the configs does not point toward a solution perhaps the output of debug tacacs authentication would be helpful.

Please post configs or post debug output.

HTH

Rick

HTH

Rick
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card