Forum Discussion
Adding F5 to TACACS
How do I add LTM v10.2.0 to TACACS for user authentication, I am using a cisco ACS, what are the configurations I should make in Cisco ACS and in the LTM
Thanks for your helps
Veeram
- nitassEmployeehave you seen these? can you try them?
- Ramkumar_Bala_7NimbostratusHi
- nitassEmployeeI have 14 users configured in the Local directory, if I change the Authentication type under system -- users -- authentication to Remote--TACACS+, will I loose access to locally configured accountsyes, i understand all user except root and admin will be authenticated by tacacs+ server.
- Ramkumar_Bala_7NimbostratusHi Nitass,
- Ramkumar_Bala_7NimbostratusHi Nitass,
- Cory_50405NoctilucentRamkumar,
- Ramkumar_Bala_7NimbostratusHi
- Elias_O_16228Nimbostratus
Thanks, This works, We are able to login to LTM using the credential in TACACS, how ever I dont see any accounting in Cisco ACS server for our logins, cant we get accounting and logs in Cisco ACS
I am facing similar issue. LTM authentication via ACS is working fine, but I cann't see accounting logs in ACS.
Help
- nitassEmployee
How ever I dont see any accounting in Cisco ACS server for our logins, cant we get accounting and logs in Cisco ACS
do you mean audit data?
sol13762: Configuring remote RADIUS or TACACS+ accounting
- Elias_O_16228Nimbostratus
Hi nitass,
I was able to get it working with the link you provided, however there is still some issues:
1) I could not add two servers for destination syntax tmos> modify sys db config.auditing.forward.destination value 192.168.1.45 192.168.1.46 (not working) unless only one server. I tried different parameters "{" still did not take it.
2) tmos> save /sys config did not save to the standby unit. Even after b config sync all, the config did not appear in standby unit. (running v10.2.x)
tmos> show running-config sys db config.auditing.forward.destination { sys db config-auditing.forward.destination value "192.168.1.45" }
3) Getting Peer communication which is the standby heartbeat address on the Tacacs+ server. I don't want this audit
tmos> modify sys db config.auditing.forward.destination value 192.168.1.45 192.168.1.46 tmos> modify sys db config.auditing.forward.shared value "mysecret" tmos> modify sys db config.auditing.forward.type value tacacs+ tmos> modify sys db config.auditing value enable tmos> modify sys db log.mcpd.level value info tmos> save /sys config
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com