ACS 4.1 NAR

Aug 21, 2007 1 Replies

I am trying to limit the access to the routers via NAR using ACS 4.1 but I get some strange results.



My worksation is 192.168.249.210 and the ACS's per-user NAR is set as follows :



Table Defines : Permitted Calling/Point of Access Locations All AAA Clients , port 23, IP address 192.168.249.210



With the above settings, I cannot login to the router while I expect I should be able to.



When I change the Table Defines to Denied Calling / Point of Access Locations, then I can login, not only from .210 but from everywhere.



I thought the "Permitted" means allowed, and Denied means "not allowed".



Any advice is greatly appreciated,



DT



I should have read the TACACS+ protocol more carefully before posting that question. The "port " in this case is an ascii string that species the port of the NAS device, not the IP-protocol port. This ascci-string port can be checked easily when loojing into the Failed Attemps log of ACS.

All works as expect now.

Just another example of doing without reading. Shame on me !

DT

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required