Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA cut-through proxy and ACS 5.3

Hi, I'm planning to migrate a customer from ACS 4.2 to ACS 5.3.

I have migrated the configuration for all the services but I'm thinking how to configure ASA 8.4 cut-through proxy service in TACACS+.

The same ASA uses TACACS+ for device mngt and RADIUS for vpn remote-access services.

How to ?

thank you in advance

rs

  • AAA Identity and NAC
Everyone's tags (5)
1 REPLY

ASA cut-through proxy and ACS 5.3

RS,

Hi here is the guide that helps you configure the cut-through proxy from the ASA this is a good example:

http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_fwaaa.html

When configuring the ACS portion you can use two methods: "Cisco ACS" downloadable access-lists, "Any Radius Server" downloadable access-lists (my favorite), or you can send the filter attribute which points the user to a defined acl on the ASA. Either way you choose, you will have to first create a network authorization profile which will have the radius attributes in the formats that are outlined in this guide. You will create an authorization policy that will call this authorization policy as the result when they meet this condition.

Let me know how things go, if you get stuck, please posts screenshots so I can help you further.

Thanks,

Tarik admani

Tarik Admani
*Please rate helpful posts*

Tarik Admani *Please rate helpful posts*
675
Views
0
Helpful
1
Replies
This widget could not be displayed.