For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

simon_84972's avatar
simon_84972
Icon for Nimbostratus rankNimbostratus
Jun 02, 2014

ACS 5.2 config for TACACS arritbute value pair,

anyone can provide how to configure cisco ACS for tacacs AAA for F5 user?

 

1 Reply

  • Here's one of the most recent threads about this topic:

     

    https://devcentral.f5.com/questions/how-to-configure-tacacs-on-cisco-acs-53-for-authenticate-administrative-users-on-ltm-1120

     

    The basic idea is that you need to create several things. On the BIG-IP:

     

    TACACS server (pointing to your ACS 5.2 box), use the following parameters:

     

    • Service Name ppp
    • Protocol Name ip

    Remote role (name of the remote role should match verbatim the group name within ACS that you want to apply this role to)

     

    And on the ACS 5.2 box:

     

    Shell profile (specifying the attribute that you assigned in your remote role configuration)

     

    Assign the shell profile to the desired identity group