VPN router AAA issue

Answered Question
Oct 1st, 2009


We have a router-ASA internet VPN. ASA is on central site, router is on remote site. We have a ACS server at central site behind the ASA, now we need the remote router to do AAA with the ACS server when someone logon to it. I added the config on ACS and router, but the problem is remote site router can not reach the ACS server unless the source ip is LAN ip. Anyone know if we can set the source ip to LAN ip for AAA reqeust packet on the router?

Thanks. Leo

I have this problem too.
0 votes
Correct Answer by Collin Clark about 7 years 2 weeks ago


ip tacacs source-interface FastEthernet0/0

Hope it helps.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 4 (2 ratings)
Correct Answer
Collin Clark Fri, 10/02/2009 - 06:09


ip tacacs source-interface FastEthernet0/0

Hope it helps.

Jatin Katyal Fri, 10/02/2009 - 06:20

Hi Leo,

Further to collin post...

yes that is possible.

on the router you need to use this command.

The ip tacacs source-interface configuration command allows you to specify a particular source IP address for TACACS.

And, On the ACS you need to add router with the same LAN IP address.




This Discussion