Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

VPN router AAA issue

Hi

We have a router-ASA internet VPN. ASA is on central site, router is on remote site. We have a ACS server at central site behind the ASA, now we need the remote router to do AAA with the ACS server when someone logon to it. I added the config on ACS and router, but the problem is remote site router can not reach the ACS server unless the source ip is LAN ip. Anyone know if we can set the source ip to LAN ip for AAA reqeust packet on the router?

Thanks. Leo

1 ACCEPTED SOLUTION

Accepted Solutions

Re: VPN router AAA issue

Leo-

ip tacacs source-interface FastEthernet0/0

Hope it helps.

3 REPLIES

Re: VPN router AAA issue

Leo-

ip tacacs source-interface FastEthernet0/0

Hope it helps.

Cisco Employee

Re: VPN router AAA issue

Hi Leo,

Further to collin post...

yes that is possible.

on the router you need to use this command.

The ip tacacs source-interface configuration command allows you to specify a particular source IP address for TACACS.

And, On the ACS you need to add router with the same LAN IP address.

HTH

JK

~BR Jatin Katyal **Do rate helpful posts**
Community Member

Re: VPN router AAA issue

Cool, thanks guys. Will have try and see how it goes.

Leo

208
Views
4
Helpful
3
Replies
CreatePlease to create content