×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

ASA 55x0 error connecting to AAA (ACS 5.2)

Unanswered Question
Apr 17th, 2012
User Badges:

ASA 55x0 error connecting to AAA (ACS 5.2)


Hi, we encountered a problem between


     CISCO ASA 5510

     CISCO ACS 5.2


If I have a downloadable ACL more long/deep of 68 lines for the user defined inside Identity Manager, it


keep in error.


ASA live log say that is unable to contact AAA


If I delete a line keeping downloadable ACL inside 68 lines, all go fine.


The service used is SSL VPN with Anyconnect 3


is it a referenced bug or is it a limit?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Harish Balakrishnan Tue, 04/17/2012 - 06:16
User Badges:
  • Silver, 250 points or more

Hello Alberto


I think there is a limit of  16 KB for the size of the downloadable acl. In your case , when you add more than 68 lines, it could be crossing the limit. What you can do here, instead of using seperate lines, go ahead and create object-group and use that in your downloadable acl config. something like follows




Regards

Harish.

Actions

This Discussion