cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
489
Views
0
Helpful
3
Replies

ACS and download ACL to several AAA-clients

uralsib
Level 1
Level 1

HI!

I need to know if there is a possibility to download ACL to the DACL-enabled device that is not a part of the RADIUS conversation? In other words I have one user that needs an access to some resources and is attempting to log to the network through PIX1. I need to authenicate him through ACS and to download ACL to PIX1 and (attention) PIX2 too (some up-stream firewall). Is there any way to do it?

1 Accepted Solution

Accepted Solutions

I don't think you can do this. As you have mentioned that the other PIX does not have Radius configuration. And you can only push DACL from Radius server on the PIX that is requesting it, not to any other PIX.

And I am not aware of any mechanism or feature, that can transfer the downloaded ACLs, from one PIX to another.

Regards,

Prem

View solution in original post

3 Replies 3

uralsib
Level 1
Level 1

Does anybody have any ideas how can I solve the problem?

Regards, Amir

I don't think you can do this. As you have mentioned that the other PIX does not have Radius configuration. And you can only push DACL from Radius server on the PIX that is requesting it, not to any other PIX.

And I am not aware of any mechanism or feature, that can transfer the downloaded ACLs, from one PIX to another.

Regards,

Prem

Prem, thank you for your reply. OK, I'll try to re-build my scheme.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: