cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
572
Views
0
Helpful
6
Replies

ASA 5520 & ACS Ver. 3.1

smartin
Level 1
Level 1

Having some problems with group policies & within the ASA system. Able to connect via ASA VPN using ACS 3.1 but how do I apply ACLS for different groups.

I cannot find any information regarding the ASA & RADIUS.

1 Accepted Solution

Accepted Solutions

vkapoor5
Level 5
Level 5

I am not sure of ASA, but PIX 6.3 supports downloadable ACLs from a RADIUS server. TACACS+ not supported. Here is the document that shows how to configure this feature in 6.3.

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/mngacl.htm#wp1030990

View solution in original post

6 Replies 6

vkapoor5
Level 5
Level 5

I am not sure of ASA, but PIX 6.3 supports downloadable ACLs from a RADIUS server. TACACS+ not supported. Here is the document that shows how to configure this feature in 6.3.

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_63/config/mngacl.htm#wp1030990

Downloadable ACLs from the RADIUS server worked ! One question, I noticed that when a user VPN's in they receive their own ACL. Is that the norm ?

If 50 users connect I would then see 50 acls.

Thanks

Stephen,

I'm currently having the same problem you originally had where downloadable ACLs dont seem to work for our VPN users connecting to the ASA. Could you share what you had to do to get this tor work.

Thanks!

Al

Ckeck out the doc

Stephen,

Thanks for the info. This is pretty much the same we have configured. I our case we are running ACS 3.3 so there is no PIX Downloadable ACL option under shared component, is now IP Downloadable ACL.

Anything especial on the ASA or just simple RADIUS authentication for your Tunnel-Group?

Thanks again,

Al

When I created a "tunnel Group" on the ASA under the "General" tab I point the "Authentication Server Group" to the RADIUS Server