11-11-2008 07:47 AM - edited 03-10-2019 04:10 PM
I just added ASA firewall to Cisco ACS 3.2
using commands as follows
aaa-server ciscoacs protocol tacacs+
aaa-server ciscoacs host 172.X.X.X
key Im@&yo
aaa authentication telnet console ciscoacs
I am able to login in into ASA (authentication passes successfully) and go to enable mode but i am unable to execute any command and it shows error as
Command Authorisation failed
i tried to add some more commands as follows
aaa authentication serial ciscoacs
aaa authentication ssh ciscoacs
aaa authentication secure-http-client ciscoacs
aaa authorization command ciscoacs
aaa accounting command ciscoacs
but dont know whether they were added to ASA configuration file or not as i cannot execute any command from privilege mode not even am able to exit from ASA using CLI
Kindly ket me know how can i be able to go into configuration mode so that aa server commands are removed
11-11-2008 02:05 PM
Remove the IP address of the firewall in your AAA server. It will then timeout and use local authentication and authorization.
Hope that helps.
11-11-2008 06:12 PM
Hi Clark
the username cisco with privilege level 15 stands removed from the ASA configuration.
SO what next
11-12-2008 06:23 AM
Please re-read my post. You will need a local username and password as well.
01-16-2009 02:51 PM
hi
I am the same probleme
I use the applaince ACS 4.2 ans asa5520 ver 7.25
I am able to login in into ASA (authentication passes successfully) and go to enable mode but i am unable to execute any command
same configuration works with router IOS
help me.
01-16-2009 02:59 PM
hi
I am the same probleme
I use the applaince ACS 4.2 ans asa5520 ver 7.25
I am able to login in into ASA (authentication passes successfully) and go to enable mode but i am unable to execute any command
same configuration works with router IOS
help me.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide