cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
818
Views
0
Helpful
4
Replies

ACS, AAA config for ASA 5540 7.2 code not working

chuckholley
Level 1
Level 1

Hi,

I cannot login using my ACS credentials on this firewall. I have a 1113 appliance running 4.2, and I am trying to setup a 5540 for AAA. Here is my config on the FW:

ssh 10.12.1.96 255.255.255.255 inside

ssh 10.10.7.179 255.255.255.255 inside

username asaadmin password acs priv 15

aaa-server ACS protocol tacacs+

aaa-server ACS host 10.12.1.30

key acskey

aaa authentication ssh console ACS LOCAL

aaa authentication serial console ACS LOCAL

aaa authentication enable console ACS LOCAL

aaa authorization command ACS LOCAL

aaa accounting ssh console ACS

I do not see this ASA in failed attempts on the ACS box. I have never been able to ping the ACS server from anywhere, but I have switches and routers authenticating.

The ACS box is 10.12.1.30

FW is 10.12.1.37 on the Managment 0/0 interface.

I have a default route to 10.12.1.1 on the FW for mgt and inside.

Thank you for your assistance.

4 Replies 4

chuckholley
Level 1
Level 1

I ran this test, it appears that the ASA and ACS appliance are not talking.

LMTVPN01(config)# test aaa-server authentication ACS host 10.12.1.30 username$

INFO: Attempting Authentication test to IP address <10.12.1.30> (timeout: 12 seconds)

ERROR: Authentication Server not responding: No error

Any Help would be appreciated!!!

LMTVPN01(config)test aaa-server authentication ACS host 10.12.1.30 username $

INFO: Attempting Authentication test to IP address <10.12.1.30> (timeout: 12 seconds)

INFO: Authentication Successful

OK, i figured out that I need to get it off the managment port due to the nature of that port and my little understanding of it :)

Howere, I still cannot SSH to the FW, I get a access denied and there are no failed attempts logged on the ACS appliance.

FIgured it out, I had to enable PIX shell on the ACS appliance and a pix/asa authorization set!!

Thanks Chuck!

Can you explain this a little more? You enable the pix shell on ACS and a pix authorization set?

Not sure exactly what this mean?

Dwane

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: